> Markdown version of [/jobs/ext/1189014-information-security-officer](https://www.wearedevelopers.com/jobs/ext/1189014-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** IDM Group, LLC - **Location:** Los Angeles, CA, United States - **Salary:** $149,760.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Data Security, Information Security Management, IT Management, Network Security, Software Vulnerability Management, Google Cloud, Software Security, RSA Archer Platform, Servicenow, Vulnerability Analysis - **Published:** July 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3e7d316c8771a6d4 ## About the Role * Proven experience as an Information System Security Officer, cybersecurity compliance analyst, security assessor, or similar cybersecurity role. * Strong knowledge of NIST Risk Management Framework, NIST Cybersecurity Framework, NIST 800-53, and related standards. * Experience with security compliance frameworks, including NIST CSF 2.0, NIST 800-53, and NIST SP 800-161. * Experience developing and maintaining SSPs, POA&Ms, security policies, procedures, risk registers, and audit documentation. * Familiarity with vulnerability management tools, security assessments, remediation tracking, and risk reporting. * Strong understanding of network security, application security, data security, and enterprise IT security principles. * Ability to communicate effectively with technical teams, business stakeholders, auditors, and leadership. * Strong analytical, documentation, organizational, and problem-solving skills. * Ability to work onsite and support a 1-year engagement. Preferred Qualifications * Experience with ServiceNow GRC or similar GRC platforms. * Knowledge of cloud security concepts and environments such as Azure, AWS, or Google Cloud Platform. * Relevant cybersecurity certifications such as CISSP, CISM, CISA, Security+, or similar. * Prior experience supporting enterprise, government, transportation, aviation, or highly regulated environments., The ideal candidate is detail-oriented, documentation-focused, and experienced in cybersecurity compliance, risk management, and security authorization processes. This person should be comfortable working across technical and non-technical teams, supporting audit readiness, tracking security risks, and helping maintain compliance with established cybersecurity frameworks. ## Description We are seeking a qualified Information System Security Officer (ISSO) to support cybersecurity, compliance, risk management, system authorization, and continuous monitoring activities for an enterprise IT environment. The selected candidate will work closely with cybersecurity leadership, IT teams, auditors, system owners, and business stakeholders to help strengthen the organization's security posture and maintain compliance with applicable security standards and regulatory requirements., * Support Risk Management Framework (RMF) processes and the system authorization lifecycle. * Create and maintain system security baselines using NIST 800-53 security controls. * Develop, review, and maintain security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, procedures, and related compliance documentation. * Perform security control assessments, validation activities, and compliance reviews. * Support governance, risk, and compliance activities using GRC platforms such as ServiceNow GRC. * Ensure alignment with applicable cybersecurity frameworks and standards, including NIST, ISO 27001, PCI, TSA, and other regulatory requirements. * Conduct vulnerability assessments and track remediation activities through the risk registry. * Work with system owners and technical teams to identify, document, assess, and mitigate security risks. * Monitor systems for compliance with approved security baselines, policies, and procedures. * Support audit readiness activities and assist with responses to audit findings. * Coordinate with appropriate teams on incident response activities and ensure proper reporting and documentation. * Provide security guidance, awareness, and recommendations to technical and non-technical stakeholders. * Prepare regular status updates, risk reports, compliance summaries, and documentation for management review. * Collaborate with cross-functional teams to improve cybersecurity controls, processes, and overall security posture. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)