> Markdown version of [/jobs/ext/1725334-information-assurance-engineer-information-system-security-off](https://www.wearedevelopers.com/jobs/ext/1725334-information-assurance-engineer-information-system-security-off). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Engineer / Information System Security Off - **Company:** Cubic Corporation - **Location:** Fort Meade, MD, United States - **Experience:** Experienced - **Salary:** $109,000.0 - $124,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Security Management, Tripwire, Software Vulnerability Management, Kubernetes, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 9, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9019470/information-assurance-engineer-information-system-security-off ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related technical discipline (or equivalent combination of education and experience). * Three (3) or more years of experience supporting Information Assurance, RMF, cybersecurity compliance, or Information System Security Officer (ISSO) responsibilities within DoD or Federal environments. * One or more DoD 8570/8140 IAT Level II certifications (e.g., Security+, CySA+, GSEC, SSCP, or equivalent). * Active DoD Secret security clearance. Preferred Qualifications * Experience supporting classified DoD and working within cross-functional technical teams. * Experience using eMASS to manage RMF authorization packages and continuous monitoring activities. * Experience with Kubernetes, container technologies, cloud platforms, and container vulnerability management. * Professional certifications such as CISSP, CISM, CAP, CASP+, CCSP, or GSLC. ## Description Cubic Digital Intelligence (CDI) is seeking an Information System Security Officer (ISSO) to support Department of Defense (DoD) cybersecurity programs. The ISSO will be responsible for implementing and maintaining Risk Management Framework (RMF) activities, supporting system accreditation efforts, continuous monitoring, vulnerability management, and cybersecurity compliance across classified and unclassified environments. This position works closely with Program Managers, Information System Security Managers (ISSMs), System Owners, Engineers, and Government stakeholders to ensure systems maintain Authorization to Operate (ATO) while meeting applicable DoD and Federal cybersecurity requirements. The ISSO will develop and maintain cybersecurity documentation, coordinate remediation activities, support security assessments, and help strengthen the organization's overall security posture in support of critical national security missions., Travel Requirements: Up to 10% travel for customer meetings, security assessments, and program support. Essential Functions * Support the implementation and sustainment of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 and DoD RMF guidance. * Develop, maintain, and update cybersecurity documentation, including SSPs, POA&Ms, Continuous Monitoring Plans, Configuration Management Plans, and Supply Chain Risk Management (SCRM) Plans. * Review and analyze vulnerability scan results from ACAS/Nessus, Tenable, Trivy, OpenSCAP, and other security assessment tools while coordinating remediation efforts with engineering teams. * Maintain and update authorization packages within eMASS and support security control implementation, assessment, and authorization activities. * Track DISA task orders (DTOs), cybersecurity findings, POA&M items, and remediation milestones to ensure timely resolution and compliance with Government requirements. * Participate in security assessments, vulnerability reviews, and compliance audits to validate adherence to DoD cybersecurity policies and standards. * Prepare technical reports, executive briefings, and status updates related to cybersecurity compliance, vulnerabilities, and continuous monitoring activities. ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)