> Markdown version of [/jobs/ext/135557-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/135557-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** JMA Resources, Inc. - **Location:** Mechanicsburg, PA, United States (Remote available) - **Experience:** Experienced - **Salary:** $83,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Comptia Cloud+, CompTIA Security+, Cyber Security, Information Systems, Disaster Recovery, Federal Information Processing Standards (FIPS), Intrusion Detection Systems, Software Vulnerability Management, Firewalls (Computer Science), SC Clearance, Information Technology, Vulnerability Analysis - **Published:** May 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4cbc652fa84f8de1 ## About the Role Do you have experience in Vuls?, * Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required. Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines., * 3 or more years of experience supporting DIACAP and/or RMF activities, with RMF experience preferred. * Experience supporting RMF testing, analysis, and documentation needed to complete RMF package submissions. * Experience performing vulnerability risk analysis based on deficiencies identified during RMF testing or security assessments. * Experience using IA tools and scanners to evaluate the security posture of a system or enclave. * Experience with Enterprise Mission Assurance Support Service, or eMASS. * Familiarity with federal IT security standards and guidance, including FISMA, FIPS, NIST Special Publications, and NIST SP 800-37. * Understanding of the RMF process in accordance with the Navy RMF Process Guide. * Current certification in at least one of the following, as required by contract: CAP, CND, CompTIA Cloud+, GSLC, or CompTIA Security+. * Strong technical writing skills, including the ability to prepare, review, and maintain security documentation. * Strong verbal and written communication skills. * Strong problem-solving skills and attention to detail. * Ability to work independently and collaboratively with technical and program teams. Preferred Qualifications: * Degree in Computer Science, Cybersecurity, Information Technology, or a related field. * Experience supporting Navy cybersecurity, A&A, or RMF activities. * Experience with security technologies such as firewalls, intrusion detection systems, intrusion prevention systems, and vulnerability assessment tools. * Experience supporting POA&M development, tracking, remediation, and closure. Creating an Environment of Respect and Opportunity ## Description JMA Resources is seeking an Information Systems Security Officer to support Risk Management Framework activities for information systems within a Navy environment. This role supports security control implementation, assessment, documentation, vulnerability management, and remediation activities. The ISSO works closely with PMO, Operations, and IT Security teams to support Authorization and Accreditation efforts, POA&M management, and ongoing security compliance., * Support security control implementation, testing, and assessment activities in alignment with the Risk Management Framework. * Assist with reviewing, documenting, mitigating, and closing system vulnerabilities through the appropriate change control and remediation processes. * Support Authorization and Accreditation activities, including security requirements review, documentation support, and package preparation. * Review, update, and maintain RMF cybersecurity documentation, including documentation related to POA&Ms, security controls, assessment results, and remediation activities. * Perform vulnerability risk analysis based on deficiencies identified during testing, scanning, or assessment activities. * Use IA tools, scanners, and security technologies to help evaluate the security posture of systems or enclaves. * Coordinate with PMO, Operations, and IT Security teams to support A&A activities and POA&M remediation. * Prepare or contribute to security assessment reports that document assessment results, findings, risks, and recommended corrective actions. * Support planning and coordination for incident response, business continuity, disaster recovery, vulnerability reporting, and threat reporting processes. * Write, edit, and maintain IT security documentation in alignment with applicable federal and DoD cybersecurity requirements. * Carry out other related duties as assigned, demonstrating flexibility and adaptability in meeting evolving client, platform, and company needs. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)