> Markdown version of [/jobs/ext/2271708-mid-career-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2271708-mid-career-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid-Career Information System Security Officer - **Company:** Lockheed Martin - **Location:** Littleton, CO, United States - **Experience:** Experienced - **Salary:** $95,900.0 - $178,100.0 - **Contract:** Permanent contract - **Skills:** Xacta, Agile Methodology, Artificial Intelligence, Confluence, JIRA, Configuration Management, Cyber Security, Information Systems, Firmware, Identity and Access Management, Information Security Management, Networking Hardware, Ansible, Security Software, Security Information and Event Management, Git, Containerization, National Industrial Security Program Operating Manual (NISPOM), Splunk, Devsecops, Docker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 27, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9122406/mid-career-information-system-security-officer ## About the Role * Active Secret security clearance. * Ability to obtain and maintain TS/SCI clearance. * DoD 8570/8140 IAT Level II certification (e.g., Security+ CE, CySA+, CCNA Security, CND). * Proven hands on experience with industry standard cybersecurity tools, including vulnerability scanners (e.g., Tenable), Security Incident and Event Management (SIEM) and auditing platforms (e.g., Splunk), endpoint protection solutions (e.g., Trellix), and package submission tools (e.g., eMASS, XACTA) * Demonstrated ability to lead the Risk Management Framework (RMF) process to secure Authorizations to Operate (ATO), encompassing Defense Counterintelligence and Security Agency (DCSA) authorizations. * Strong technical root cause analysis skills with a track record of developing corrective actions, policies, and procedures to resolve discrepancies. * Experience conducting risk and vulnerability assessments in line with applicable regulations, such as the DCSA Assessment and Authorization Guide (DAAG), National Industrial Security Program Operating Manual (NISPOM), NIST Special Publication (SP) 800-53, and various DISA Security Technical Implementation Guides (STIGs) Desired Skills * DoD 8570/8140 IAM Level II certification (e.g., CISSP, CISM, CASP+/SecurityX). * Proven track record of deploying and integrating complex, multi-classification technologies across large-scale, enterprise-wide environments. * Network device administration experience to include security best practices and monitoring of firewall, routers, and switches. * Direct experience with the Signals Reconnaissance program. * Strong background in Agile and DevSecOps methodologies and associated toolsets (e.g., JIRA, Confluence, Docker, Ansible, Git). * In-depth knowledge of the NISPOM and the DAAG. * Familiarity with key security frameworks and guidelines, including the Joint Special Access Program (JSIG) Implementation Guide, CNSSI 1253, and NIST SP 800-37 (Risk Management Framework) * Experience with containerization * Proficient in AI prompting as it applies to this position and practice. ## Description * Coordinating and managing interactions with government partners to facilitate and maintain 100% active status of all Authorizations to Operate. * Overseeing technical administration of information system in accordance with internal LM and customer security requirements, primarily Risk Management Framework (RMF) to include Continuous Monitoring, Plan of Action and Milestones (POA&M), and Change Management. * Developing and implementing government-approved information system security procedures and system security plans for the operation of networked and standalone classified systems. * Communicating, implementing, and managing a formal cybersecurity program * Overseeing and conducting risk assessments on cybersecurity architecture and perform comprehensive investigations of computer security incidents, collaborating with outside agencies as required. Other Key Responsibilities and Challenges of this role include (modify as appropriate for the position): * Ensure configuration management (CM) for security-relevant software, hardware, and firmware. * Assist and conduct cybersecurity education and training. * Assist in conducting investigations of computer security violations and incidents. * Handling mission requirements which may drive unpredictable work hours/schedules * Working in a high paced environment driven by growing and ever-changing technical implementation requirements ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)