Information Systems Security Officer; ISSO – FedRAMP/DoD IL| Active Secret | Herndon, VA
Listed on 2026-03-05
-
IT/Tech
Cybersecurity, Information Security
38
North Security is the world’s most experienced, technically expert, cloud advisory team. Since the inception of cloud computing, we have helped organizations around the world take secure, compliant advantage of the cloud to power modern business. From tech start-ups to Fortune 500 companies, our impressive client portfolio includes government, major healthcare organizations, cloud service providers, and security vendors, with many at the forefront of innovation and disruptive technology.
Our goal is to become the preeminent cloud security engineering and compliance advisory team, in the US and internationally, trusted by the world’s most demanding cloud-centric organizations. At 38
North, you will work with senior FedRAMP, DoD, and cloud security experts in a disciplined, technically rigorous advisory environment. You will be expected to continuously advance your technical and consulting capabilities while contributing to corporate initiatives that support our growth.
In exchange, we offer competitive compensation (commensurate with experience) and the opportunity to operate in a high-accountability, assessment-focused organization that prioritizes technical quality and defensible outcomes.
About the RoleThis position is on-site full-time(Monday through Friday) in Herndon, Virginia. No exceptions.
38
North is seeking a senior-level Information Systems Security Officer (ISSO) to support a FedRAMP High + DoD Impact Level 6 (IL6) cloud environment.
This role will serve as the on-site security authority for the IL6 system, responsible for day-to-day security operations, continuous monitoring, vulnerability management oversight, and support of DoD authorization activities.
The ISSO will operate within a classified environment supporting IL6 workloads and must demonstrate the maturity, independence, and discipline required to sustain a defensible security posture under DoD oversight.
This position requires hands‑on execution within a structured RMF and DoD Cloud Computing Security Requirements Guide (CC SRG) framework.
Duties and Responsibilities- Serve as the Information Systems Security Officer (ISSO) for the IL6 cloud environment
- Execute day‑to‑day security operations in support of classified IL6 workloads
- Lead continuous monitoring activities in accordance with FedRAMP High and DoD CC SRG requirements
- Oversee vulnerability management processes, including scanning coordination, analysis, and remediation tracking
- Develop, maintain, and manage Plans of Action and Milestones (POA&Ms)
- Prepare and submit monthly continuous monitoring (CONMON) artifacts to DISA
- Support formal assessments, audits, and authorization activities
- Maintain and update system security documentation as required
- Interface directly with engineering teams, leadership, and DoD stakeholders
- Provide authoritative guidance on control implementation, risk posture, and remediation strategy
- Minimum of 10 years of cybersecurity, federal compliance, or classified systems security experience
- Prior experience serving as an ISSO for DoD or federal systems
- Demonstrated experience supporting FedRAMP High environments
- Experience operating within DoD Cloud Computing Security Requirements Guide (CC SRG) environments; IL6 experience strongly preferred
- Strong working knowledge of RMF processes and continuous monitoring programs
- Active DoD Secret security clearance required at time of hire. Clearance must remain in good standing for the duration of employment
- Must be eligible for and maintain access to DoD Impact Level 6 (IL6) classified information environments
- NIST SP 800-53 and FedRAMP (High baseline requirements)
- NIST SP 800-37 (RMF)
- DoD Cloud Computing Security Requirements Guide (CC SRG), including IL6 overlays
- Vulnerability management lifecycle oversight
- POA&M development and remediation tracking
- Security documentation maintenance (SSP updates and supporting artifacts)
- Experience interfacing with DISA or DoD assessment authorities
- Understanding of secure cloud architectures in high‑assurance environments
- Experience supporting secure implementation of enterprise cloud…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).