> Markdown version of [/jobs/ext/2560729-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/2560729-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Everforth Apex - **Location:** Linthicum Heights, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Access Network, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Databases, Firmware, Security Information and Event Management, Software Engineering, Apex Code, Computer Networking Systems, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/599ba02d-d47d-4ccd-b54e-75e617fd8333 ## About the Role Apex Systems Inc., is immediately seeking an Information Systems Security Officer (IA 2/3) who is a self-starter, highly organized, has a strong drive for quality, and eagerness to learn/grow. This position will support one of our highly-regarded clients in the government arena, and offer a strong upside for growth within the organization. The qualified applicant will have worked in secured federal government facilities in the past, have a strong understanding/background in ICD 503 (RMF)/JSIG/JAFAN, and have past experience in an ISSM or ISSO role., * Bachelor's Degree with 2-5+ years of experience; or 10+ years of relevant work experience in lieu of degree. Degree must be in a Computer Sciences, Cybersecurity, Management Information Systems, or related field. * DOD 8570 Compliant; Must have one of the following: Security+, CISSP, CISM, CAP, CASP, GSLC, CISSO * 3-5+ years of past experience in an ISSM/ISSO role or similar joint responsibilities * Experience with SCIF/SAPF/Secured environments * Knowledge of NISPOM information system requirements, particularly chapter 8; MCITP/MCSA 2008/2012 & NIST/RMF/NISPOM/JAFAN/DCID 6/3 knowledge + RMF is the focus. * ICD 503 (RMF), JSIG, and JAFAN knowledgeable * Knowledge of and experience with Defense Security Service ODAA processes and procedures * Windows environment experience; and the ability to develop and implement IS certification test(s) and conduct ongoing periodic reviews, * Hands on experience with vulnerability scanning tools (ie. NessSecurity Center) * Experience/Knowledge of Splunk or other SIEM (Security Information and Event Management) products * Knowledge of Windows security / group policy and Cisco networking * Involvement in security audits/inspections * Familiarity with DISA Security Implementation Guides (STIGs) * Background of understanding of System Security Plans (SSP) ## Description * Designs, tests, and implements state-of-the-art secure operating systems, networks, and database products * Conducts risk assessment and provides recommendations for application design * Participate in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access * Uses encryption technology, penetration and vulnerability analysis of various security technologies, and information technology security research; and may prepare security reports to regulatory agencies * Ensures systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan * Ensures that all users have the requisite security clearances, authorization, and need-to-know, and are aware of their security responsibilities before granting access * Ensures configuration management (CM) for security-relevant IS software, hardware, and firmware is maintained and documented * Ensures all information system security-related documentation is current and accessible to properly authorized individuals * Maintains records, outlining required patches/system upgrades that have been accomplished throughout the information system's life cycle * Ensures that all systems/network are compliant and in scope of current accreditation * Evaluates proposed changes or additions to the information system, and advises the Information Systems Security Manager (ISSM) of their security relevance * Create and maintain Plan of Action and Milestones (POAM) or Risk Acceptance/Acknowledgement Letters (RALS) * Assist with security education / Conduct training sessions * Participate in internal / external security audits/inspections * Directs program system administrators on security matters * Performs weekly audits as directed by the Information Systems Security Manager (ISSM) ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)