> Markdown version of [/jobs/ext/1506159-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1506159-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** KBR Inc - **Location:** Bethesda, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $128,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Software System Penetration Testing, User Authentication, Cyber Security, Information Systems, System Configuration, Desktop Virtualization, HP Thin Clients, Hyper-V, Information Security Management, Network Security, Linux Servers, Uptime, Windows Servers, Network Architecture, Node.Js, Zero Trust Network Access, Risk Management Information Systems, Security Information and Event Management, Virtualization Technology, Wide Area Networks, Firewalls (Computer Science), Information Technology, SolarWinds (Software), Network Support, Splunk, Server Operating Systems & Platforms, McAfee EPolicy, User Administration, Vulnerability Analysis, Vmware - **Published:** July 30, 2026 - **Apply:** https://dejobs.org/x/x/94900DBAA08543869A235C210D459DDE/job/ ## About the Role Required: * Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field * Certifications: CISSP, CISM, CASP, Security+ * Security Clearance: Active TS/SCI * Experience: Minimum 10 years of system administration or cybersecurity-related experience, specifically within DoD environment. * Technical Skills: * Proficient in Windows server and Linux server management, including installation, security policies, configuration, and troubleshooting. Desired: * Education: Master's degree in computer science, Information Technology, Cybersecurity, or a related field. Advanced degrees or certifications (CISSP, CISM, CASP, Security+) * Virtual Desktop Infrastructure: Horizon, UAG, Provision and Maintain VM pools * Client Support: Solid understanding and experience supporting zero/thin clients * Risk Management System Support: Experience supporting systems within a DoD Risk Management Framework (RMF) accredited environment. * SIEM Solutions: Splunk, SolarWinds, etc. * Skills: Coordination, Communication and Presentation skills * Functionality: Layer 2/3 Networking experience * Firewall experience * DoD 8570 certifications: Security+, CISSP, Computing Environment * DoD Network experience: Experience working with DoD Wide Area Networks and familiarity with various network architectures and common protocols to include: * Experience working with Defense Research and Engineering Network (DREN) * Experience working with the Secret Defense Research and Engineering Network (SDREN) * EPO (Trelix) experience - policy, agent updates, compliance dashboards, ACAS experience - scanning, reporting, compliance dashboards Ready to Make a Difference? ## Description The successful candidate will provide support to the Test Resource Management Center's (TRMC) All Domain Test Range (ADTR) and INDOPACOM Pacific-Rim Multi-Domain Training and Experimentation Capability Team, Joint Mission Environment Test Capability (JMETC) Secret Network (JSN) Node, JMETC Multiple Independent Levels of Security Network (JMN) Node, Secret Defense Research and Engineering Network (SDREN), Defense Research and Engineering Network (DREN). In this role, you will be a critical part of our team responsible for evaluating customer requirements pertaining to complex technical challenges. The successful candidate will assist with providing solutions to complex problems in a manner which meets both functional and security requirements. You will be responsible for keeping the team's computing environment operational and in compliance with all TRMC directives and applicable RMF requirements. To do this you will frequently collaborate with other distributed team members to discuss current system status and plan desired future enhancements. The candidate will have a blended skill set with a strong background in both systems administration and cybersecurity. This individual will possess experience in Windows and Linux server management, Active Directory, Security Technical Implementation Guides (STIGs), and virtualization technologies. This role is critical in ensuring the integrity, confidentiality, and availability of our information systems within a Department of Defense (DoD) environment., * Security Management: * Develop, implement, and maintain security policies, procedures, and standards to safeguard organizational information systems. * Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate potential threats. * Monitor security alerts and logs to respond to incidents in a timely manner, ensuring compliance with DoD regulations. * Manage Privileged Access Management (PAM) solutions to ensure secure access control for sensitive systems and data. * Filter and generate reports from Security Information and Event Management (SIEM) tools to provide insights into security incidents and trends. * Respond to JFHQ-DODIN issued orders, such as Cyber Task Orders (CTO). * Participate in DoD mandated Zero Trust efforts (initiatives, planning, testing and implementation). * Systems Administration * Administer Windows and Linux servers, ensuring optimal performance, security and uptime. * Manage Active Directory for user account provisioning, authentication, and access control, ensuring compliance with organizational security policies. * Implement and maintain STIGs to harden system configurations and reduce vulnerabilities across all server environments. * Virtualization and Cloud Management * Oversee the virtualization of servers using VMware, Hyper-V, or similar technologies, ensuring secure and efficient resource allocation. * Manage cloud-based services and applications, ensuring they adhere to security policies and best practices. * Risk Management Framework (RMF) Compliance * Apply RMF principles to assess and manage risk associated with information systems, including categorization, selection of security controls, implementation, assessment, authorization, and continuous monitoring. * Collaborate with stakeholders to ensure all systems are RMF-compliant and maintain relevant documentation. * Training and Awareness * Develop and conduct security training programs for staff to enhance awareness of information security best practices and organizational policies. * Function as a security advisor to other departments, providing guidance on secure system design and implementation. * Documentation and Reporting * Maintain comprehensive documentation of security processes, incidents, and remediation efforts. * Prepare and present reports on security posture, vulnerabilities, and incident response efforts to senior management and other stakeholders. * Additional Tools and Technologies * Experience with McAfee ePolicy Orchestrator (ePO) for centralized security management. * Familiarity with Assured Compliance Assessment Solution (ACAS) for vulnerability scanning and compliance monitoring. ## Related Videos - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevOps at Netflix](https://www.wearedevelopers.com/videos/270-devops-at-netflix) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)