> Markdown version of [/jobs/ext/2156368-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2156368-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Booz Allen Hamilton Inc. - **Location:** Fayetteville, NC, United States - **Experience:** Experienced - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Network Security, Cybercrime, Plan of Action and Milestones - **Published:** August 20, 2026 - **Apply:** https://justjobs.com/main/sendform/8/8/28176/1/18007880?backUrl=%2Fcareer%2F18007880%2FInformation-System-Security-Officer-North-Carolina-Fayetteville ## About the Role * 5+ years of experience leading and implementing the Assessment and Authorization process under Risk Management Framework for new and existing information systems * 3+ years of experience reviewing assessment reports and assisting projects in identifying security risks, including technical and non-technical, and developing effective mitigation strategies, including Plan of Action and Milestones * 3+ years of experience managing ATO packages in eMASS * Experience applying abstract security requirements, including NIST 800-53 controls to information systems * Experience in an advisory environment and communicating technical subjects to clients * Knowledge of supporting the development or modification of System Security Plans, security requirements, and supporting documentation for the Assessment and Authorization process * Ability to ensure all products and administrative documentation is completed and maintained, including for continuity and historical reference, and design, develop, and implement network security measures that provide confidentiality, integrity, availability, authentication, and non-repudiation * Top Secret clearance * HS diploma or GED * DoD 8570 IAM Level III Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required. ## Description Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the Department of Defense (DoD). In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is a lead information security risk specialist like you who can break down complex threats into manageable plans of action. As an information security risk specialist on our team, you'll advise for the DoD, leading the discovery of their cyber risks, understanding applicable policies, and developing a mitigation plan. You'll oversee the analysis of technical and personnel details from operations and engineers as your team reviews the entire threat landscape. Then, you'll guide your team through a plan of action with task breakdown, presentations, policy, and milestones. Your client will rely on you to translate security concepts to your team members so they can make the best decisions to secure their simulation training network. This is your opportunity to take a leadership role in information security while sharing your skills in network defense, incident management, and threat analysis with both your clients and your team. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Blockchains: One Size doesn't Fit All](https://www.wearedevelopers.com/videos/409-blockchains-one-size-doesn-t-fit-all) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)