Information Systems Security Officer (ISSO) Job at Tesla Government, Falls Church, VA

VzY2NXU5YlpkOEcyQ1lLZFpET0xCbWV4UWc9PQ==
  • Tesla Government
  • Falls Church, VA

Job Description

Position: Information Systems Security Officer (ISSO)
Employment Type: Full Time  
Location:
Falls Church, VA (Hybrid role)

The Role: The Information Systems Security Officer (ISSO) is responsible for overseeing the security posture and compliance of Tesla Government customer-facing systems operating in government-regulated environments. This role ensures that systems maintain Authorization to Operate (ATO) by managing compliance activities, validating control implementation, and coordinating security efforts across engineering, DevOps, and security teams.

The ISSO is accountable for the accuracy, completeness, and audit readiness of security artifacts, as well as ongoing monitoring of system security posture. The role works closely with Cloud Security Engineers and DevOps to ensure that controls are implemented effectively and remain aligned with regulatory requirements.

The ISSO operates with a high degree of ownership over compliance outcomes and is responsible for ensuring that systems remain secure, compliant, and audit-ready throughout their lifecycle.

About Us: Tesla Government Inc. (no affiliation with the automotive company) is a rapidly growing small business, located in Falls Church, Virginia. Founded in 2009, Tesla Government seeks to improve how government agencies manage and share information internally and with government and external partners. Our proven agile, outcome-oriented approach delivers results quickly, reducing risk and driving client success.

We offer Flex PTO, flexible work schedule, health benefits, 4% matching on 401k contributions, competitive compensation, and work from home (telework). We have a friendly, active work environment, and our projects make a difference.

Key Responsibilities – Other duties may be assigned

ATO Ownership and Compliance Management

  • Own ATO sustainment activities for assigned systems, ensuring continuous compliance with applicable frameworks (e.g., NIST RMF, FedRAMP, STIGs).

  • Maintain and manage system security documentation, including SSPs, POA&Ms, and control implementation evidence.

  • Ensure traceability between system controls, implementation artifacts, and compliance requirements.

  • Coordinate with stakeholders to prepare for and support audits, assessments, and security reviews.

Security Control Oversight and Validation

  • Ensure required security controls are implemented, documented, and operating as intended.

  • Review control implementations across infrastructure, applications, and operational processes.

  • Validate control effectiveness through testing, review, and collaboration with engineering teams.

  • Identify gaps in control implementation and drive remediation efforts.

Vulnerability and Risk Management

  • Oversee vulnerability management processes, including tracking, prioritization, and remediation of findings.

  • Review scan results (e.g., ACAS/Nessus, STIGs, container scans) and ensure appropriate action is taken.

  • Maintain and manage POA&Ms, ensuring findings are documented, tracked, and resolved in a timely manner.

  • Assess and communicate risk posture to stakeholders.

Continuous Monitoring and Reporting

  • Ensure continuous monitoring activities are executed and documented appropriately.

  • Review system logs, alerts, and security data to validate compliance and detect anomalies.

  • Produce and maintain security status reports and compliance summaries.

  • Ensure ongoing visibility into system security posture for leadership and stakeholders.

Secure Change and Configuration Oversight

  • Review system and application changes to ensure security and compliance requirements are maintained.

  • Ensure that configuration changes align with approved baselines and do not introduce compliance gaps.

  • Collaborate with engineering teams to integrate security requirements into delivery workflows.

  • Identify and escalate risks introduced through system changes.

Incident Response and Security Operations Support

  • Support incident response activities, including documentation, coordination, and reporting.

  • Ensure incidents are properly tracked, investigated, and resolved in accordance with compliance requirements.

  • Validate that incident response processes meet regulatory and audit expectations.

Coordination and Stakeholder Engagement

  • A ct as the primary point of contact for security compliance matters for assigned systems.

  • Coordinate with Cloud Security Engineers, DevOps, and development teams to ensure alignment on security requirements.

