> Markdown version of [/jobs/ext/1953456-junior-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1953456-junior-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Information System Security Officer (ISSO) - **Company:** ASEC Inc - **Location:** Ridgecrest, CA, United States (Remote available) - **Experience:** Starter - **Salary:** $90,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, CompTIA Security+, Cyber Security, Information Systems, Linux, Information Security Management, Networking Hardware, SAP (Applications), Software Vulnerability Management, SARS Software Products, Information Technology, Scap Compliance Checker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9079130/junior-information-system-security-officer-isso ## About the Role Join a mission-focused cybersecurity team protecting critical DoD information systems. As a Junior Information System Security Officer (ISSO), you'll play a hands-on role in vulnerability management, RMF compliance, and continuous monitoring, gaining valuable experience while directly supporting a mission-critical program. If you're detail oriented, technically driven, and ready to grow in a high-impact security environment, this is your opportunity to make a difference., What You'll Bring: * CompTIA Security + is required. BS degree in Information Technology, Cybersecurity, Computer Science, or related area of study, desired. The following certifications are highly desired: CISSP, SecurityX (formerly CASP+), CISM, or GSLC. Please upload copies of any relevant IT certifications you hold. 2-3 years of experience in the following technical areas is preferred: * Information Assurance / Cybersecurity (IA/CS) within DoD environments. * Risk Management Framework (RMF) in accordance with DoDI 8510.01. * Implementation of security controls aligned with CNSSI 1253, NIST SP 800-53, and JSIG * Conducting vulnerability assessments using ACAS, DISA STIGs, and SCAP Compliance Checker with automated benchmarks., * Ability to build positive, collaborative relationships across teams and with external partners. * Effective communicator with strong verbal and written skills. * Proactive, self-directed work style with the ability to operate independently. * Analytical thinker with proven problem-solving capabilities. * Highly organized, with the ability to balance competing priorities in a fast-paced environment. ## Description * Support the implementation and enforcement of cybersecurity policies, standards, and procedures in alignment with DoD RMF requirements. * Perform vulnerability assessments using tools such as ACAS, SCAP Compliance Checker, and DISA STIG benchmarks to identify and remediate security gaps. * Apply and validate DISA STIG configurations across Windows, Linux, and network devices to ensure compliance with DoD security standards. * Assist in continuous monitoring activities, including reviewing audit logs, tracking POA&M items, and supporting security control assessments. * Contribute to the development and maintenance of RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and related artifacts supporting ATO efforts. * Coordinate with system owners, engineers, and ISSMs to track vulnerabilities, implement mitigations, and support remediation timelines. * Review and verify compliance of hardware and software against NIAP Common Criteria certifications and the DISA Approved Products List (APL). * Support preparation of security authorization packages and interface agreements (MOAs/MOUs) for interconnected systems. * Conduct risk assessments and assist in identifying mitigation strategies to protect classified and unclassified DoD information systems. * Participate in cybersecurity working groups and cross-functional meetings to ensure alignment with program milestones and mission objectives. * Provide user awareness support and assist with incident response documentation and reporting activities. This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary., * Supporting continuous monitoring, security audits, risk assessments, and mitigation planning * Reviewing technologies for compliance with NIAP Common Criteria and the DISA Approved Products List (APL). * Familiarity with ICD 705, DoD 5205.07/5205.07-M (Vol 1-4), SAP policy, and JSIG requirements. ## Related Videos - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)