Haystack
← Back to Jobs
Employee
Technology
NC

Information System Security Officer (ISSO) — Senior with Security Clearance

Neuma Consulting LLCWashingtn, DC🇺🇸United StatesPosted 26 Aug 2026

Quick Overview

Seniority
Mid Senior
Employment type
Employee
Work mode
On Site
Location
Washingtn, DC, United States
Posted
Yesterday
Agile

Job Description

Information System Security Officer (ISSO) — Senior Clearance Required: Active TS/SCI (recent CI Polygraph strongly preferred) Location: Onsite —
SCIF support required (Reston, VA or JB Anacostia–Bolling, Washington, DC) Contract: Defense
Intelligence Agency (DIA) | 5-year contract through 2030 Start Date: Immediate About Neuma Consulting At Neuma Consulting LLC, we believe that inspired lives produce inspired solutions.

As a minority-owned, mission-driven government consulting firm based in Northern Virginia, we partner with defense and intelligence agencies to revolutionize how intelligence is produced, visualized, disseminated, and consumed. We are intentional about building an environment where talented people can do their best work—professionally and personally—while delivering high-impact solutions to some of the nation's most critical missions.

Our Values • Relational Integrity – We operate with honesty, trust, and respect in every interaction. • Collective Ingenuity – We believe the best solutions emerge from collaboration and diverse perspectives. • Intentional Stewardship – We thoughtfully manage our time, talent, and resources to deliver lasting value. • Creative Rest – We recognize that balance and rest are essential to sustained creativity and performance. • Transforming Generosity – We go beyond expectations for our teammates, our customers, and our community. • Fun! – We take pride in our work and believe enjoying the journey matters.

The Opportunity Neuma Consulting is hiring a Senior Information System Security Officer (ISSO) to support the
Defense Intelligence Agency (DIA) on a recently awarded 5-year contract, offering long-term stability and a central role in keeping the EPD application ecosystem authorized, monitored, and mission-ready. The EPD environment spans shared enterprise services, cross-domain data movement, and a flagship application used across the Intelligence Community—all while the platform migrates from virtual machines to a fully containerized architecture.

As the systems evolve, you will own the security authorization and continuous monitoring that keep them operating, serving as the day-to-day security lead and the primary interface between our engineering teams and the government security stakeholders.

What You'll Do • Serve as ISSO for assigned EPD systems, executing assessment and authorization activities under the Risk Management Framework (RMF) in accordance with ICD 503 and NIST SP 800-53 • Develop and maintain the full security authorization package: System Security Plans (SSPs), security assessment support, contingency plans, incident response plans, configuration management plans, and POA&Ms • Manage the POA&M lifecycle—track findings, coordinate remediation with developers and DevOps, validate closure, and report status to the ISSM and government stakeholders • Run continuous monitoring: review vulnerability scans, audit logs, and STIG/configuration compliance across VM and containerized environments; report deviations and drive fixes • Maintain system records and artifacts in the customer's governance tool of record (e.g., XACTA/eMASS) • Perform security impact analyses for system changes—including the VM-to-container migration and cross-domain (high-to-low) transfer processes—and participate in change control boards • Support security assessments and audits; prepare evidence and coordinate assessor engagement • Lead incident response coordination for assigned systems, including reporting per DIA requirements • Advise engineering teams on classification handling, need-to-know (NTK) enforcement, least privilege, and secure configuration • Review server logs and consoles onsite to support security triage of production issues Environment: JWICS, RMF/ICD 503, NIST SP 800-53, XACTA/eMASS, ACAS/Nessus, STIGs,
Splunk, GitLab CI Pipelines, Docker, OpenShift, MongoDB, PostgreSQL, Redis, Elasticsearch A Great Fit If You: are equally comfortable writing an SSP the government will scrutinize and sitting with engineers to walk through a scan finding, want your compliance work tied to systems the IC actually uses every day, and have experience securing systems through major architecture transitions.

Because the EPD systems exist on JWICS and the work is hands-on in the SCIF, a recent CI Poly is strongly preferred to enable onsite work from day one.

What the Role Requires • Education: Master's degree from an accredited college or university; or a Bachelor's degree from an accredited college or university plus an additional 2 years of related experience • Experience: Minimum 8 years of experience related to the specific labor category (minimum 10 years with a Bachelor's degree) • Active TS/SCI clearance (recent CI Polygraph strongly preferred) • Mandatory: RMF and NIST SP 800-53 expertise; hands-on experience developing and maintaining SSPs, POA&Ms, and full authorization packages; experience with vulnerability management tools and interpreting scan results • DoD 8140/8570 IAM Level II compliant certification (e.g., Security+, CGRC/CAP, CISSP, CISM) • Experience supporting assessment and authorization in DoD or Intelligence Community environments (ICD 503 experience strongly preferred) • Experience with continuous monitoring, STIG compliance, and audit log review • Experience working within collaborative, cross-functional Agile teams • Strong technical writing, leadership, and communication skills • Comprehensive knowledge across key tasks and high-impact assignments, with the ability to plan and lead major technology assignments, evaluate performance results, recommend changes affecting project growth and success, and function as a technical expert across multiple project assignments • Highly Desired: CISSP or CGRC, XACTA or eMASS experience, JWICS experience, container/OpenShift security, cross-domain solution (CDS) experience, Splunk, experience supporting DevSecOps pipelines and automating compliance evidence collection • 100% onsite Reston, VA or JB Anacostia–Bolling, Washington, DC Why Neuma?

At Neuma, you'll find the impact and visibility of a small company combined with long-term mission stability. We value thoughtful leadership, technical excellence, and a culture that supports both performance and balance.

Benefits & Perks • 401(k) with up to 6% company match (immediately vested) • 15 days of paid vacation plus 11 federal holidays • $1,500 annual education and training assistance • Medical, dental, and vision insurance with low deductibles • Company-paid life, short-term, and long-term disability insurance • Flexible work hours (flextime) • Charitable giving match up to $1,000 annually • Quarterly company events and employee referral bonuses Join Us If you're a cleared senior ISSO who wants to own the security posture of systems used across the Intelligence Community—alongside people who value integrity and collaboration—Neuma
Consulting is the place for you.

Similar jobs