> Markdown version of [/jobs/ext/1576340-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1576340-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** MIT Lincoln Laboratory - **Location:** Lexington, MA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Security Content Automation Protocol, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 22, 2026 - **Apply:** https://www.dice.com/job-detail/6985dbcb-dd67-4b4a-9a8b-b3f0012ed3ff ## About the Role * Minimum 4 years of experience in: * System Auditing * Regulatory & Compliance * STIGs/SCAP * Risk Management Framework (RMF) * Assessment and Authorization (A&A) * NIST SP 800-37, * Bachelor''s degree (preferred, not required) * Experience with: * HBSS * NIST 800-171 Security Clearance * Active Top Secret (TS) Clearance with SCI eligibility is required. * Candidate may be required to successfully complete a Counterintelligence (CI) Polygraph. * SCI eligibility must be validated prior to submission. ## Description MIT Lincoln Laboratory is seeking an Information System Security Officer (ISSO) to support Air Force Programs within the Cyber Security Team. The ideal candidate will have mid-level experience supporting Risk Management Framework (RMF), Assessment & Authorization (A&A), regulatory compliance, and security control implementation in DoD environments. Key Responsibilities * Assist and support compliance activities to ensure system security configuration guidelines are followed and compliance monitoring is maintained. * Continuously validate organizational compliance with applicable policies, guidelines, procedures, regulations, and laws. * Ensure Plans of Action & Milestones (POA&M) and remediation plans are in place for vulnerabilities identified during risk assessments, audits, and inspections. * Promote security awareness across the organization and ensure security principles are reflected in organizational goals. * Track audit findings and recommendations to ensure appropriate mitigation actions are completed. * Recommend resource allocations required to securely operate and maintain cybersecurity requirements. * Provide technical documentation, incident reports, examination findings, summaries, and situational awareness information to key stakeholders. * Identify potential security violations and report incidents in accordance with established procedures. * Assist Program Managers and the Information System Security Manager (ISSM) in developing and maintaining: * System Security Plans (SSP) * Plan of Action & Milestones (POA&M) * Risk Assessment Reports * Continuous Monitoring Strategy Ensure systems are operated, maintained, and disposed of in accordance with organizational security policies and procedures. Conduct network, system, and application vulnerability scanning, configuration assessments, and remediation. Align IT security priorities with the organization''s security strategy. Prepare for and participate in periodic compliance assessments. Interpret patterns of noncompliance to determine their impact on organizational risk and cybersecurity effectiveness., * Categorization of Systems (CS102.16) * Selecting Security Controls (CS103.16) * Implementation of Controls (CS104.16) * Assessing Security Controls (CS105.16) * Authorizing Systems (CS106.16) * Monitoring Security Controls (CS107.16) * Continuous Monitoring (CS200.16) Current DoD 8570 IAT Level II Certification: * Security+ CE, GSEC, SSCP, or CCNA Security ## Related Videos - [Beyond the Numbers: Engineering Recruiting Excellence Through Quality, Data, and Team Empowerment](https://www.wearedevelopers.com/videos/1491-beyond-the-numbers-engineering-recruiting-excellence-through-quality-data-and-team-empowerment) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)