> Markdown version of [/jobs/ext/2028022-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/2028022-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Booz Allen Hamilton Inc. - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Systems Engineering, Big Data, Cyber Security, Systems Analysis, Nmap, Software Vulnerability Management, HP WebInspect, Cloud Platform System, Azure Security Center, SC Clearance, Tenable Nessus, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87998497/1 ## About the Role * 5+ years of experience with information assurance or cybersecurity * Experience serving as an Information Systems Security Officer (ISSO) * Experience managing and administering Assured Compliance Assessment Solution (ACAS) and Host-Based Security System (HBSS) * Experience utilizing the Enterprise Mission Assurance Support Service (eMASS) to address security controls, create POA&Ms, and upload artifacts such as STIG checklists or ACAS scans * Experience supporting system security and authorization processes * Experience reviewing vulnerability documentation and writing residual risk statements * Experience reporting IT security events or incidents based on policies and procedures * Knowledge of Microsoft Defender for Endpoint (MDE) * Secret clearance * HS diploma or GED Nice If You Have: * Knowledge of cloud-based infrastructure and DevSecOps principles and practices * Ability to use and operate security tools, including Tenable Nessus, SecurityCenter, IBM Guardium, HP WebInspect, or Network Mapper * Bachelor's degree in IT ## Description Join a team of communications and systems engineers supporting engineering, sustainment, and management of communications systems. Perform ongoing system analysis activities for programs. Perform risk assessments of systems and equipment, assist engineers with identifying solutions for vulnerabilities, create and map Security Technical Implementation Guides (STIGs), submit change requests for system components, develop a Plan of Action and Milestones (POA&M), create documentation supporting Risk Management Framework (RMF) accreditations, perform vulnerability management using automated systems, and create and submit RMF packages. Brief the technical security posture to client leadership, prepare brief slides and summaries of vulnerabilities, and advise on how to prevent and mitigate future security threats. Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Implement infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises.Perform risk and vulnerability assessments in network, system, and application areas. Leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)