> Markdown version of [/jobs/ext/1219152-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1219152-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Cumberland Additive, Inc. - **Location:** Pflugerville, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Audit Trail, Backup Devices, Configuration Management, Cyber Security, Information Systems, Information Security Management, Data Streaming, Software Vulnerability Management, Data Logging, Information Technology, Plan of Action and Milestones - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=39560bede41bde36 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or Information Systems preferred. Equivalent combinations of education, certifications, and relevant work experience may be considered. * Minimum 2 years of demonstrated cybersecurity or information technology experience supporting CMMC Level 2, NIST SP 800-171, DFARS 252.204-7012, or equivalent CUI cybersecurity compliance requirements; experience in an AS9100D or regulated manufacturing environment preferred. * Working knowledge of CUI handling, access control, MFA, endpoint protection, vulnerability management, incident response, configuration management, backup validation, logging, and account lifecycle management. * Ability to create and maintain SSPs, POA&Ms, policies, procedures, evidence libraries, audit records, and corrective action * Experience coordinating across IT, Quality, Engineering, Operations, HR, Purchasing, Contracts, and external service * Strong documentation discipline and ability to translate cybersecurity requirements into practical manufacturing * Ability to conduct internal reviews, identify gaps, assign corrective actions, and verify closure ## Description The Information System Security Officer (ISSO) is responsible for leading, maintaining, and continuously improving the organization's cybersecurity compliance program. The position serves as the primary coordinator for CMMC Level 2 activities and works across all departments to ensure cybersecurity remains integrated into normal business operations., * Serve as the primary owner and coordinator of the CMMC Level 2 compliance program and C3PAO assessment * Maintain cybersecurity policies, procedures, documentation, and assessment * Coordinate internal reviews, corrective actions, and continuous improvement * Partner with the MSP and internal IT resources to ensure technical security controls remain effective and aligned with business needs. * Support the protection of Controlled Unclassified Information (CUI) and related information * Work with Quality to integrate cybersecurity into the quality management system. * Support external assessments and cybersecurity-related compliance * Provide cybersecurity awareness, guidance, and training across the * Monitor regulatory and contractual cybersecurity requirements and recommend Key Deliverables * Current SSP with accurate system scope, boundary, asset inventory, data flows, control narratives, and * Current POA&M with ownership, due dates, risk notes, remediation status, and closure * CMMC Level 2 evidence library mapped to applicable practices and assessment * Recurring control review calendar and completed review * CUI handling procedure, CUI flow map, and department-specific work * Training matrix and completion records for cybersecurity awareness, CUI handling, and user * Internal audit results, corrective actions, and management review inputs related to * Supplier and external service provider records relevant to CUI handling and cybersecurity ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)