Jobs and Careers
DE
Senior Information System Security Officer (ISSO)
Development InfoStructure(Multiple States), United Statesfull_timeVerifiedPosted 5 Aug 2026
💰 $109,000/yr($99,000/yr – $109,000/yr)
About the role
Join Our Team
Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies such as DevSecOps, AI, and Machine Learning. With over 30 years of experience, we have established ourselves as a trusted partner for government agencies, delivering tailored, mission-critical solutions that drive digital transformation and operational excellence. Our client-centric approach, coupled with our deep domain expertise and technical prowess, enables us to forge enduring relationships and consistently deliver high-impact, adaptive solutions that resonate with the unique needs of the public sector.
About This Role
As a Senior ISSO, you will perform senior ISSO duties for assigned systems and lead an assigned area of the program spanning authorization, continuous monitoring, vulnerability and POA&M management, audit support, and compliance. You will work directly in the agency’s compliance platform rather than around it, and you will be expected to produce artifacts a federal assessor can accept without a round of rework.
What You’ll Do
Maintain Authorization Packages
Areas of Focus
Both positions carry the identical qualification bar and both must be able to assume the Lead ISSO role. They differ only in primary area of ownership, and each area has a trained backup so that no part of the program depends on one person.
What We’re Looking For
Required Qualifications
Education & Experience
Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies such as DevSecOps, AI, and Machine Learning. With over 30 years of experience, we have established ourselves as a trusted partner for government agencies, delivering tailored, mission-critical solutions that drive digital transformation and operational excellence. Our client-centric approach, coupled with our deep domain expertise and technical prowess, enables us to forge enduring relationships and consistently deliver high-impact, adaptive solutions that resonate with the unique needs of the public sector.
About This Role
As a Senior ISSO, you will perform senior ISSO duties for assigned systems and lead an assigned area of the program spanning authorization, continuous monitoring, vulnerability and POA&M management, audit support, and compliance. You will work directly in the agency’s compliance platform rather than around it, and you will be expected to produce artifacts a federal assessor can accept without a round of rework.
What You’ll Do
Maintain Authorization Packages
- Maintain authorization packages, control implementation statements, inheritance records, and POA&M items in CSAM for assigned systems
- Develop and recommend system security categorizations and control baselines, documenting tailoring rationale
- Reconcile inherited controls against current cloud provider and common control provider documentation
- Keep records audit-ready and internally consistent between the compliance platform and supporting repositories
- Execute continuous monitoring plans: recurring security reviews, Splunk log ingestion verification, and monthly posture reporting
- Analyze vulnerability scan results from Tenable, Qualys, and Microsoft Defender; validate findings and document false-positive rationale with supporting evidence
- Coordinate remediation with engineering teams and track POA&M items to closure with bidirectional ServiceNow traceability
- Produce monthly reporting that gives federal stakeholders analysis and recommended action, not raw data extracts
- Prepare security impact analyses for change requests within contract turnaround times
- Support change advisory and change control board meetings, and perform post-change verification
- Analyze proposed changes for significant-change implications and prepare the resulting assessment packages
- Provide ISSO-side incident response coordination: affected-system context from CSAM within one business hour of declaration, situation reports, root cause analysis inputs, and corrective action tracking
- Support audits, assessments, and FISMA reporting through evidence staging, auditor coordination, draft finding responses, and corrective action plans
- Step into Lead ISSO duties during planned and unplanned absences without a drop in service
- Represent the team in agency governance forums when the Lead is unavailable
- Lead internal quality reviews of deliverables when acting in the Lead role
Areas of Focus
Both positions carry the identical qualification bar and both must be able to assume the Lead ISSO role. They differ only in primary area of ownership, and each area has a trained backup so that no part of the program depends on one person.
- Monitoring and Remediation: primary owner of continuous monitoring and security posture management and of vulnerability and POA&M execution, and the coordination point for incident response
- Authorization and Assurance: primary owner of security documentation and artifact management, security impact analysis and change coordination, and audit, assessment, and compliance support, working alongside the Lead ISSO on authorization efforts. Depth in CSAM is prioritized for this position.
What We’re Looking For
Required Qualifications
Education & Experience
- Bachelor’s degree in cybersecurity, computer scienc
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s