> Markdown version of [/jobs/ext/2461460-ewan-information-system-security-officer-isso-onsite](https://www.wearedevelopers.com/jobs/ext/2461460-ewan-information-system-security-officer-isso-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # eWAN Information System Security Officer (ISSO) (Onsite) - **Company:** RTX - **Location:** Tewksbury, MA, United States - **Experience:** Experienced - **Salary:** $86,800.0 - $165,200.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Configuration Management, Cyber Security, File Transfer, Identity and Access Management, Information Security Management, Network Security, Linux System Administration, Scaled Agile Framework, Security Content Automation Protocol, Security Information and Event Management, Software Configuration Management, Information Security Management System, National Industrial Security Program Operating Manual (NISPOM), Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fd9511be1d238181 ## About the Role * Typically requires a University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years experience. * Experience managing and implementing security program requirements in a classified environment. * Compliance-based auditing using the RMF, Defense Counterintelligence and Security Agency (DCSA) Assessment and Authorization Process Manual (DAAPM), National Industrial Security Program Operating Manual (NISPOM). * Certifications equivalent to or exceeding DoD 8570.01-M IAM Level I (Security+ or other). * Knowledge and/or experience with STIGs, SCAP, Splunk, Tenable or other system hardening and compliance, vulnerability assessment, network security and/or SIEM tools. * Active and transferable secret U.S. government issued security clearance is required prior to start date., * Experience working in DoD classified operating environments and/or in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF), NIST 800-53- Rev 4. * Experience with Scaled Agile Framework (SAFe) work practices. * Experience with large multi-facility networks of complex components, including Windows and Linux environments. * Excellent oral and written communication skills with attention to detail and ability to multitask. * Ability to adapt to rapidly changing environment and work under pressure to meet project deadlines. ## Description The ISSO assists the Information System Security Manager (ISSM) to provide oversight for the information systems security control methods, mitigations, and tools throughout a systems' lifecycle in compliance with U.S. Department of Defense (DoD) security laws, regulations and guidelines. The ISSO will participate in projects, guide and counsel internal customers, assist in developing and maintaining program/dataset specific processes and standards, and provide training and guidance on tools and methods to other members of the cybersecurity team. What You Will Do: * Responsible for assessing and monitoring system compliance, auditing, security plan development, and delivering information systems security education and awareness. * Assists in investigating information system security violations and preparing reports specifying corrective and preventative actions. * Responsible for reviewing and approving configuration management requests within delegated authority, conducting technical and administrative security assessments, and performing security sustainment activities including hardware and software change management, account management, media protection, and file transfer reviews. * Support the integration of new cybersecurity processes, procedures, and tools, assists with the creation and maintenance of cybersecurity documentation, and ensures audit records are collected and analyzed in accordance with approved security plans. * Develop, update, and/or review Risk Management Framework (RMF) documentation to include the System Security Plan (SSP), Security Control Traceability Matrix (SCTM), Plan of Action and Milestone (POA&M), Risk Assessment Report (RAR), as assigned by the ISSM. * Collaborate with CDS and peer BU ISSMs/ISSOs for alignment and sharing of best practices., Whether you're just starting out on your career journey or are an experienced professional, we offer a robust total rewards package with compensation; healthcare, wellness, retirement and work/life benefits; career development and recognition programs. Some of the benefits we offer include parental (including paternal) leave, flexible work schedules, achievement awards, educational assistance and child/adult backup care. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Devouring APIs with Python](https://www.wearedevelopers.com/videos/355-devouring-apis-with-python) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)