> Markdown version of [/jobs/ext/1312644-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1312644-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** XPECT Solutions Inc. - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Information Systems Security Architecture Professional, Nmap, Information Technology, Tenable Nessus, Plan of Action and Milestones - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/f2453943-7bdd-42d4-8cba-6571ae22be46 ## About the Role * ACTIVE TOP SECRET CLEARANCE * 5+ years serving as an Information Systems Security Officer (ISSO) at a cleared facility * 7+ years of work experience in a computer science or Cybersecurity related field * Hold at least one of the following certifications: + Certified Information Systems Security Professional (CISSP) + Global Information Security Professional (GISP) + CompTIA Advanced Security Practitioner (CASP) * Familiarity with the use and operation of security tools including Tenable Nessus and/or Security Center, IBM Guardium, HP Weblnspect, Network Mapper (NMAP), and/or similar applications Preferred Additional Skills and Qualifications * Bachelor's or advanced degree in Computer Science, Cybersecurity, or other cyber discipline ## Description XPECT Solutions is looking for a Mid-Level Information System Security Officer (ISSO). The Information System Security Officer (ISSO) plays a critical role in ensuring the confidentiality, integrity, and availability of information systems within an organization. Acting as the primary liaison between system owners and cybersecurity stakeholders, the ISSO is responsible for implementing and maintaining security controls, managing risk assessments, and ensuring compliance with federal regulations and organizational policies. This role requires a deep understanding of security frameworks, continuous monitoring practices, and incident response procedures to safeguard sensitive data and support mission-critical operations Core Responsibilities * Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each IS * Provide liaison support between the system owner and other IS security personnel * Ensure that selected security controls are implemented and operating as intended during all phases of the IS lifecycle * Ensure that system security documentation is developed, maintained, reviewed, and updated on a continuous basis * Conduct required IS vulnerability scans according to risk assessment parameters. * Develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities * Manage the risks to ISs and other our customer's assets by coordinating appropriate correction or mitigation actions, and oversee and track the timely completion of (POAMs) * Coordinate system owner concurrence for correction or mitigation actions * Monitor security controls for our customer's ISs to maintain security Authorized To Operate (ATO) * Upload all security control evidence to the Governance, Risk, and Compliance (GRC) application to support security control implementation during the monitoring phase * Ensure that changes to our customer's IS, its environment, and/or operational needs that may affect the authorization status are reported to the system owner and IS Security Manager (ISSM) * Ensure the removal and retirement of ISs being decommissioned in coordination with the system owner, ISSM, and ISSR ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)