> Markdown version of [/jobs/ext/194718-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/194718-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** CHAOS Industries - **Location:** Los Angeles, CA, United States - **Experience:** Starter - **Salary:** $140,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, Audit Trail, CentOS, Cyber Security, Information Systems, System Configuration, Linux, Firmware, Identity and Access Management, Networking Hardware, Red Hat Enterprise Linux, ArcSight SIEM Tool, Security Content Automation Protocol, Security Information and Event Management, Software Vulnerability Management, Data Processing, SC Clearance, Information Technology, Nessus, Splunk, Scap Compliance Checker, User Administration - **Published:** May 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=87d533d81127ce45 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Equivalent combination of education and experience considered. * 3+ years of experience in information security or IT, with at least 1-2 years in an ISSO, security analyst, or equivalent role supporting classified U.S. Government systems. * Hands-on experience with RMF-based system authorization activities (ICD 503, JSIG, or DAAPM) at the Secret or TS/SCI level. * Working knowledge of ACAS/Nessus, SCAP Compliance Checker, and DISA STIGs. * Familiarity with Windows Server and/or RHEL/CentOS administration in classified environments. * Experience conducting audit log reviews, account management, and POA&M tracking. * IAT Level II or IAM Level II certification required: Security+, CySA+, CAP, CASP+, or equivalent (IAW DoD 8570.01-M / DoD 8140). * Active Secret clearance required at time of hire; TS/SCI eligibility preferred or required depending on program assignment. Preferred Requirements: * Experience supporting Special Access Programs (SAPs) or SCI compartmented programs. * Familiarity with Xacta, eMASS, or equivalent GRC/authorization management platforms. * Knowledge of cross-domain solution (CDS) environments or Type 1 encryption device administration. * Experience with SIEM platforms (Splunk, ArcSight, or similar) in a classified environment. * Exposure to CMMC Level 2/3 requirements or CUI handling in defense contractor settings. * Additional certifications: CISSP (Associate), CEH, GCIH, or equivalent. ## Description CHAOS Industries is seeking a detail-oriented and mission-focused Information Systems Security Officer (ISSO) to support the day-to-day security operations of classified information systems within one or more assigned programs. Under the direction of the ISSM, the ISSO serves as the on-the-ground security authority responsible for maintaining system compliance, executing continuous monitoring activities, supporting authorization efforts, and ensuring that all users and administrators adhere to applicable security policies and procedures. This role is ideal for a security professional looking to grow within the defense and intelligence community while working on cutting-edge classified programs., * System Security Operations & Compliance + Support the development and maintenance of system security documentation including System Security Plans (SSPs), Security CONOPs, hardware/software baselines, and standard operating procedures (SOPs). + Ensure all assigned information systems operate in accordance with established ATOs and applicable government security requirements (NIST RMF, ICD 503, JSIG, DAAPM). + Monitor system configurations and enforce compliance with approved baselines; document and report any deviations to the ISSM. + Assist in the preparation and submission of security authorization packages and support AO review activities. * Continuous Monitoring & Vulnerability Management + Execute routine audit log reviews, account management checks, and security event monitoring across assigned systems. + Conduct and analyze vulnerability scans using ACAS/Nessus and SCAP tools; triage findings and track remediation to closure. + Apply and validate DISA STIG/SRG configurations on Windows, Linux (RHEL/CentOS), and network devices; document compliance status. + Maintain and update Plan of Action & Milestones (POA&Ms); coordinate with system owners and administrators to remediate open findings. + Support SIEM integration efforts and contribute to development of alerting thresholds and use cases. * Incident Response & Reporting + Identify, document, and report security incidents and anomalies in accordance with program and government reporting timelines. + Conduct initial triage of potential security violations; preserve evidence and coordinate with the ISSM and FSO for escalation as required. + Participate in lessons-learned reviews following incidents and contribute to improvement of security procedures. * User Support & Security Awareness + Brief incoming personnel on program security requirements, acceptable use policies, and information handling procedures. + Conduct periodic security reminders, refresher training, and spot checks to reinforce security awareness among program staff. + Serve as the first point of contact for user security questions, access requests, and account provisioning/de-provisioning activities. * Configuration & Change Management + Review hardware, software, and firmware change requests for security impact; document assessments and provide recommendations to the ISSM. + Maintain accurate and current hardware/software inventories and media control logs for all assigned systems. + Coordinate with system administrators to ensure patching schedules align with security requirements and authorization conditions. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)