> Markdown version of [/jobs/ext/1756907-cyber-security-analyst-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1756907-cyber-security-analyst-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst/Information Systems Security Officer - **Company:** ARET LLC - **Location:** Los Angeles, CA, United States (Remote available) - **Experience:** Starter - **Salary:** $80,000.0 - $90,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, BitLocker Drive Encryption, Configuration Management, Cyber Security, Information Systems, Linux, McAfee VirusScan, Red Hat Enterprise Linux, Security Software, Security Information and Event Management, Scap Compliance Checker, Server Operating Systems & Platforms, Plan of Action and Milestones - **Published:** July 22, 2026 - **Apply:** https://www.dice.com/job-detail/22740b24-895a-46f8-aae7-a9db4a047b51 ## About the Role * Active Top Secret security clearance with ability to obtain a CI polygraph. * 1-2 years of experience performing ISSO or equivalent cybersecurity duties for classified systems. * Demonstrated experience with JSIG, RMF, and NIST 800-53 security controls. * Hands-on experience in security auditing, continuous monitoring, and documentation of control implementation. * Current IAT Level II Security Certification or higher (Security+, CASP, CySA+, CISSP, GSEC) or ability to obtain within 3 months of the start date. * Must have solid technical knowledge on how Windows and Server operating systems are hardened. * Experience with common information system Cyber Security tools, technologies, and STIGs (NessACAS, SCAP Compliance Checker, STIG Viewer, Microsoft Group Policy, etc.). * Strong interpersonal skills, technical writing skills, and the ability to work autonomously and on a team. * Strong written communication skills and the ability to document/diagram information systems and procedures. * Must be able to lift 25 pounds. Nice to Have (Preferred Skills): * Knowledge of the Risk Management Framework is a plus; * Experience with Security Directives, Policies, Publications and Regulations including but not limited to the NIST 800-171, NIST 800-53, JSIG and/or ICD 503; * Experience in one or more of the following Cybersecurity tools/technologies: SIEM or Log Reduction & Analysis Tools, McAfee ePO, SCC Tool, Bitlocker, Rapid7 IDR, InsightVM; * Technical knowledge on how Linux (RHEL 8/9) systems are configured, hardened, and managed. ## Description * Perform duties as ISSO in accordance with JSIG, RMF, and NIST 800-53. * Develop, maintain, and update security authorization documentation including System Security Plans (SSPs), Plan of Actions and Milestones (POA&M), SCTMs, ConMon Reports, and audit logs. * Conduct security control implementation, validation, and assessment activities. * Perform and document system audits and risk analysis. * Manage and execute Continuous Monitoring (ConMon) tasks to ensure compliance throughout the system lifecycle. * Support configuration management (CM) processes with a minimum of 1-2 years direct CM experience, including review and documentation of system changes, baseline management, and change control. * Provide incident response support, including investigation, reporting, and remediation of security events. * Support preparation for internal and external inspections and assessments. * Support ISSM with other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)