> Markdown version of [/jobs/ext/1921893-ninformation-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1921893-ninformation-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # nInformation Systems Security Officer - **Company:** AUSGAR Technologies Inc - **Location:** San Diego, CA, United States - **Experience:** Starter - **Salary:** $125,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Kubernetes Security, Amazon Web Services, Audit Trail, Command-Line Interface, Cloud Computing, Cyber Security, Information Systems, Linux, Hypervisor, Identity and Access Management, Virtualization Technology, Software Vulnerability Management, Data Logging, SC Clearance, Kubernetes, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://jobs.military.com/career/298262/information-systems-security-officer-26-019-california-ca-san-diego ## About the Role * Must have a current Top-Secret clearance with the ability to obtain a TS/SCI security clearance.\n * A Security+ CE is required. \n * Must have or be able to obtain within six months of hire, a DoD 8570 IAT Level III certification (CISSP, CASP+, CISA, GCED, GICSP, CGRC, etc.).\n * Bachelor's degree in Cybersecurity, Information Technology, Information Systems or a related field from an accredited college or university and 8+ years of experience or equivalent combination of work experience and education.\n * 2+ years of experience as an ISSO or ISSM.\n * 1-2 years of experience securing cloud-native environments, including AWS and Kubernetes, with knowledge of container security, IAM, logging, monitoring, vulnerability management and compliance requirements.\n * Experience maintaining Authority to Operate (ATO) packages within eMASS or XACTA and supporting RMF activities for classified systems.\n * Experience conducting ACAS vulnerability scanning, vulnerability remediation tracking and POA&M management.\n * Experience reviewing security logs, audit records, and compliance evidence to support. Continuous Monitoring (ConMon) requirements.\n * Experience implementing and maintaining security controls in accordance with NIST 800-53 and DoD cybersecurity requirements.\n * Experience with Linux operating systems and command-line administration.\n * Experience with virtualized environments and hypervisors.\n * Knowledge of XACTA or eMASS.\n * Knowledge of the A&A process for DoD information systems.\n * Knowledge of NISPOM, DCSA A&A; Process Manual, JSIG, ICD 503/703, STIGs, RMF and associated NIST publications.\n * Knowledge of incident handling and response procedures, including data spills involving unclassified and classified systems.\n * Previous experience within the U.S. Department of Defense highly desired. \n * Expected travel up to 10% (1-2 trips/year). \n ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An alternative approach to digital sovereignty: Confidential Computing](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [20 Years of Solving Unsolvable Problems](https://www.wearedevelopers.com/videos/100214-20-years-of-solving-unsolvable-problems) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)