← Back to all jobs

Information Systems Security Officer (ISSO)

CACI · VA · Posted 2026-09-03

Apply on the company site →

Job description

Job Title: Information Systems Security Officer (ISSO) Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local * * * The Opportunity: CACI is seeking an Information Systems Security Officer (ISSO) for the Global Mission Operations Support (GMOS) contract, supporting the Department of State. This role offers a unique opportunity to enhance national security through advanced IT solutions. You will collaborate with experienced professionals in an innovative environment, guiding a high-performing team to deliver excellence. The GMOS contract aims to provide world-class IT support by modernizing and maintaining applications and infrastructure using an integrated IT Service Management approach. Join us to make a meaningful impact on a program of national importance. Responsibilities: • Leads comprehensive security and internal controls maintenance in accordance with DOS policies and procedures across CA IT enterprise supporting 40,000+ users • Maintains comprehensive security-approved thresholds for sites ensuring enterprise compliance with DOS security policies • Leads monitoring and response to vulnerability and threat reports coordinating remediation activities with bureaus and agencies • Provides comprehensive security guidance for service portfolio management ensuring alignment with Federal accessibility standards and compliance requirements • Ensures all infrastructure architecture and standards development align with DOS and Federal security requirements • Ensures all engineering designs for physical and virtual hosting environments incorporate comprehensive security best practices complying with DOS security policies, FISMA requirements, and NIST standards • Leads security compliance for engineering IT services including Exchange, AD, DNS, DHCP, and backup services ensuring alignment with modern security protocols • Provides comprehensive security guidance for network engineering services ensuring secure connectivity and compliance across 350+ facilities • Leads infrastructure audits, assessments, and compliance analysis ensuring system baselines meet DOS and DT/EA/CST security requirements • Possesses and applies a comprehensive knowledge across key tasks and high impact assignments, plans and leads major technical assignments, and functions as a technical expert across multiple project assignments; may supervise others Qualifications: • BA/BS degree and 13+ years of relevant cybersecurity, information assurance, information systems security, or related experience; equivalencies considered. • Active Secret clearance. • Extensive experience serving as an ISSO, ISSM, cybersecurity engineer, or equivalent security professional supporting complex enterprise IT environments. • Demonstrated experience implementing and maintaining cybersecurity requirements in accordance with NIST Risk Management Framework (RMF), FISMA, NIST SP 800-53, and applicable Federal security standards. • Experience supporting the Assessment & Authorization (A&A) lifecycle, including security controls, authorization packages, continuous monitoring, and system reauthorization. • Experience developing and maintaining cybersecurity documentation including System Security Plans (SSPs), POA&Ms, risk assessments, security controls, and authorization artifacts. • Demonstrated experience conducting security assessments, compliance reviews, vulnerability analysis, and continuous monitoring, including tracking findings through remediation and closure. • Experience with enterprise vulnerability management, security monitoring, configuration compliance, and system hardening tools and practices. • Strong understanding of security requirements across enterprise infrastructure, including Windows/Linux, Active Directory, Exchange, network services, virtualization, hosting/cloud environments, and identity and access management. • Experience reviewing system architectures, engineering designs, configurations, and changes to identify cybersecurity risks and ensure security requirements are incorporated throughout the system lifecycle. • Experience supporting incident response, threat management, vulnerability remediation, and security escalation in coordination with technical teams and Government cybersecurity stakeholders. Desired – • Prior cybersecurity experience supporting Federal Government enterprise IT environments, particularly the Department of State. • Familiarity with Department of State cybersecurity policies, security authorization processes, and enterprise security tools. • Experience securing large-scale, globally distributed on-premises, virtualized, hybrid, or cloud environments. • Experience with ServiceNow, SIEM/SOC technologies, EDR, vulnerability management platforms, or comparable enterprise security tools. • Knowledge of Zero Trust Architecture (ZTA) principles and Federal Zero Trust requirements. • Relevant cybersecurity certification such as CISSP, CISM, SecurityX/CASP+, CGRC, CCSP, or equivalent. • ITIL 4 Foundation certification or experience supporting an ITIL-based enterprise service management environment. -What You Can Expect: A culture of integrity. At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation. An environment of trust. CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality. A focus on continuous growth. Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break