> Markdown version of [/jobs/ext/1010794-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1010794-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Applied Information Sciences, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $101,000.0 - $152,000.0 - **Contract:** Permanent contract - **Skills:** Software Documentation, Cyber Security, Information Security Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Nmap, HP WebInspect, Information Technology, Tenable Nessus, Splunk, Service Stack, Vulnerability Analysis - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e31c2d39306059c3 ## About the Role Do you have experience in Vulnerability scanning implementation?, Do you have a Bachelor's degree?, * Minimum 5+ years of ISSO or ISS Engineer experience in a cleared environment * Minimum 5+ years of experience in cybersecurity or a related technical field * Bachelor's degree in Cybersecurity, Computer Science, IT, or related field. An additional 4 years of experience will be considered in lieu of a degree. * DoD 8570/IAT Level III certification or equivalent (e.g. Security+) * Hands-on experience with tools such as: + Tenable Nessus / Security Center + Splunk + IBM Guardium + HP WebInspect + NMAP or similar tools * Strong understanding of: + RMF (Risk Management Framework) + NIST 800-53 security controls + System accreditation processes * Active Top Secret clearance., * Experience supporting multiple systems through the ATO lifecycle * Familiarity with federal agency compliance environments (DoD, IC, Civilian) ## Description At AIS, we are dedicated to providing our employees with diverse opportunities to grow their careers while supporting a variety of impactful projects. For this position, we are seeking a talented individual to join AIS as a Senior Security Engineer. * Core Knowledge & Skills: Designs secure architectures, leverages advanced threat detection, leads incident response, and implements security automation. * Work & Complexity: Manages complex incidents, conducts threat analysis, leads audits, and implements process improvements. * Quality & Independence: Delivers high-quality reports, aligns practices with industry standards, and operates with high autonomy. * Teamwork & Communication: Leads team projects, collaborates cross-functionally, mentors juniors, and resolves conflicts. * Consulting & Engagement: Provides strategic consulting, leads improvement initiatives, recommends advanced technologies, and manages vendor relationships., The Information System Security Officer (ISSO) is responsible for executing security compliance activities across assigned systems, ensuring adherence to RMF requirements, and supporting authorization efforts. This role requires independent execution of security control assessments, system documentation, and continuous monitoring activities., * Perform documentation, testing, and ongoing assessment of security controls * Ensure complete system scoping, including all assets, components, and technology stacks * Clearly document and articulate control implementation in SSPs and related artifacts * Lead activities supporting system ATOs and reauthorizations * Ensure proper system lifecycle management, including decommissioning activities * Maintain consistent and compliant continuous monitoring practices * Coordinate with ISSMs, engineers, and system owners to resolve security findings ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)