> Markdown version of [/jobs/ext/1366375-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1366375-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Mantech International Corporation - **Location:** United States - **Contract:** Permanent contract - **Skills:** Java (Programming Language), PHP (Programming Language), Data Analysis, Software as a Service, Cloud Engineering, Databases, Data Integrity, Data Normalization, Data Security, Federal Information Processing Standards (FIPS), Infrastructure as a Service (IaaS), Identity and Access Management, Information Security Management, JSON, Python (Programming Language), Network Architecture, Office Suite, Platform as a Service (PAAS), Web Platforms, Data Processing, Restful APIs, Api Management, Qualys, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9042637/information-system-security-officer ## About the Role * Hands-on experience with NIST RMF (800-30, 800-37, 800-53, and 800-53A) - practical implementation, not just familiarity. * Demonstrated experience building control packages and drafting implementation statements. * Experience in creating or supporting Security Assessment Plans and Security Assessment Reports. * Experience with Q-Compliance (or the ability to ramp quickly). * Experience interpreting data from vulnerability scanning tools (e.g., Tenable, Qualys) to identify risks in databases and file-processing pipelines. * Understanding network architectures, including SaaS, IaaS, or PaaS environments; experience securing modern, cloud-native web platforms preferred. * Technical background sufficient to collaborate with system owners on design documentation. * SME-level knowledge of NIST SP 800-137 (ISCM). * 1+ years of technical experience with Python, Java, or PHP - sufficient to read, interpret, and understand code to independently verify control implementation and evaluate technical alternate solutions for complex NIST requirements. * 1+ year of experience with a GRC tool (such as CSAM). * Experience with Q-Compliance and/or Q-Audit. * Experience with API testing (REST APIs), JSON payload security, and/or scripting and automation. * Relevant industry certifications (e.g., CISA, CAP, CISSP, Security+). * Must be a U.S. Citizen with the ability to obtain and maintain a Public Trust clearance prior to starting this position. * Must be able to remain in a stationary position 50% and constantly operate a computer and other office productivity machinery, such as a calculator, copy machine and computer printer. ## Description * Categorizes systems (FIPS 199) in coordination with system owners, accounting for high-volume PII/NPI data aggregation risks inherent to organizational data. * Build the control package: apply NIST SP 800-53 controls, develop the SSP, draft implementation statements, and collect evidence validating secure data ingestion and processing. * Guide system owners on writing and resolving implementation statements. * Drive controls to secure status and see them through testing, with emphasis on data integrity, encryption-in-transit (TLS), and Identity & Access Management (IAM). * Partner closely with the Security Assessment Provider/SCA to ensure quality of artifacts and evidence to enable the assessment. * Advise system owners on control prioritization, ensuring alignment with both NIST frameworks and financial regulatory data protection standards (e.g., FFIEC expectations). * Support RMF & A&A: Cyber Risk Framework (CRF) input, Change Request Reviews, POA&M tracking, SA&A Project List, and SOPs/A&A artifacts on a best-effort basis. ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)