HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    TO

    Toyon Research Corporation

    Senior Information Systems Security Officer (ISSO)

    Arlington, United StatesOn-SiteFull-timePosted 2w ago
    All Toyon Research Corporation jobs

    Job description

    US Citizenship is Required. Ability to qualify for a US Department of Defense security clearance required. Candidate must be SAP program eligible.

    This position is in-person in our Arlington, VA office.

    Toyon Research Corporation is seeking a Senior ISSO to lead the full Risk Management Framework (RMF) lifecycle for assigned information systems, from security categorization through authorization and continuous monitoring. This is a hands-on, customer-facing role — the successful candidate will be comfortable wearing multiple hats, collaborating closely with a small team, and engaging directly with DoD CIO Security Control Assessors (SCAs) and internal stakeholders with a service-oriented mindset. The role carries responsibility for producing and maintaining RMF artifacts, coordinating remediation across system owners and engineering teams, and providing mentorship on RMF, compliance, and risk management best practices.

    Responsibilities

    • Lead the full RMF lifecycle for assigned systems: security categorization, control implementation, assessment, authorization, and continuous monitoring
    • Develop and maintain RMF artifacts, including SSPs, SARs, POA&Ms, Security Impact Analyses, Contingency Plans, and ATO documentation
    • Conduct vulnerability assessments using tools such as Tenable Nessus, SCAP Compliance Checker, and STIG Viewer
    • Validate compliance with DISA STIGs, CIS Benchmarks, NIST SP 800-53, and organizational baselines
    • Coordinate remediation efforts with system owners, administrators, and engineering teams
    • Support security monitoring and incident response through Splunk Enterprise, including reviewing audit logs and privileged account activity
    • Assess cloud security configurations in AWS and Microsoft Azure
    • Evaluate network and endpoint security controls
    • Support audits and inspections; manage POA&M tracking
    • Provide cybersecurity guidance and mentorship on RMF, compliance, risk management, and security best practices
    • Interface directly with DoD CIO Security Control Assessors (SCAs)

    Job details are sourced from the employer's original posting.

    Open job posting
    TO

    About the company

    Toyon Research Corporation

    This company's name is a UUID, indicating it might be a placeholder or an internal identifier. Further information is needed to determine its business.

    View all Toyon Research Corporation jobstoyon.com
    Open roles
    47

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.