> Markdown version of [/jobs/ext/2026382-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2026382-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** KBR Inc - **Location:** Colorado Springs, CO, United States - **Salary:** $104,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cyber Security, Information Systems, Software Design Documents, Linux, Internet Protocol, Network Architecture, Systems Development Life Cycle, SAP (Applications), Security Content Automation Protocol, Cloud Platform System, Kubernetes Helm Charts, Firewalls (Computer Science), Gitlab, Containerization, Kubernetes, Information Technology, Cyber Warfare, Software Version Control, Devsecops, Service Stack, Vulnerability Analysis, Vmware - **Published:** August 11, 2026 - **Apply:** https://kbr.wd5.myworkdayjobs.com/KBR_Careers/job/Colorado-Springs-Colorado/Information-Systems-Security-Officer--ISSO-_R2128081 ## About the Role * Security Clearance: Active TS/SCI, eligible for SAP * Education: BS degree in Computer Science or Information Systems. Other degrees will be considered with relevant work experience. * One or more of the following certifications (must be current): CISM, CISSO, FITSP-M, GCIA, GCSA, GCIH, GSLC, GICSP, CISSP, CISSP-Associate, CISSP-ISSMP * At least four (4) years of experience applying the DoD Risk Management Framework (RMF), including: NIST SP 800-53, DISA STIGs, SCAP and IAVAs, FISMA * Experience managing cybersecurity projects in cloud environments (AWS, Azure, or VMware) * Experience supporting ATO processes, POA&Ms, and cyber strategy development in federal or military environments * Knowledge of Linux and Windows Operating Systems * Knowledge of networking architecture and devices and supporting infrastructure, including IDSs, firewalls, and CDSs * Experience with Kubernetes and containerization * Strong passion for conducting independent research, tackling complex problems, and continuously learning and adopting new technologies * Excellent communication and collaboration skills * Strong problem-solving and analytical skills * Ability to work in a fast-paced environment and meet deadlines Desired Qualifications: * At least eight (8) years of experience analyzing, assessing, and implementing corrective actions based on vulnerability scanning and penetration testing results * At least eight (8) years of experience supporting defensive cyber operations for DoD, including incident handling, reporting, system defense, and information recovery * Knowledge of Cybersecurity Process and Approval for Special Access Programs (SAPs) * DevSecOps experience integrating security measures throughout the entire SDLC * Familiar with air-gapped Kubernetes deployments using Helm charts and Zarf * Proficient in using GitLab for version control, CI/CD pipelines, and collaboration * Experienced in leveraging Agile Software Development methodologies for efficient and iterative project management * High level of curiosity and investigative mindset with an attention to detail, a tenacity of thought, the flexibility to adapt to new challenges, and the resiliency to overcome short-term hurdles by staying focused on the team's deliverables ## Description * Architect, develop and implement out-of-the-box cyber solutions to meet warfighter needs and ensure end-to-end security * Serve as a cybersecurity advisor to the Government * Analyze customer requirements and identify the need for cybersecurity solutions * Develop and maintain a deep understanding of the organization's overall technology landscape * Create and maintain documentation for systems, enclaves, applications, including design documents, implementation guides, standard operating procedures, and approval paperwork * Oversee implementation of RMF, NIST SP 800-53, and STIG requirements, ensuring alignment with DoD security mandates * Perform vulnerability assessments, support remediation of scan findings and IAVAs, and manage incident response workflows and recovery operations to maintain hardened security posture * Support security documentation, security control assessments, and continuous monitoring in alignment with FISMA * Loading and managing cryptographic keys for High Assurance Internet Protocol Encryptors (HAIPE) * Provide expert guidance in support of cyber audits, ATO packages, and continuous compliance processes * Engage with customers to better define the problem space and vision to determine capabilities and priorities for prototypes * Work across multiple technology stacks, gaining hands-on experience with various languages, frameworks, and tools to support a broad range of applications ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)