  • Engage with government stakeholders, assessors, and auditors during reviews and evaluations.

  • Provide guidance on compliance requirements and security expectations to internal teams.

  • Provide business development expertise to company stakeholders and support leadership planning for security and compliance initiatives

Qualifications

  • Experience supporting or leading ATO processes in government or regulated environments.

  • Strong familiarity with NIST RMF, STIGs, and related compliance frameworks.

  • Experience maintaining security documentation, including SSPs, POA&Ms, and control evidence.

  • Experience with vulnerability management processes and security scanning tools.

  • Understanding of cloud environments (preferably AWS or AWS GovCloud) and associated security controls.

  • Strong understanding of system security concepts, including access control, logging, and configuration management.

  • Ability to interpret and apply regulatory requirements to technical systems.

  • Strong organizational and documentation skills.

  • Ability to obtain or maintain a security clearance.

Preferred Experience

  • ACAS / Nessus

  • STIG compliance validation

  • Splunk, CloudWatch, or similar logging/monitoring tools

  • Experience supporting audits and assessments

  • Familiarity with DevSecOps practices and CI/CD environments

  • CMMC Level 2 practice and assessment requirements

  • FISMA reporting and continuous monitoring requirements

  • FedRAMP continuous monitoring (monthly scanning, annual assessment, significant change requests)

What Success Looks Like

  • Systems maintain ATO with no significant compliance gaps or audit findings.

  • Security documentation is accurate, complete, and audit-ready at all times.

  • Vulnerabilities and risks are tracked, communicated, and resolved effectively.

  • Continuous monitoring activities provide clear visibility into system security posture.

  • Security requirements are consistently applied across system changes and operations.

  • The ISSO is a trusted authority on compliance and security posture for assigned systems.


To apply please submit:

  • Resume

  • Cover Letter


Compensation: The expected initial salary for this role is $205,000 annually. Actual compensation may vary based on factors including, but not limited to, job-related knowledge and skills, education, experience, certifications, geographic location, and organizational needs. Individual compensation will be determined on a case-by-case basis.

In addition to base salary, Tesla Government offers a comprehensive benefits package, which includes medical, dental, and vision insurance, retirement savings options, paid time off, paid holidays, and professional development opportunities.

Tesla Government Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.

Job Tags

Full time, Local area, Remote work, Work from home, Flexible hours

Similar Jobs

Northeast Healthcare Recruitment, Inc.

Outpatient Internal or Family Medicine Physician Job at Northeast Healthcare Recruitment, Inc.

 ...outpatient with minimal call Work Environment: Outstanding team environment focused on community health Accepting 2027 Graduates Visa Sponsorship: J1 or H1B visa eligibility Compensation & Benefits: Salary $239,000 -$253,5000 Competitive benefits... 

CA High Speed Rail Authority

Attorney IV Job at CA High Speed Rail Authority

 ...Job Description and Duties Attorney IV Under general direction of an Attorney Supervisor at the California High-Speed Rail Authority...  ...about the job in the . Working Conditions Part-time telework is available for this position for California residents... 

Air Education Inc.

Remote English Tutor — U.S. Elementary Schools Job at Air Education Inc.

 ...engagement and growth. Required qualifications Bachelors degree or higher. Authorization to work in the United States....  ...Preferred qualifications (not required) Bilingual in Spanish and English. Degree or coursework in education, literacy, English, or a... 

Pack to the Future LLC

Driver Helper Job at Pack to the Future LLC

 ...Pack to the Future is looking for reliable Delivery Driver Helpers to assist our drivers with delivering packages to customers. We are an...  ...loading and unloading packages Work 4-5 days per week with shifts up to 10 hours Deliver products up to 55lbs. to customers in a... 

Strike

Drilling Crew Member - Class A CDL Job at Strike

 ...family of companies, is known for installing cathodic protection systems for owner - operators of underground pipeline infrastructure as well as oil and gas production companies. Job Responsibilities: Perform duties assigned by the Foreman. Safely drive CMV trucks...