> Markdown version of [/jobs/ext/1773862-information-systems-security-officer-engineer](https://www.wearedevelopers.com/jobs/ext/1773862-information-systems-security-officer-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer/Engineer - **Company:** Tetrad Digital Integrity LLC - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Network Diagrams, SC Clearance, Information Technology, Process Control Systems, Operational Systems, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fa14e5fa363aab48 ## About the Role * Active Secret clearance * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, and 3+ years of experience supporting cybersecurity, RMF, or information assurance in military, federal, or government contractor environments. * Experience supporting the Risk Management Framework, including eMASS, RMF artifacts, and authorization activities, as an ISSE, ISSO, or similar cybersecurity role. * Proficiency implementing DISA STIGs/SRGs and conducting ACAS vulnerability scanning and remediation., * Familiarity with NAVFAC environments and/or operational technology (OT) or industrial control systems (ICS), including industrial protocols, HVAC control systems, and utility/energy management technologies. ## Description * Perform system decomposition and CYBERSAFE assessments to identify mission-critical components and support Facility Related Control Systems (FRCS) cybersecurity requirements. * Execute the full RMF lifecycle, including development, review, and maintenance of authorization packages supporting initial ATOs, continuous monitoring, and reauthorization efforts. * Develop and maintain RMF artifacts, including system inventories, network diagrams, categorization documentation, security plans, assessment plans, continuous monitoring plans, vulnerability reports, and STIG/SRG compliance documentation. * Manage RMF activities within eMASS, including artifact uploads, control implementation, vulnerability mapping, test results, POA&M management, and authorization workflows. * Implement and validate NIST 800-53 security controls through vulnerability scanning, patching, STIG/SRG compliance, and remediation of IT infrastructure and IP-based control systems. * Coordinate authorization boundary changes, on-site validation activities, and Operational Technology Design Authority (OTDA) change requests. * Collaborate with cross-functional teams and stakeholders to support nationwide cybersecurity assessments, remediation efforts, and provide regular RMF status updates to program leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Data is Shaping our Games](https://www.wearedevelopers.com/videos/176-how-data-is-shaping-our-games) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Designing Reliable Distributed Systems: Failures, Retries & Idempotency](https://www.wearedevelopers.com/videos/1963-designing-reliable-distributed-systems-failures-retries-idempotency) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)