Information System Security Officer (ISSO)/Support Specialist
SkyePoint DecisionsAbout the role
Overview
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.
Join the SkyePoint team and become part of a highly skilled, professional workforce dedicated to delivering mission-critical solutions. Our exceptional technical experts provide innovative services and solutions to federal agencies, making a meaningful impact every day. At SkyePoint, we value top talent and foster an environment where your ideas and contributions truly matter. Be part of a team that values excellence and rewards innovation—your future starts here!
This is a contingent position based upon customer approval and funding.
Responsibilities
SkyePoint Decisions is seeking an Information Systems Security Officer (ISSO)/Support Specialist for our customer. This person will serve as the day-to-day security owner for assigned information systems, providing essential governance and compliance expertise that bridges technical security operations with federal authorization requirements. This role is central to the mission of transforming cybersecurity from reactive compliance activities to proactive risk management that enables mission success. The ISSO Support Specialist maintains System Security Plans (SSPs) and Authority to Operate (ATO) packages while partnering closely with technical teams to ensure security controls are effectively implemented and continuously monitored. This position serves as the crucial liaison between the customer's technical capabilities and the formal Assessment & Authorization (A&A) process, helping to streamline the path toward Continuous ATO (c-ATO) operations.
This position is onsite in Beltsville, MD. This person may be required to occasionally travel to Washington, DC office.
Responsibilities:
System Security Governance & Documentation:
- Develop, maintain, and update System Security Plans (SSPs) and ATO artifacts for assigned information systems
- Prepare comprehensive Assessment & Authorization (A&A) submissions and continuous ATO (c-ATO) evidence packages
- Create and maintain security control implementation documentation aligned with NIST SP 800-53 requirements
- Coordinate with system owners, developers, and technical teams to ensure accurate security posture documentation
- Support security assessments and respond to auditor inquiries with detailed evidence and remediation plans
Continuous Monitoring & Risk Management:
- Perform ongoing security monitoring activities to maintain approved operational security posture for assigned systems
- Review audit logs and vulnerability evidence to validate security control effectiveness
- Create, track, and manage Plans of Action and Milestones (POA&Ms) from identification through closure
- Coordinate with Vulnerability Management and Remediation teams to ensure timely resolution of security findings
- Generate regular reports on security safeguard status and maintain comprehensive ATO documentation
Proactive Vulnerability & Risk Response:
- Proactively address system risks and vulnerabilities before they become compliance violations or security incidents
- Prioritize vulnerabilities based on potential impact and exploitability to recommend effective mitigation strategies
- Ensure systems are patched and securely configured according to Security Technical Implementation Guides (STIGs)
- Work with Engineering teams and IT operations to implement security patches and configuration changes
- Validate that remediation efforts effectively address identified security flaws and control weaknesses
Stakeholder Coordination & Integration:
- Serve as primary security advisor to system owners and business stakeholders
- Coordinate security changes with Engineering teams and IT operations personnel
- Interface with A&A team to provide automated evidence and compliance data
- Collaborate with SOC teams to ensure security monitoring requirements are properly implemented
- Participate in Purple Team exercises by providing system-
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s