> Markdown version of [/jobs/ext/1617617-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1617617-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO - **Company:** MSI - - **Location:** Mooresville, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Antivirus, Microsoft Azure, Cyber Security, Information Systems, System Configuration, Digital Technology, Azure Active Directory, Security Information and Event Management, Software Vulnerability Management, SARS Software Products, Microsoft InTune, Information Technology, Patch Management, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cecff2a0429149c2 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience). * 5+ years of cybersecurity, information assurance, or information systems security experience within a DoD or federal contractor environment. * Strong knowledge of: * + DoD Risk Management Framework (RMF) + NIST SP 800-53 + NIST SP 800-171 + CMMC Level 2 + STIG implementation * Experience managing Authorization to Operate (ATO) packages. * Experience supporting classified information systems. * Experience administering Microsoft 365 GCC High, Azure Active Directory, Microsoft Defender, Intune, and endpoint security solutions. * Experience conducting vulnerability management and remediation. * Familiarity with SIEM solutions and continuous monitoring tools. * Excellent documentation and technical writing skills. * Strong communication and collaboration skills. Preferred Qualifications * Experience supporting CMMC Level 2 environments or similar regulated environments * Familiarity with tools such as Microsoft Defender, SIEM platforms, and compliance tools (e.g., IntelliGRC) * Relevant certifications (Security+, CySA+, CISSP, or similar) * Experience with audit preparation and evidence collection Security Requirements * S. Citizenship is required. * An active Secret security clearance is required. * Must be able to maintain eligibility for access to classified information. Physical Requirements * Prolonged periods sitting at a desk and working on a computer * Must be able to lift up to 30 pounds at times. * Must be able to access and navigate each department at the organization's facilities. ## Description The Information Systems Security Officer (ISSO) is responsible for the security, compliance, and operational integrity of MSI Defense Solutions' information systems supporting both classified and unclassified environments. The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems comply with DoD Risk Management Framework (RMF), NIST SP 800-171, NIST SP 800-53, CMMC, and other applicable federal security requirements. This position is responsible for maintaining Authorization to Operate (ATO) packages, supporting security assessments, implementing continuous monitoring activities, and safeguarding Controlled Unclassified Information (CUI) and classified information. The ISSO partners closely with Information Technology, Security, Engineering, Program Management, and government customers to ensure cybersecurity requirements are integrated throughout the system lifecycle. The ISSO will report to the Digital Technology Manager. The position requires a full-time work week spent in the office or hybrid with 3 days onsite. Normal hours are Monday through Thursday 7:00am-4:30pm and Friday 7:00am - 12:00pm. (Must be flexible to work additional hours as needed based on project requirements and deadlines.), * Serve as the Information Systems Security Officer (ISSO) for classified and unclassified information systems. * Maintain compliance with the DoD Risk Management Framework (RMF), NIST SP 800-53, NIST SP 800-171, CMMC, and applicable DoD cybersecurity policies. * Develop, maintain, and update System Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), and RMF documentation. * Administer and maintain the organization's Governance, Risk, and Compliance (GRC) platform (e.g., IntelliGRC), ensuring security documentation, evidence, POA&Ms, and assessment artifacts remain current and audit ready. * Support Authorization to Operate (ATO), Authority to Connect (ATC), and continuous monitoring activities. * Ensure implementation and maintenance of required security controls across enterprise systems. * Conduct vulnerability assessments, security audits, and remediation tracking. * Coordinate vulnerability scanning, patch management, and secure system configuration. * Investigate, document, and coordinate cybersecurity incident response activities. * Administer user access controls and privileged account management in accordance with least privilege principles. * Ensure compliance with security requirements for classified systems and secure facilities. * Lead the preparation for internal audits, DCSA assessments, customer inspections, and CMMC assessments including evidence collection, artifact management, and assessor coordination. * Collaborate with IT, Engineering, and Program teams to integrate cybersecurity throughout project execution. * Develop and maintain cybersecurity policies, procedures, and user awareness initiatives. * Support secure implementation of Microsoft 365 GCC High, Azure, Microsoft Defender, Intune, and related security technologies. * Serve as the primary cybersecurity liaison for government customers and external auditors. * Monitor compliance status, track remediation activities, and provide regular reporting on cybersecurity posture and outstanding compliance actions to leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)