Information System Security Officer (ISSO) - SCIF Office Location: Onsite role - Reston, VA Clearance Required: Active TS/SCI with Full Scope Polygraph Number of Positions: 1
Seeking a Information System Security Officer (ISSO) to serve as the security authorization authority for classified information systems operating within a SCIF environment. This is a systems security function focused on authorization, control enforcement, and compliance oversight. This role is responsible for ensuring systems are authorized, continuously monitored, and compliant with the NIST Risk Management Framework (RMF) and applicable Intelligence Community Directives (ICD 503, ICD 704, ICD 705).
Key Responsibilities
System Authorization & RMF Governance
Own the Authorization to Operate (ATO) lifecycle for classified systems
Develop and maintain System Security Plans (SSPs) and RMF documentation
Lead security assessments, authorization decisions, and reauthorization activities
Ensure alignment with NIST 800-53 control requirements
Continuous Monitoring & Risk Management
Operate continuous monitoring (ConMon) programs for in-scope systems
Track and manage vulnerabilities, control gaps, and remediation activities
Ensure timely resolution of findings impacting system authorization status
Security Governance & Control Independence
Enforce segregation of duties between system administration and security authorization
Validate that system changes are properly reviewed, approved, and documented
Maintain oversight of privileged access and security-relevant system modifications
Engineering & Platform Collaboration
Partner with Agency infrastructure, platform, and application teams on secure system design and operation
Provide security requirements during system deployment and change activities
Support remediation of audit findings and control deficiencies
Required Qualifications
5-8 years of experience in ISSO, ISSM, or equivalent systems security role
Active TS/SCI with Full Scope Polygraph
Completion of an IC ISSO training program (or equivalent)
Strong experience with NIST RMF and ATO lifecycle management
Experience developing and maintaining SSPs and security authorization packages
Working knowledge of ICD 503, ICD 704, ICD 705
Experience operating in classified or SCIF environments
Strong understanding of NIST 800-53 security controls and assessment processes
Ability to work independently in a highly regulated environment
Strong documentation, communication, and audit readiness skills
Preferred Experience
Prior experience supporting IC or DoD classified system environments
Experience with continuous monitoring (ConMon) and control automation
Background in cloud, hybrid, or on-prem classified infrastructure environments
Experience supporting security assessments, ATO renewals, and audit remediation
Familiarity with enterprise security and vulnerability management tooling
Education
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field preferred; equivalent experience considered.
Certifications & Licenses
TS/SCI with Full Scope Polygraph