> Markdown version of [/jobs/ext/2096848-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2096848-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** BOMBECK FAMILY LEARNING CTR - **Location:** Dayton, OH, United States - **Experience:** Experienced - **Contract:** Contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Identity and Access Management, Secure Coding, Microsoft SharePoint, Software Vulnerability Management, Google Cloud, Office365, Information Technology, Performance Monitor, Operational Systems - **Published:** August 17, 2026 - **Apply:** https://secure.dc4.pageuppeople.com/apply/875/gateway/default.aspx?c=apply&lJobID=503796&lJobSourceTypeID=796&sLanguage=en-us ## About the Role * Associates Degree in Cybersecurity, Computer Science, or related field * 3+ years relevant cybersecurity experience * Experience with the NIST RMF process * Security Technical Implementation Guides (STIGs) application experience * The applicant must meet DoD 8140 (formerly 8570) Compliance: IAT Level II or higher certification requirements on hire date (Security+ CE) * Familiarity with the DOD Information Assurance Vulnerability Management program * Effective verbal and written communication skills * Ability to obtain a Secret level security clearance * US Citizenship An R3 must meet all R2 minimum qualifications in addition to the qualifications listed below. * A minimum of eight years of directly related experience Preferred Qualifications: While not everyone may possess all of the preferred qualifications, the ideal candidate will bring many of the following: * 5+ years' DoD cybersecurity experience * IAT Level III or IAM Level I Certification * Bachelor's Degree in Cybersecurity, Computer Science, or related field * Additive Manufacturing experience * Systems Administration experience * Experience with Secure Development Operations Systems, as either a user, developer, or system administrator * Experience with submission of system security package to DoD for ATO, IATO, etc * Active Secret level security clearance. * Familiarity with Enterprise Mission Assurance Support Service (eMASS). * Experience with approved government cloud services such as Microsoft Azure, Amazon Web Services, Google Cloud. * Relevant cloud infrastructure and security certifications (i.e. Office365, SharePoint, Amazon AWS) * Cloud Application experience * Experience managing various project activities ensuring accurate task completion Special Instructions to Applicants ## Description Secure Innovation. Strengthen Readiness. The Information System Security Officer (ISSO) position is supporting the Air Force Rapid Sustainment Office (RSO). The RSO increases mission readiness by rapidly identifying, applying and scaling technology essential to the operation and sustainment of the U.S. Air Force. Success comes from our teamwork and mutual respect for each other's talents and unique perspectives. This role supports the government cyber lead and provides cybersecurity support for advanced software-intensive technologies to include agile manufacturing, conditioned-based maintenance, augmented reality/virtual reality, cloud-based infrastructure and services, and robotics. Responsibilities: * Serve as cybersecurity technical advisor, consultant, and primary point of contact to the Program Manager, Information System Owner, and other stakeholders for the Information systems * Assessing systems for vulnerabilities and providing corrective recommendations. * Supporting government Cyber lead in performing RMF activities leading to system RMF acceptance IAW DoDI 8510.01, NIST 800-series special publications, USAF policy and instructions, and guidance as applicable on RSO IT systems in networked, standalone, and cloud configurations. * Support, coordinate, and continuously monitor system security posture and ensure adverse events are formally handled and reported * Developing, reviewing, and updating necessary documentation associated with achieving RMF accreditation of each system. * Applying currently accepted methods for documenting the RMF status of each RSO system within the DoD environment. * Security Technical Implementation Guides (STIGs) for all systems * Managing projects in compliance with DoD and AF RMF policies including but not limited to the following: o DoDI 8500.01 - Cybersecurity Risk Management Framework for DoD Information Technology. o DoD 8140 (formerly 8570) o CNSSI 1253 - Security Categorization and Control Selection for National Security Systems. o NIST 800-series Special Publications (SP). o Computer Security, including SP 800-53 - Security Controls and Assessment Procedures for Federal Information Systems and Organizations and Air Force Instruction Series 17. Cyberspace: Accomplishing system categorization, security control selection, security control implementation, security control assessment, and security control monitoring, including, but not limited to, accomplishing the RMF steps as outlined in DoDI 8510.01 on a system-by-system basis * Providing system performance reporting. * Support System Administrator for multiple cloud projects and implementations. * Supporting Interim Authority to Test (IATT)/ Authority to Operate (ATO) planning and execution. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)