Location:Â Ashburn, VA
Clearance:Â Secret Clearance (or able to obtain)
Salary Rate: $150,000-$180,000
Our client is seeking an experienced Information System Security Officer (ISSO) to support a U.S. Customs and Border Protection (CBP) program in Ashburn, VA. The ISSO will serve as the principal point of contact for the security posture of one or more assigned information systems, ensuring compliance with DHS, CBP, and NIST cybersecurity policies throughout the system's lifecycle. This role works closely with the Information System Security Manager (ISSM), Authorizing Official (AO), system owners, and technical teams to maintain a strong Risk Management Framework (RMF) posture and support continuous authorization to operate (ATO).
•    Serve as the primary ISSO for assigned CBP information systems, acting as the liaison between the ISSM, AO, system owners, and technical staff on all security-related matters.
•    Execute the NIST Risk Management Framework (RMF) lifecycle, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring.
•    Develop, update, and maintain security authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Contingency Plans, and Risk Assessments.
•    Support Assessment and Authorization (A&A) activities and coordinate Security Control Assessments (SCAs) with independent assessors.
•    Monitor and track POA&M remediation activities, ensuring vulnerabilities are addressed within DHS/CBP-mandated timeframes.
•    Conduct continuous monitoring activities in accordance with DHS 4300A / CBP security policy and the organization's Information Security Continuous Monitoring (ISCM) strategy.
•    Review vulnerability scan results (e.g., Nessus, ACAS) and coordinate remediation with system administrators and engineering teams.
•    Support incident response activities for assigned systems, including detection, reporting, and coordination with the Security Operations Center (SOC).
•    Ensure system configurations align with applicable security baselines (e.g., DISA STIGs, CIS Benchmarks) and DHS/CBP policy.
•    Participate in Configuration Control Board (CCB) activities to assess the security impact of proposed system changes.
•    Prepare for and support audits, inspections, and compliance reviews conducted by DHS, CBP, or external oversight bodies.
•    Maintain awareness of, and ensure compliance with, applicable federal cybersecurity laws, regulations, and guidance, including FISMA, NIST SP 800-53, and FIPS publications.
•    U.S. Citizenship required.
•    Ability to obtain and maintain a CBP Background Investigation (BI) / Public Trust clearance; existing favorable CBP or DHS suitability determination preferred.
•    Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience in lieu of degree.
•    Minimum of 3–5 years of hands-on experience performing ISSO, ISSM, or comparable information systems security duties on federal information systems.
•    Working knowledge of the NIST Risk Management Framework (RMF), NIST SP 800-37, and NIST SP 800-53 security controls.
•    Familiarity with DHS 4300A Sensitive Systems Policy or equivalent federal agency security policy.
•    Experience preparing or maintaining ATO documentation (SSP, SAR, POA&M, Contingency Plan).
•    Strong written and verbal communication skills, with the ability to translate technical risk into terms understandable to non-technical stakeholders.
Candidates must hold, at minimum, both of the following certifications at time of application (in accordance with DoD 8570.01-M / DoD 8140 IAM Level II requirements):
•    Certified Information Systems Security Professional (CISSP)
•    CompTIA Security+ (CE)
•    Prior experience directly supporting CBP, DHS, or another federal law enforcement/homeland security agency.
•    Additional certifications such as CAP, CISM, CEH, or Cloud+.
•    Experience with cloud environments (AWS GovCloud, Azure Government) and associated FedRAMP/ATO requirements.
•    Experience with GRC and vulnerability management tooling (e.g., Xacta, CSAM, Nessus/ACAS, Splunk).
•    Active DHS/CBP Entry-on-Duty (EOD) or current CBP suitability determination.
Learn more about this Employer on their Career Site
