> Markdown version of [/jobs/ext/232708-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/232708-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** AEVEX - **Location:** Dayton, OH, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Configuration Management, Cyber Security, Information Security Management, Network Security, Windows Servers, Data Processing, Information Security Management System, Information Technology, Splunk, User Administration, Vulnerability Analysis - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b9c127c4a9280c70 ## About the Role Do you have experience in Windows?, Do you have a Bachelor's degree?, * Strong working knowledge of DoD RMF, NIST SP 800-53, CNSSI, and related security policies. * Knowledge of access control procedures, media control, classified data handling, and COMSEC requirements * Experience with Windows Server, Active Directory, endpoint security tools, and network security concepts * Hands-on experience administering or monitoring security tools such as Splunk Enterprise * Excellent written and verbal communication skills with strong documentation abilities. * Ability to work effectively in a secure, compliance-focused environment. Education / Certifications * DoD 8570/8140 compliant certification (Security+, CISSP, or equivalent) required. * Bachelor's degree in Information Technology, Cybersecurity, or a related field preferred. Experience * 3+ years of ISSO or relevant DoD cybersecurity experience supporting classified systems. * Hands-on experience with eMASS, ACAS, STIGs, and security documentation. * Experience supporting classified environments and secure facilities. ## Description As an Information System Security Officer (ISSO) - Classified Systems, you will be responsible for maintaining the security posture and regulatory compliance of classified information systems and secure rooms in accordance with DoD regulations and the Risk Management Framework (RMF). This role ensures the confidentiality, integrity, and availability of classified information in a secure production environment., * Maintain the security posture of the classified system and secure room, ensuring daily compliance with DoD, NIST, and RMF requirements. * Manage RMF documentation including System Security Plan (SSP), Plan of Action and Milestones (POA&M), and continuous monitoring activities. * Conduct vulnerability scanning, risk assessments, and remediation using tools such as ACAS and STIGs. * Support Authority to Operate (ATO) packages, security incident response, and configuration management. * Serve as the primary security Point of Contact (POC) for the system, working closely with system owners and authorizing officials. * Perform classified material control, user access management, and security awareness activities. * Perform other duties as required. Standard Essential Functions * Regular and reliable attendance on a full time basis [or in accordance with posted schedule]. * Responsible for exhibiting professional behavior with both internal and external business associates that reflects positively on the company and is consistent with the company's policies and practices. * Embodies AEVEX's cultural values and aligns daily actions with department goals and company culture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)