LMI is a nonprofit business that was established in 1961 to address complex issues throughout the federal government of the United States. LMI is headquartered in McLean, Virginia
Cybersecurity Information System Security Officer – ISSO
Location
United States
Posted
24 days ago
Salary
$111.4K - $192.9K / year
Seniority
Senior
Job Description
Cybersecurity Information System Security Officer – ISSO
LMI
• Responsible for the day-to-day security operations of one or more information systems • Maintaining the system’s Authorization to Operate (ATO) under the DoD Risk Management Framework (RMF) • Serve as the primary point of contact for the ISSM, the Authorizing Official’s representative, and the engineering team on all matters of system security • Develop and maintain the full body of RMF artifacts—System Security Plan (SSP), Security Assessment Plan (SAP), Plan of Action and Milestones (POA&M), Continuous Monitoring strategy, Privacy Impact Assessment, and Contingency Plan • Shepherd packages through eMASS or equivalent • Track vulnerabilities, IAVMs, and STIG compliance; manage POA&M closure; coordinate audits and assessments; review system changes for security impact • Translate policy (NIST 800-53, CNSSI 1253, DoDI 8500.01, 8510.01) into clear engineering guidance • Proactively solve unusual and/or complex problems with little or no direction given • Operate effectively in a fast-paced technical environment supporting senior military leadership • Partner closely with the Cybersecurity Engineer, the engineering team, and government stakeholders to keep the system secure, compliant, and operational
Job Requirements
- Active Secret clearance required with the ability to obtain and maintain a Top-Secret clearance
- Minimum of 3-years of experience as an ISSO, ISSM, or equivalent role on DoD information systems
- Demonstrated experience taking systems through the RMF process and achieving/maintaining ATO
- Hands-on experience authoring and maintaining SSPs, SARs, POA&Ms, and Continuous Monitoring documentation
- Working knowledge of NIST SP 800-53, NIST SP 800-37, CNSSI 1253, and applicable DoD/CJCS issuances
- Experience using eMASS, Xacta, or equivalent governance, risk, and compliance (GRC) tooling
- DoD 8570/8140 IAM Level II certification (Security+ CE, CAP, CASP+, or equivalent) at time of hire
- Active DoD Top-Secret Clearance (Desired)
- Bachelor’s or Master’s Degree in Cybersecurity, Information Systems, or related field (Desired)
- DoD 8570/8140 IAM Level III certification (CISSP, CISM, or equivalent) (Desired)
- Experience supporting Special Operations, Intelligence Community, or Combatant Command customers (Desired)
- Experience with cloud ATOs in Azure Government, AWS GovCloud, or Microsoft 365 GCC High (Desired)
- Familiarity with DevSecOps, CI/CD security gates, and continuous ATO (cATO) approaches (Desired)
- Prior experience as a Security Control Assessor (SCA) or assessment team member (Desired)
Benefits
- High Fringe/Full-Time
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Secure how Life360 accesses frontier models. Design, build, and iterate the access controls, policy enforcement, and authorization patterns that govern how systems interact with the frontier models they rely on. • Build secure patterns for MCP access and tool use authorization. Build and own the controls that vets, risk-tier, and govern how we integrate with external tools and services via MCP as adoption expands across engineering teams. • Design and build the identity and authorization model for autonomous agents: service identities, scoped credentials, and least-privilege access patterns. Define and enforce the trust boundaries that govern how agents interact across orchestration chains. • Design and build agentic observability and adversarial defenses. Build the telemetry pipelines and behavioral monitoring that provide visibility into AI system behavior. Implement architecture-level defenses against prompt injection and related adversarial attack classes. • Shape security for the common AI end-user platform. Lead design reviews, build access controls, data boundary enforcement, and abuse detection that keep a shared AI environment safe across users with different privilege levels. • Secure the shared knowledge layer. Define access control and data governance for retrieval augmented and reasoning systems, ensuring AI-powered tools don't surface sensitive data to the wrong systems or users. • Build AI supply chain integrity into the platform. Develop model provenance practices, service vetting, and dependency controls that keep the AI stack trustworthy as it grows. • Partner with Privacy, Legal, and Data Platform to ensure the right controls are built into pipelines handling real-time location, family relationship data, and data involving minors.
• Own the security strategy for frontier model access and MCP governance. Define how we securely connect to frontier models and external tool integrations: the risk framework, the authorization architecture, and the escalation model before those patterns harden at scale. Set the direction that builders implement within • Architect the identity and trust model for non-human agents. Define how agents authenticate, how trust is established and revoked across orchestration chains, and how the model evolves as agent capabilities expand, covering service identities, scoped credentials, and least-privilege access patterns across the platform. • Set the adversarial defense posture for AI systems in production. Define our approach to prompt injection defense, adversarial input handling, and behavioral monitoring patterns and establish the detection philosophy, telemetry requirements, and response framework the team builds and operates within. • Shape security architecture for the common AI end-user platform. Lead design reviews and build the access controls, data boundary enforcement, and abuse detection that keep a shared AI environment safe across an employee population with varying privilege levels. • Secure the shared knowledge layer. Define access control and data governance for retrieval and reasoning, ensuring AI-powered tools don't inadvertently surface sensitive data to the wrong systems or users. • Build AI supply chain integrity into the platform. Develop model provenance practices, service vetting, and dependency controls that keep the AI stack trustworthy as it grows. • Partner with Privacy, Legal, and Data Platform to ensure the right controls are built into pipelines handling real-time location, family relationship data, and data involving minors.
Senior AI Security Researcher
NVIDIANVIDIA uses AI tools in its recruiting processes. NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
• Develop and answer open-ended AI security research questions that helps NVIDIA understand, measure, and reduce risk in frontier models, agentic systems, AI platforms, and AI-enabled products. • Develop practical methods, prototypes, evaluations, or tools that reveal how AI systems can fail under adversarial conditions and how those risks can be mitigated. • Explore a range of AI security problems, such as LLM and agent security, adversarial testing, model evaluation, cyber-defense automation, vulnerability discovery, secure deployment, or autonomous response. • Translate research into usable outcomes for engineering and security teams, including proof-of-concept demonstrations, benchmarks, technical guidance, mitigations, and secure-by-design recommendations. • Collaborate across offensive security, product security, AI research, platform, cloud, and infrastructure teams to connect research insights with NVIDIA's highest-impact security priorities. • Help shape NVIDIA's AI-security research strategy by mentoring others, identifying emerging risks, and building repeatable practices for evaluating and defending AI systems.
• Lead the development of security architecture guidance and standards • Assess and evaluate security postures and identify protection needs • Develop and deliver reports and strategic enterprise solutions • Support risk management and compliance activities


