> Markdown version of [/jobs/ext/2290532-information-systems-security-officer-grand-forks-north-dakota](https://www.wearedevelopers.com/jobs/ext/2290532-information-systems-security-officer-grand-forks-north-dakota). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - Grand Forks, North Dakota - **Company:** York Inc - **Location:** Grand Forks, ND, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Backup Devices, Cloud Computing, Cloud Computing Security, Configuration Management, Cyber Security, Firmware, Identity and Access Management, Information Security Management, Security Content Automation Protocol, Security Information and Event Management, Data Streaming, Software Vulnerability Management, Data Logging, Cloud Platform System, SC Clearance, Information Technology, Tenable Nessus, Cloudwatch, Splunk, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9125072/information-systems-security-officer-grand-forks-north-dakota ## About the Role The candidate must understand DoD Risk Management Framework (RMF) requirements and possess sufficient AWS cloud knowledge to evaluate security configurations, analyze evidence, identify risk, and collaborate with technical and government stakeholders., * Five or more years of information assurance, cybersecurity, or RMF experience supporting the U.S. Government or a government contractor. * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field; equivalent experience may be considered. * Experience developing DoD authorization documentation and maintaining eMASS packages. * Working knowledge of DoD RMF, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A, and applicable cybersecurity requirements. * Experience with DISA STIGs, SCAP, STIG Viewer, and ACAS/Tenable Nessus or comparable tools. * Familiarity with AWS architecture, IAM, networking, encryption, logging, monitoring, and the shared-responsibility model. * Experience with AWS security services, inherited controls, Splunk, or other SIEM tools. * Ability to interpret cloud and Space Vehicle technical evidence and communicate remediation requirements. * Security+ or another qualification satisfying applicable DoD 8140/DCWF requirements. * Active Secret clearance with eligibility to obtain and maintain Top Secret clearance and required program access. * Strong communication, documentation, risk-analysis, and independent task-management skills. * Willingness to work full-time in office in Grand Forks, ND. Preferred for the Role * Experience supporting AWS GovCloud IL5, classified AWS IL6, or Space Vehicle authorization packages. * Experience supporting multiple authorization boundaries, ATOs, or IATTs. * Familiarity with spacecraft, flight software, firmware, payloads, ground systems, or mission interfaces. * Experience supporting DCSA, SDA, Space Force, or comparable DoD programs. * CISM, AWS Certified Security - Specialty, or comparable certification. ## Description York Space Systems is seeking an experienced Information System Security Officer (ISSO) to support AWS GovCloud IL5 and applicable AWS IL6 environments. The ISSO will assist the Information System Security Manager (ISSM) with authorization, security-control implementation, continuous monitoring, vulnerability management, and maintenance of the cybersecurity posture for assigned authorization boundaries., * Support RMF, IATT, ATO, and continuous-monitoring activities for cloud environments and Space Vehicle systems. * Coordinate with the ISSM, system owners, administrators, engineers, assessors, and government stakeholders. * Develop and maintain SSPs, SCTMs, POA&Ms, SOPs, contingency plans, configuration documentation, and assessment evidence. * Evaluate AWS shared-responsibility requirements, inherited controls, Customer Responsibility Matrices, and DoD Cloud Computing SRG requirements. * Review cloud security configurations involving IAM, networking, encryption, logging, monitoring, backups, and vulnerability management. * Analyze evidence from CloudTrail, Config, Security Hub, Guard Duty, Cloud Watch, Systems Manager, Inspector, and AWS Backup. * Support Space Vehicle authorization packages by reviewing applicable architectures, interfaces, hardware, software, firmware, and security-control documentation. * Assess vulnerability scans, audit logs, compliance results, and technical findings; coordinate remediation with administrators and engineers. * Review DISA STIGs, SRGs, SCAP results, system inventories, change requests, and security impacts across assigned authorization boundaries. * Evaluate relevant interfaces and data flows among cloud environments, ground systems, Space Vehicles, and mission components. * Support incident response, data-transfer requirements, media protection, and Configuration Control Board activities. * Lead System level change request through formalized Configuration Control boards (CCB) * Notify the ISSM of security incidents, unauthorized changes, control deficiencies, or other conditions affecting authorization or operational risk. * Other Duties as Assigned. This role will not have direct reports. ## Related Videos - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [From Black Box to Glass Box : Bedrock AgentCore Observability](https://www.wearedevelopers.com/videos/2126-from-black-box-to-glass-box-bedrock-agentcore-observability) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)