> Markdown version of [/jobs/ext/1921816-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1921816-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Pantex, Inc. - **Location:** Amarillo, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Information Systems, Computer Networks, Databases, Information Security Management, Information Systems Security Architecture Professional, Network Security, PL-SQL, Software Security, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=33b406f94b24df93 ## About the Role * Bachelor's degree in engineering/science/information technology discipline: Minimum 2 years of relevant experience. * OR Master's degree in engineering/science/information technology discipline. * OR applicants without a bachelor's degree may be considered based on a combination of at least 10 years of completed education and/or relevant experience., * Knowledge of computer networking concepts and protocols, and network security methodologies * Knowledge of risk management processes (e.g., methods for assessing and mitigating risk) * Knowledge of cybersecurity and privacy principles * Knowledge of cybersecurity threats and vulnerabilities * Knowledge of Security Assessment and Authorization process * Knowledge of RMF best practices * Ability to present administrative, technical, and operational information clearly and effectively through the oral and written word as well as diagrams and charts * Knowledge of NIST 800-53/53A security controls * Ability to assess and provide written assessments of A&A packages * Understanding of RMF in the Department of Energy (DOE) Community * Security+, Certified Ethical Hacker (CEH) Certification or Certified Information Systems Security Professional (CISSP) Certification * FedRAMP and Cloud compliance experience * Knowledge of IT security principles and methods (e.g., firewalls, demilitarized zones, encryption) * Knowledge of Application Security Risks * Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy * Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161) * Knowledge of Personally Identifiable Information (PII) data security standards * Knowledge of authentication, authorization, and access control methods * Knowledge of database systems * Knowledge emerging technologies that have potential for exploitation * Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, * Procedural Language/Structured Query Language (PL/SQL) and injections, race conditions, covert channel, replay, return-oriented ## Description The Cyber Security Professional is responsible for the Assessment and Authorization (A&A) of Federal information systems, as well as the development of accreditation and other required cybersecurity documentation for new and existing systems. Additionally, this person will utilize various network tools for continuous monitoring of Information Technology (IT) assets. This role encompasses the responsibilities of the Information System Security Officer (ISSO) and/or the Security Control Assessor (SCA) for classified and unclassified information systems. The position requires and understanding of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) as well as Department of Energy (DOE) and National Nuclear Security Adminstration (NNSA) cybersecurity directives. The role includes executing assessment and authorization activities, developing and maintaining cybersecurity documentation, performing continuous monitoring, and collaborating with technical stakeholders to ensure that cybersecurity controls and risk management activities align with DOE and NNSA policies and mission needs, while also staying up to date on the latest cybersecurity risks and threats., * A&A of Federal information systems * Development of accreditation and other required cybersecurity documentation for new and existing information systems * Conduct independent comprehensive assessments of the management, operational, and technical security controls, and control enhancements employed within, or inherited, by an IT system, to determine the overall effectiveness of the controls * Perform continuous monitoring of IT assets * Develop risk assessments and the proper mitigations * This role includes responsibilities of the ISSO and/or the SCA or classified and unclassified IT systems * Perform other duties as assigned * Ensure systems adhere to applicable federal, DOE, and NNSA cybersecurity policies, standards, and guidelines * Support system owners during the system lifecycle, including security impact analyses for changes and configuration updates Maintain system security documentation, including System Security Plans (SSPs), contingency plans, and configuration baselines * Coordinate with auditors, assessors, and external reviewers during cybersecurity inspections and evaluations ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)