(703) Cybersecurity Information System Security Officer (ISSO)
Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future. Position Description: Arlo Solutions is seeking an experienced Information System Security Officer (ISSO) to support the Office of the Under Secretary of War for Acquisition & Sustainment (OUSW(A&S)). This hybrid position supports cybersecurity operations at the Pentagon and Alexandria, Virginia, providing leadership across the full DoD Risk Management Framework (RMF) lifecycle for multiple information systems supporting Controlled Unclassified Information (CUI) through classified environments. The ISSO serves as the primary cybersecurity advisor responsible for ensuring systems remain secure, compliant, and mission-ready by leading Assessment & Authorization (A&A), Continuous Monitoring (ConMon), cybersecurity governance, and risk management activities. The position requires close collaboration with Program Managers, Information System Owners, Engineers, Security Control Assessors (SCAs), Authorizing Officials (AOs), and senior Government leadership to integrate cybersecurity throughout the system lifecycle. Location: Arlington, VA (HybridClearance: Active Top Secret Security Clearance (SCI eligibility preferred) Responsibilities and/or Success Factors: Serve as the ISSM for multiple DoD information systems supporting OUSW(A&S) mission requirements. Lead all phases of the DoD Risk Management Framework (RMF), including system categorization, control implementation, assessment, authorization, and continuous monitoring. Develop and maintain RMF authorization packages, including System Security Plans (SSPs), Security Assessment documentation, Plans of Action & Milestones (POA&Ms), Continuous Monitoring artifacts, and supporting Body of Evidence (BoE). Coordinate Assessment & Authorization (A&A) activities supporting Authorization to Operate (ATO), Interim Authorization to Test (IATT), Authorization to Operate with Conditions (ATO-C), and system reauthorization. Manage Continuous Monitoring (ConMon), vulnerability management, STIG compliance, security control implementation, and cybersecurity reporting. Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official (AO) risk decisions. Coordinate Security Control Assessments (SCAs), validate remediation activities, and ensure timely closure of assessment find...