> Markdown version of [/jobs/ext/1774317-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1774317-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** Utah State University - **Location:** North Logan, UT, United States - **Experience:** Expert - **Salary:** $94,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Log Analysis, Network Segmentation, Network Protocols, SAP Security, Systems Architecture, Software Vulnerability Management, SARS Software Products, Information Technology, Splunk, Servicenow, Vulnerability Analysis - **Published:** July 16, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17603434?backUrl=%2Fcareer%2F17603434%2FInformation-Systems-Security-Officer-Isso-Utah-North-Logan ## About the Role Space Dynamics Laboratory (SDL) is seeking a highly experienced Information Systems Security Officer (ISSO) to support and secure mission-critical systems within the intelligence community. This position requires a strong background in TS/SCI environments, and advanced cybersecurity practices supporting highly sensitive national security missions. The ideal candidate has 5+ years of experience in cybersecurity, risk management, and information system security within classified environments., * Active TS/SCI clearance * 5-10 years of experience in information systems security within IC or other highly classified environments * DoW 8570/8140 compliant - IAT Level II and IAM Level II (or higher) required at time of hire * Bachelor's degree in cybersecurity, computer science, information assurance, or a related field (or equivalent experience) * Certifications: Security+, CySA+, GSEC, SSCP, CCSP or equivalent * Extensive knowledge of IC and DoW security frameworks: ICDs, CNSSI, NIST 800-53, RMF, JSIG, and SAP security controls * Experience with security documentation including SSPs, POA&Ms, SARs, ISAs, MOUs, and ATO packages * Experience supporting SCI systems, including accreditation and lifecycle management * Experience executing Incident Response Plans, including classified data spillage remediation * Hands-on experience with Continuous Monitoring (CONMON) activities and reporting * Experience using Tenable tools (ACAS) for vulnerability scanning and remediation tracking * Experience using Splunk for log analysis and security monitoring * Ability to produce detailed technical reports for system owners and stakeholders * Strong technical background in vulnerability management, system hardening, and secure architecture, * Master's degree in cybersecurity, computer science, or a related field * Certifications: CISSP, CISM, CISA, CGRC, CASP+, or equivalent * Experience with JSIG, ICD 503, and RMF processes * Familiarity with Service Now (SNOW), eMASS, XACTA, and/or other IC authorization tools * Deep understanding of multi-enclave architectures, cross-domain solutions, and classified network segmentation * Experience with interconnection agreements (ISA/MOU/MOA) in IC environments * Ability to assess and articulate risk for non-implemented or inherited controls * Strong understanding of network protocols, system architectures, and secure configurations in TS/SCI environments * Ability to translate technical security concepts into mission-relevant risk language for leadership * Experience working across multi-disciplinary teams including developers, engineers, and system administrators * Demonstrated ability to work independently with minimal supervision in high-security environments ## Description Security Compliance & Risk Management * Ensures information systems comply with Intelligence Community Directives (ICDs), CNSSI, NIST 800-53, and the Risk Management Framework (RMF) for TS/SCI systems * Conducts risk assessments, vulnerability management, and mitigation planning for highly classified systems * Performs audits of log review, reduction, and analysis using Splunk to support security monitoring and investigations * Leads and executes the full Risk Management Framework (RMF) lifecycle to achieve and maintain an Authorization to Operate (ATO) for TS/SCI systems Incident Response & Continuous Monitoring * Oversees security operations, threat analysis, and intrusion detection in TS/SCI enclaves * Develops and executes incident response plans, including data spill response and containment in classified environments * Performs and manages Continuous Monitoring (CONMON) activities, including analysis of security posture, tracking of vulnerabilities, and reporting to support ongoing authorization * Executes vulnerability scanning using tenable tools (e.g., ACAS) and analyze results to identify, prioritize, and remediate system vulnerabilities Policy Development & Documentation * Develops and maintains security policies, procedures, and guidelines in alignment with IC, and national-level security requirements * Ensures audit readiness and proper documentation of security controls, artifacts, and assessment evidence * Manages and maintains RMF documentation including SSPs, POA&Ms, SARs, and security control traceability Collaboration & Leadership * Works closely with program managers, ISSMs, ISSEs, system administrators, and engineers to ensure secure system design and operation * Serves as a trusted advisor to leadership on IC cybersecurity requirements, emerging threats, and risk posture * Interfaces with Government stakeholders including Authorizing Officials (AOs), Security Control Assessors (SCAs), and IC oversight teams ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)