> Markdown version of [/jobs/ext/2577907-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2577907-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Booz Allen Hamilton Inc. - **Location:** United States - **Experience:** Experienced - **Salary:** $62,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Databases, Information Security Management, SAP (Applications), Software Security, Patch Management, Splunk - **Published:** August 2, 2026 - **Apply:** https://justjobs.com/main/sendform/8/8/28176/1/17796779?backUrl=%2Fcareer%2F17796779%2FInformation-System-Security-Officer-California-El-Segundo ## About the Role * Experience supporting collateral and special access program (SAP) environments and managing and safeguarding information systems in classified environments * Experience conducting security assessments, auditing, continuous monitoring, and implementing and maintaining RMF-based security controls * Knowledge of incident response processes and reporting requirements * Knowledge of information system hardening, secure configuration baselines, patch management, and security tools such as ACAS, HBSS, ESS, or SPLUNK * Knowledge of government security policies such as DoD 5200.01, ICDs, and CNSSI 1253 and NIST SP 800-53, DoD RMF, JSIG, and DAAG standards * Ability to apply security policies and procedures to ensure database and software security and analyze moderately complex security issues and develop practical solutions * TS/SCI clearance * Bachelor's degree and 4+ years of experience with Information System Security or Master's degree and 2+ years of experience with Information System Security * DoD 8140 baseline Certification such as Security+ CE Certification Nice If You Have: * Experience reviewing and updating system security documentation such as SSPs, SCTMs, or POA&Ms * Ability to communicate effectively with technical and nontechnical stakeholders, work independently with moderate guidance, and assist junior personnel in understanding security requirements * Possession of sufficient technical competence commensurate with the complexity of the systems * CISSP or CAP Certification ## Description * Ensuring systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the security plan. * Verifying the implementation of delegated aspects of the system security program. * Ensuring all proper account management documentation is completed prior to adding and deleting system accounts. * Verifying all system security documentation is current and accessible to properly authorized individuals. * Conducting periodic assessments of authorized systems and providing the ISSM with corrective actions for all identified findings and vulnerabilities. * Ensuring audit records are collected and analyzed in accordance with the security plan. * Reporting all security-related incidents to the ISSM. * Monitoring system recovery processes to ensure security features and procedures are properly restored and functioning correctly. * Formally notifying the ISSM of any changes to a system that could affect authorization. * Serving as a member of the Configuration Control Board (CCB), if designated by the ISSM. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)