> Markdown version of [/jobs/ext/1830249-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1830249-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** KBR Inc - **Location:** Dayton, OH, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Identity and Access Management, Information Technology Audit, Security Content Automation Protocol, Verification and Validation (Software), Information Technology, National Industrial Security Program Operating Manual (NISPOM), Vulnerability Analysis - **Published:** July 10, 2026 - **Apply:** https://www.juju.com/job/00000000gfbpq4 ## About the Role + Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field and 4+ years of ISSO experience; or equivalent combination of education and experience. + Experience supporting DoD cybersecurity programs and Risk Management Framework (RMF) requirements. + Experience developing, submitting, and maintaining RMF authorization packages. + Experience supporting Joint Special Access Program Implementation Guide (JSIG) environments. + Experience developing and maintaining RMF documentation, including SSPs, PIAs, Security Checklists, POA&Ms, and related ATO artifacts. + Knowledge of independent verification and validation methodologies. + Experience conducting research, analysis, and security assessments both independently and within a team environment. + Current DoD 8570-compliant IAM Level I certification (Security+ CE, CAP, or equivalent). + Active DoD Secret security clearance with the ability to obtain and maintain Top Secret/SCI eligibility, or a qualifying background investigation completed within the required timeframe. + Strong written and verbal communication skills with the ability to communicate effectively across technical and non-technical audiences. Preferred Qualifications + Current IAM Level II certification (CISSP, CISM, CASP+, CAP, or equivalent). + Experience conducting Security Control Assessments (SCAs) and validating security controls against SSP, NIST SP 800-53, and JSIG requirements. + Knowledge of information system maintenance, asset management, and inventory control processes. + Experience coordinating cybersecurity compliance activities with leadership and organizational stakeholders. + Experience developing waiver and exception packages for information system vulnerabilities. + Knowledge of quality assurance, quality control, and independent verification and validation practices. + Experience supporting cybersecurity operations within a corporate environment and global enterprise. + Familiarity with cybersecurity assessment and compliance tools, including eMASS, ACAS, SCAP Tool, or similar platforms. ## Description KBR is seeking an experienced Information Systems Security Officer (ISSO) to join our Information Assurance (IA) Operations team in Beavercreek, OH. This position is onsite and will support cybersecurity operations and compliance activities for KBR information systems operating within classified environments. Reporting directly to the Site Information Systems Security Manager (ISSM), the ISSO will serve as a key member of the Information Assurance team, supporting Assessment & Authorization (A&A) activities, continuous monitoring efforts, and cybersecurity compliance initiatives. This role is responsible for helping maintain Authorization to Operate (ATO) packages, assessing system security posture, and ensuring compliance with applicable DoD and federal cybersecurity requirements., + Serve as the onsite Information Systems Security Officer (ISSO) supporting Information Assurance (IA) Operations and site-hosted information systems. + Conduct security assessments of systems and networks to identify vulnerabilities, configuration deviations, and compliance gaps. + Perform passive compliance evaluations and active vulnerability assessments to validate cybersecurity requirements and controls. + Support Assessment & Authorization (A&A) activities and maintain Authority to Operate (ATO) packages in accordance with Risk Management Framework (RMF) requirements. + Develop, review, and maintain RMF documentation, including System Security Plans (SSPs), Security Checklists, Privacy Impact Assessments (PIAs), POA&Ms, and other authorization artifacts. + Assist with implementation and compliance of applicable cybersecurity requirements, including JSIG, NISPOM, NIST SP 800-53, NIST SP 800-171, and RMF guidance. + Monitor system audit records and security events, conduct periodic reviews, and track corrective actions through closure. + Analyze vulnerability scan results and coordinate remediation efforts with system administrators and technical stakeholders. + Support security certification testing, inspections, audits, investigations, and compliance reviews. + Assist in evaluating emerging technologies, software implementations, and hardware deployments to ensure cybersecurity requirements are met. + Coordinate with site leadership and cross-functional teams to support security initiatives and maintain compliance requirements. + Participate in continuous monitoring activities and contribute to process improvement efforts across IA Operations. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)