> Markdown version of [/jobs/ext/1921029-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1921029-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Sonalysts, Inc. - **Location:** Waterford, CT, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Computer Networks, Linux, Identity and Access Management, Python (Programming Language), Network Security, Windows Servers, Network Monitoring, Nmap, Windows PowerShell, Security Content Automation Protocol, Shell Script, Security Information and Event Management, Software Vulnerability Management, Scripting, Information Technology, Metasploit, Nessus, Nexpose, National Industrial Security Program Operating Manual (NISPOM), Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=af7a62aaa3654bcd ## About the Role * Bachelor's degree in an Information Technology-related field and 4 years of relevant information systems security experience; OR 8 years relevant Information Systems security experience * Hold a current DOD Information Assurance Workforce (IAWF) Level II (or higher) IAM or IAT certification(s) (e.g., GSEC, Security+, SSCP, CCNA-Security, CISA, CISM, GCIH, GCED, CISSP, CASP) * Must be a U.S. citizen, possessing an active U.S. Department of Defense (DoD) Final SECRET security clearance* Preferred, but not required, experience in the following: * Possessing an active U.S. Department of Defense (DoD) Top Secret Security Clearance* * Technical aptitude administering and troubleshooting Microsoft Windows Server 2016 (or higher) * Technical aptitude administering and troubleshooting Microsoft Windows 10 (or higher) * Experience as an ISSO, ISSM, ISSE, or SCA supporting classified programs. * Experience with Linux OS * A Level III DOD IAWF Certification * Experience with Enterprise Mission Assurance Support Service (eMASS) system * Experience creating, maintaining, enforcing, and training Security policies * Experience communicating security policy and concepts to Leadership * Experience with security administration of a DOD classified network/information system. * Experience with network monitoring, testing and troubleshooting tools/utilities * Experience with vulnerability management to include creating and updating the Plan of Action and Milestones (POA&M) for an information system's IA package, testing, applying, and verifying software updates and patches from an IA perspective * Experience with vulnerability scanning tools and techniques (Nessus/ACAS, Nmap, Eye Retina, Nexpose, Metasploit), Security Information and Event Management (SIEM) tools and techniques * Knowledgeable in the use of scripting languages/tools to automate information system administration and security functions (Shell Script, PowerShell, Python, etc.) * Experience with Security Content Automation Protocol (SCAP) tools * Maintaining a U.S. Government security clearance involves periodic comprehensive background checks. Candidates are eligible for a clearance if they have demonstrated sound financial management (including good credit) over time, are free of criminal records, have limited foreign contacts or ties, and other factors indicative of a position of trust to protect information sensitive to the U.S. Government. ## Description Sonalysts, Inc. is seeking an Information Systems Security Officer (ISSO) for our Waterford, CT office. What you will be doing: * Advise and interface with the Information Systems Security Manager (ISSM) on security considerations in information systems procurement, development and implementation, operation and maintenance, and disposal activities under the Risk Management Framework (RMF) company-wide * Assist with information systems security compliance of classified information systems in accordance with the National Industrial Security Program Operating Manual (NISPOM)/32CFR§117, DCSA Assessment & Authorization Process Manual (DAAPM), DODI 8500.01, and NIST SP 800 (series) * Maintain information system security plans, contingency plans, incident response plans, and configuration management plans for all systems under their responsibility * Monitor day-to-day server and network security operations * Participate in Configuration Control Board (CCB) and configuration management activities for all systems under their responsibility * Serve as focal point on Department of Defense Information Network (DoDIN) connected systems * Occasionally travel to receive training, complete system installations, and conduct oversight reviews ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)