Senior Information Systems Security Officer (ISSO)
Description

US Citizenship is Required. Ability to qualify for a US Department of Defense security clearance required. Candidate must be SAP program eligible.


This position is in-person in our Arlington, VA office.


Toyon Research Corporation is seeking a Senior ISSO to lead the full Risk Management Framework (RMF) lifecycle for assigned information systems, from security categorization through authorization and continuous monitoring. This is a hands-on, customer-facing role — the successful candidate will be comfortable wearing multiple hats, collaborating closely with a small team, and engaging directly with DoD CIO Security Control Assessors (SCAs) and internal stakeholders with a service-oriented mindset. The role carries responsibility for producing and maintaining RMF artifacts, coordinating remediation across system owners and engineering teams, and providing mentorship on RMF, compliance, and risk management best practices.


Responsibilities

  • Lead the full RMF lifecycle for assigned systems: security categorization, control implementation, assessment, authorization, and continuous monitoring
  • Develop and maintain RMF artifacts, including SSPs, SARs, POA&Ms, Security Impact Analyses, Contingency Plans, and ATO documentation
  • Conduct vulnerability assessments using tools such as Tenable Nessus, SCAP Compliance Checker, and STIG Viewer
  • Validate compliance with DISA STIGs, CIS Benchmarks, NIST SP 800-53, and organizational baselines
  • Coordinate remediation efforts with system owners, administrators, and engineering teams
  • Support security monitoring and incident response through Splunk Enterprise, including reviewing audit logs and privileged account activity
  • Assess cloud security configurations in AWS and Microsoft Azure
  • Evaluate network and endpoint security controls
  • Support audits and inspections; manage POA&M tracking
  • Provide cybersecurity guidance and mentorship on RMF, compliance, risk management, and security best practices
  •  Interface directly with DoD CIO Security Control Assessors (SCAs)
Requirements
  • Associate’s degree in computer science or related field
  • 5 years of experience as an ISSO, ISSE, ISSM, or SCA
  • IAT Level II certification required (Security+ CE at minimum)
  • Strong working knowledge of the Risk Management Framework (RMF)
  • Experience implementing and assessing NIST SP 800-53, FISMA, and DoD cybersecurity requirements
  • Hands-on experience performing vulnerability scanning and remediation using Tenable Nessus
  • Experience administering, securing, or supporting Red Hat Enterprise Linux (RHEL) and Windows Server environments
  • Experience using Splunk Enterprise for security monitoring, log analysis, and incident investigation
  • Experience supporting cloud environments, including Microsoft Azure
  • Experience using eMASS, Xacta, or comparable RMF management tools
  • Excellent written and verbal communication skills, with the ability to communicate technical information to both technical and non-technical stakeholders
  • Willingness and ability to work collaboratively on a small team, covering a broad range of responsibilities


Preferred Qualifications

  • Experience with ACAS, Ansible, or Red Hat Satellite.
  • 8-10 years of experience as an ISSO, ISSE, ISSM, or SCA preferred


The annual pay range for the Security Specialist is $110,000 to $170,000.


The posted pay range values provide the candidate with guidance on annual base compensation for the position, at a full time level of effort, exclusive of overtime, bonus, and benefits-related compensation, over a range of qualifications that may fit hiring objectives. Toyon Research Corporation will consider the individual candidate’s education, work experience, applicable knowledge, skills and training, among other factors, when preparing an offer of employment. 


Equal Opportunity Employer including Disability and Veterans 


Applicant Privacy Notice 


Learn more about our company in our latest video, We are Toyon. 


The application window for this posting will remain open until the position is filled.   


Ref #2692-H