> Markdown version of [/jobs/ext/1471460-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1471460-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Mag Aerospace Industries, Inc. - **Location:** Bragg, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, Cloud Computing, Cyber Security, Information Systems, Custom Software, Linux, Federal Information Processing Standards (FIPS), Identity and Access Management, Networking Hardware, Websense, Information Technology - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/43c7f69e-9f27-4b94-abc7-c74ef7a4830b ## About the Role Minimum Requirements Knowledge and Skills * In compliance with DoD Cyber Workforce 8570.01 * Experience in Information Assurance / Cybersecurity, including development, integration, and implementation of cyber security and program protection standards for networking, computers, and custom applications * Thorough knowledge of the Department of Defense 8510.01 Risk Management Framework (RMF) for DoD Information Technology, DoD Instruction 8500.1 Cyber Security, DoD Directive 8140.01, Cyberspace Workforce Management, NIST 800 Special Publications, Federal Information Processing Standards (FIPS), and knowledge of current authorization practices, particularly within the DoD * Experience in creating and maintaining the security configuration baselines for Windows and Linux platforms, networking equipment, cloud technologies, and custom applications (i.e., Minimum Benchmarks: CIS, STIGS) * Provide subject matter expertise, advice and assistance in the planning, implementation, and accreditation of technology and solutions * Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Management Level IAM Level II The minimum years of related experience required: 5+, * The minimum level of education required is: BS in Computer Science or Information Technology (or equivalent experience), * Familiar with DIA assessments and accreditation documentation within the XACTA management platform * Familiar with eMASS - USSOCOM ENTERPRISE MISSION ASSURANCE SUPPORT SERVICES platform * Meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Management Level (IAM Level III) * Ability to read, review, and consolidate ACAS scans, DISA STIGS, and Websense results * Excellent interpersonal skills, including the ability to work on multi-functional teams * Display detailed knowledge and understanding of multiple technology infrastructures * Ability to serve as a principal advisor on all matters, technical and otherwise, involving the security of an IS * Exhibit individual initiative to influence events and achieve goals. Be proactive and a self-starter, going beyond specific job responsibilities to ensure goals and achieved or exceeded * Travel as necessary for customer projects, technology expositions, and corporate meetings ## Description The MAG Team is seeking to hire an experienced Information Systems Security Officer to support the Special Operations community based out of Ft. Liberty (formerly Ft. Bragg), NC! In this role, you will provide a variety of services leveraging the Risk Management Framework (RMF) accreditation. Services are associated with validation, approval, and sustainment of cybersecurity accreditation packages. Additionally, you will performs and analyze a range of Information Security Systems Officer activities and assist with the development and implementation of security policies., Duties include, but are not limited to: * Gather and translate customer requirements, interact with stakeholders from many areas, and lead efforts to ensure customer products and recommendations will meet customer information security policies in an ever-changing technical environment * Categorize the IT and the information processed, store, and transmitted by the system based on an impact analysis due to a loss of Confidentiality, Integrity, and Availability (CIA) impacts * Select an initial set of baseline security controls for the Information System (IS) based on the security categorization; overlay tailoring and supplementing the security control baseline as needed based on an organizational assessment of risk and local conditions * Assess the security control using the appropriate methods and procedures to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome * Authorize the IS based on the determination of the risk to the organizational operations, organizational assets, or to individuals resulting from the operation of the IS and the decision that this risk is acceptable * Monitor the security of the IS on a continuous basis including assessing control effectiveness, documenting changes to the system, conducting security impact analyses of the associated changes, and reporting the security status of the system to appropriate organizational officials on a regular basis * Review, prepare and update RMF authorization packages * Conduct assessments of information security controls to measure the effectiveness of controls and identify any gaps * Manage remediation efforts and report on the status of control deficiencies * Provide security expertise to business units and key stakeholders * Provide timely status updates/reporting on assessments and assigned projects ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)