> Markdown version of [/jobs/ext/1229492-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1229492-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Kratos Defense & Security Solutions, Inc. - **Location:** White Sands, NM, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software Applications, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Data Processing, SC Clearance, Nessus, Plan of Action and Milestones - **Published:** July 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9023009/information-system-security-officer-isso ## About the Role * Bachelor's Degree (engineering or another technical discipline) with 3+ years of experience in Cybersecurity Domain or Non-Degree with 8+ years of experience in Cybersecurity Domain * Experience with implementing and evaluating DoD STIG requirements, NIST RMF, IAVMs and Cybersecurity assessment tools (ACAS, Nessus, SCC, STIG Viewer) * Knowledge of the Risk Management Framework (RMF) process and NIST security controls * Knowledge of information system architecture and standards as they apply to cyber security * Knowledge of NIST SP 800-160, Systems Security Engineering * Minimum 8570 IAM I Certification (i.e. CAP, GSLC, Sec+ CE, etc.) * US Citizen * Active Secret Clearance or eligibility to obtain (and maintain) a Secret Clearance, * Ability to travel occasionally for work duties ## Description 5-D Systems, Inc. a KRATOS company, is seeking a highly motivated candidate to fill an ISSO position at WSMR. The WSMR ISSO will support an Army Project Office providing ISSO support to an Army Test Team. The ISSO will be a key member of a team performing Hardware and Software Cybersecurity analysis along with key functions supporting the Risk Management Framework (RMF) Assessment and Authorization (A&A) process for data processing, test, and tactical systems. Duties include, but are not limited to: * Provide accurate technical evaluations of the equipment, software applications, full systems, or network and documenting the security posture, capabilities, and vulnerabilities against applicable NIST controls. * Selecting and assessing security controls, timely completion of accreditation packages, formulating and implementing mitigations and maintaining the security posture of systems. * Must have experience with eMASS and initiating, updating, and maintaining RMF packages. * Identify, assess, make risk mitigation recommendations, and document system security threats/risks throughout a system's lifecycle; validate system security requirements; formulate and maintain documentation and system certification and accreditation activities (planning, testing, assessing and coordinating). * Ability to work with system developer to update, maintain, and track RMF and POA&M documentation. * Documenting preliminary or residual security risks for system operation and manage and approve Authorization Packages. * Monitoring and evaluating a system's compliance with Department of Defense (DoD) security, resilience, and dependability requirements including performing validation steps, comparing actual results with expected results, and analyzing the differences to identify impacts and risks at the software application, system, and network levels. * Work with teams to provide solutions and to ensure continued functionality of systems within DoD RMF Framework. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)