user avatar

Information System Security Officer

Xpect Solutions Inc.

Posted today

Job Requirements

Crystal City, VA
Public Trust Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Company Overview



XPECT Solutions, LLC. has built a strong reputation by supporting our clients in meeting their strategic goals and mission objectives. We provide high quality resources for a wide range of IT and security solutions at best-value pricing. Our success is built on a solid foundation of well-vetted, highly technical personnel, a disciplined project management approach, and an overarching commitment to customer service. We develop, test, deploy, and support exceptional solutions that enhance system functionality, while maximizing reliability and availability, and ensure the tightest security.


Job Overview


XPECT Solutions seeks an experienced Information Systems Security Officer (ISSO) to lead compliance and security operations for government information systems. In this role, you will navigate the full NIST Risk Management Framework, ensure adherence to NIST 800-53 controls and DHS 4300A requirements, and oversee continuous authorization and monitoring activities. You will partner with Government Security Assurance Management teams, IT Program Managers, and security operations centers to protect critical systems and maintain compliance posture. This role demands deep technical security expertise, regulatory knowledge, and the ability to communicate complex security concepts to diverse stakeholders.



Core Responsibilties (to include but not limited to):



Risk Management Framework & Authorization


  • Participate in all phases of the NIST 800-37 Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor)

  • Ensure systems comply with NIST 800-53 security controls and DHS 4300A requirements

  • Prepare comprehensive security documentation and collect security artifacts in advance of assessments

  • Conduct self-assessments and support Security Control Assessment activities



Security Compliance & Remediation


  • Evaluate effectiveness of proposed solutions to audit findings, Security Control Assessments, and other security weaknesses

  • Perform root cause analysis of audit findings and security incidents

  • Develop requirements for security control remediation activities

  • Review vulnerability scans from security assessment tools (Nessus, WebInspect, DbProtect, etc.)

  • Develop security control implementation statements and review supporting procedures and work instructions


Security Documentation & Planning

  • Review and update the System Security Plan (SSP) and supporting security documentation

  • Work with Government Security Assurance Management (SAM) on Plan of Action and Milestones (POA&M) closure requests

  • Prepare status reports on security control accuracy and completeness

  • Interpret security principles and requirements for remediation plans

  • Brief Security Assurance Management and support teams on security posture and remediation strategies


Configuration & Change Management

  • Perform security impact analysis of proposed configuration changes

  • Review security implications of system changes with Government IT Program Managers (ITPMs) and support staff



Continuous Monitoringg & Ongoing Operations


Once a system is operational, the ISSO performs recurring activities—ad hoc, daily, weekly, monthly, quarterly, and annually—documented in the continuous monitoring plan:


  • Support all Authorization to Operate (ATO) and continuous authorization activities

  • Plan of Action and Milestones (POA&M) Management to track identified system weaknesses to resolution

  • Information Security Vulnerability Management (ISVM)—review system scans at least monthly for new weaknesses, missed patches, unauthorized assets, or configuration changes

  • Patch Management to ensure all systems are patched regularly and compliance is maintained

  • Document and monitor any security issues or inconsistencies

  • Review ISVM findings for applicability and create POA&Ms or take corrective action as required

  • Audit Log Monitoring and Event Management—periodically review logs for security incidents, unauthorized access attempts, and anomalous activity

  • Awareness and Training—ensure all system users complete security awareness and role-based security training annually

  • Work with federal product managers to prioritize security-related POA&Ms or enhancements into active sprints and releases

  • Provide 24×7 on-call support for security incidents and escalations

  • Ensure compliance with Zero Trust cybersecurity principles and support agency adoption of zero trust network architectures



Requirements:


  • Must Be Able to Obtain Public Trust Level 6C

  • Bachelor's Degree in Physics, Mathematics, Information Technology, Computer Science, Business, or related discipline

  • Minimum of 5 years of professional experience in cybersecurity, information assurance, or related technical roles.

  • Demonstrable expertise in NIST RMF, NIST 800-53, NIST 800-37, and DHS 4300A requirements

  • Knowledge and experience of information security practices within federal and/or state government environments.

  • Excellent written and oral skills

  • Ability to work on-site in Crystal City, Virginia,1 day per week


Preferred Additional Skills and Qualifications:

  • CISSP, CCSK, GCIH, or other advanced cybersecurity certification

  • Experience with FedRAMP, FISMA, or other federal compliance frameworks

  • Hands-on experience with vulnerability assessment tools (Nessus, WebInspect, Qualys, etc.)

  • Experience in Zero Trust architecture design and implementation

  • Knowledge of cloud security (AWS, Azure, GCP) and containerized environments

  • Experience working with Security Operations Centers (SOCs) and incident response teams

  • Demonstrated success working with Agile/DevSecOps practices and sprint-based development environments



Benefits


Xpect Solutions, Inc. is a one-of-a-kind employer with a talented team that is cleared at various levels and is certified in dozens of industry-recognized certifications. Our talented staff are the key to our success. They bring the knowledge, experience and technical skills to deliver the best solutions to our customers.


We support our team by providing open communication, win-win partnerships with clients and vendors, a team-oriented culture that supports an employee focus on professional development and growth for a long-lasting and happy career.


We offer a benefits package that is designed to keep our most important assets – our employees – healthy, happy, energized and moving forward. Our philosophy is simple – empower our employees with the benefits, resources and the financial incentives they need to be successful.


Benefits and Perks:


  • A competitive Medical, Dental, and Vision plan

  • Retirement Savings Plan

  • Life Insurance

  • AD&D Insurance

  • Short Term and Long Term Disability Insurance

  • 3 weeks of annual PTO

  • 11 days of Holiday PTO

  • Performance Awards

  • Referral Bonus Plan (of up to $2,500/year)

  • Education Reimbursement/Training (of up to $2,500/year)




#CJ

Apply Now

Refer to a Friend



Copyright 2026 Xpect Solutions. All rights reserved.


Powered by ApplicantStack™ Applicant Tracking
Privacy Policy | Terms of Use


group id: RTX147f67