> Markdown version of [/jobs/ext/2147224-cyber-security-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/2147224-cyber-security-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security, Information Systems Security Officer - **Company:** BAE Systems - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Salary:** $97,008.0 - $164,914.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Configuration Management, Cyber Security, Information Systems, Desktop Computing, Linux, File Systems, Identity and Access Management, Information Security Management, Networking Hardware, Security Content Automation Protocol, C4ISR, Peripherals, Information Technology, Nessus, National Industrial Security Program Operating Manual (NISPOM), Vulnerability Analysis, User Accounts - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/80D3020B14D84C5BB0AC2B544D6946A3/job/ ## About the Role * IAM Level I certification commensurate with DoD 8570.1M requirements (or ability to obtain certification within 6 months) * 4 or more years of Information Security or relevant cybersecurity experience * Minimum of a High School Diploma * High level of personal motivation and initiative to learn and acquire new skills, and adapt seamlessly to an ever-changing security environment. * Customer focused, excellent communicator and ability to work with limited supervision. * Strong organizational skills * Able to interface with other IA team members, other security disciplines (industrial security, physical security, special programs security, etc.), program personnel and government security representatives. * Support the ISSM to ensure all security certification and accreditation documents in relation to all classified systems are up-to-date. * Ensure continuous monitoring (e.g. weekly, monthly, etc.) in accordance with cognizant security authority requirements are being implemented and met. * Experience with compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC). * Experience with validating compliance of various systems (Windows, Linux, Network Devices and peripherals). * Experience with IA configuration management and change request processes. * Experience with conducting regular audits to ensure that systems are being operated securely, and information systems security policies and procedures are being implemented as defined in security plans. Preferred Education, Experience, & Skills * Working knowledge of system functions, security policies, technical security safeguards, and operational security measures. * Bachelors Degree * Experience with the review and creation of mitigation reports from compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC). * Experience with the preparation for Assessment and Authorization s (A&A) * Experience with the development of core documentation including System Security Plans, Standard Operating Procedures, Plan of Actions and Milestones, Remediation Plans, and Configuration Management Plans. * Experience with development and delivery of IA-related briefings and training material. * Experience in conducting routine investigations of information systems security violations and incidents, reporting as necessary to management * Ability to translate operational requirements into technical requirements and architectures needed to meet program objectives * Experience with conducting all aspects of a self-inspection * Experience with periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and integrity scans to determine compliance * Prepares incident reports of analysis methodology and results * Knowledge of new and emerging information technology (IT) and cybersecurity technologies. ## Description See what you re missing. Our employees work on the world s most advanced electronics from detecting threats for F-35 pilots to illuminating the night for soldiers. Spanning air, land, sea, and space, we are developing the technology of tomorrow, delivered today. Drawing strength from our differences, we re innovating for the future. And you can, too. Our flexible work environment provides you a chance to change the world without giving up your personal life. We put our customers first exemplified by our mission: We Protect Those Who Protect Us. Sound like a team you want to be a part of? Come build your career with BAE Systems. In Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR) Systems, you ll help develop systems that sense, control, exploit and disseminate actionable information to warfighters supporting a variety of missions. Continue your career as a cybersecurity professional with BAE Systems, supporting and protecting information systems critical to national security at one of the leading companies in Aerospace and Defense. Develop your Information Assurance (IA) career through hands on application, work with seasoned professionals, and a training and development plan designed to grow your skills in a fast paced, team-based environment. If you are looking to learn, influence, and help develop top cyber technologies, applications, and processes that protect and service our customers wherever they may be air, land, and sea come join our award-winning security family here at Electronic Systems (ES). Responsible for supporting adherence to all aspects of a rigorous Risk Managed Framework (RMF) compliance program as stipulated by NISPOM/DAAPM, JSIG, ICD 503, STIGs and associated NIST publications. Support the Information System Security Manager in obtaining and maintaining Authority to Operate (ATO) approvals for various systems by adhering to the Risk Management Framework (RMF). This position supports cybersecurity efforts throughout the RMF process for one or more assigned programs(s) to include supporting the development and management of System Security documentation, Plans of Action and Milestones (POA&Ms), assessing and auditing systems security controls, and continuous monitoring of controls. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)