> Markdown version of [/jobs/ext/2067655-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2067655-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Mantech International Corporation - **Location:** Stafford, VA, United States - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Backup Devices, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Information Security Management, Networking Hardware, Intrusion Detection and Prevention, Systems Architecture, Software Vulnerability Management, Information Technology, Epic ECSM, Network Server, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 15, 2026 - **Apply:** https://dejobs.org/x/x/84223042335D4393BF1E41059414AAD3/job/ ## About the Role MANTECH seeks a motivated, career and customer-oriented Information System Security Officer to support our contract under Marine Corps Systems Command (MCSC) out of Quantico, VA. The successful candidate will support the security compliance, and ongoing authorization of United Stated Marine Corps Systems., * Bachelor's Degree and at least 6 years of related experience (additional 2 years of experience may be substituted in lieu of degree. * Must be compliant and certified at the DoW 8140 intermediate level, thus will need a CASP, Security+, CISSP, or CISM certification. * Knowledge of federal requirements: NIST SP 800-53, CNSSI 1253. FIPPS199 and FIPS 200, ECSM 018, etc. * Demonstrates understanding of cybersecurity compliance frameworks, security controls, and system authorization processes. * Strong understanding and experience of using Enterprise Mission Assurance Support Service (eMASS). i.e. importing, exporting, maintaining system packages through all steps of RMF. * Experience supporting security audits, vulnerability assessments, and compliance activities., * Ability to effectively collaborate with technical teams, cybersecurity professionals, and government authorizing organizations. (translating the RMF security controls into practical technical configurations and system architecture designs) * Comprehensive knowledge of enterprise information technology, cybersecurity, and information assurance principles, including data backup and recovery, system functionality, security controls, continuous monitoring, intrusion detection, penetration testing, and defense-in-depth strategies. * Demonstrates ability to think critically, analyze complex information, identify potential issues, and develop effective solutions with minimal oversight. * Experience assessing, documenting, and clearly communicating cybersecurity and compliance risks to both technical and non-technical stakeholders Security Clearance Required: * Must have a current / active Secret clearance Physical Requirements: * Sedentary work ## Description * This position will work closely with technical teams, security stakeholders, and authorizing agencies to protect information system assets, maintain compliance requirements, identify and mitigate cybersecurity risks, and support ongoing Authorization to Operate (ATO) activities. * Prepare, review, and maintain security documentation including System Security Plans (SSPs), Risk Assessment Reports, Security Requirements Traceability Matrices (SRTMs), and authorization packages. * Maintain the operational security posture of assigned information systems and ensure compliance with established security policies, standards, and procedures. * Conduct and support Security Technical Implementation Guide (STIG) compliance reviews across infrastructure components including servers, network devices, operating systems, and applications. * Assisting the Information System Security Manager (ISSM) with managing Plan of Action and Milestones (POA&Ms), ensuring the technical vulnerabilities are tracking, remediated, or mitigated with acceptable workarounds. * Initiating corrective and protective security measures in coordination with the ISSM when threats or active Vulnerabilities are discovered. Assisting mthe ISSM in monitoring, reporting, and enforcing Information Assurance Vulnerability Management (IAVM). * Collaborate with engineering and operational teams to resolve security findings and maintain compliance throughout the system lifecycle. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)