> Markdown version of [/jobs/ext/2632494-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2632494-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Amentum Services, Inc. - **Location:** Sunnyvale, CA, United States - **Experience:** Expert - **Salary:** $175,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Cloud Services, Software Requirements Analysis, Information Security Management System, SARS Software Products, Plan of Action and Milestones - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/F0451B3155374298B4B91B7F02AEBFB2/job/ ## About the Role * Must have an active Top Secret US Government Clearance, with the ability to obtain an SCI Clearance. Please note US Citizenship is required to maintain a Top Secret Clearance. * Bachelor of Science degree with 5 years of professional experience in cybersecurity design and development activities * Strong oral and written communication skills Desired qualifications: * SCI clearance eligibility * Experience in NASA Security or served as an ISSO in other agencies. * Experience in NASA Risk Information Security Compliance System and Assessment and Authorization. * Experience with Cloud Services and classified networks. * Certification level to meet DoD 8140 IAT or DoD 8570 IAT Level II certification or higher. ## Description * Develop and maintain detailed and accurate System Security Plans (SSP), including security documentation for component and interface specifications, to support appropriate cybersecurity and privacy throughout the information systems' life cycle * Assist the Information System Owner (ISO) and Information System Security Manager (ISSM) in ensuring that all components of the information system are appropriately updated and patched in accordance with Federal and NASA requirements * Support the Government with identifying and prioritizing essential system functions or sub-systems required to support essential capabilities or business functions for restoration or recovery after a system failure or during a system recovery event based on overall system requirements for continuity and availability * Provide technical guidance to address the adequacy and effectiveness of information security policies, procedures, and practices * Ensure that cybersecurity design and development activities are properly documented (providing a functional description of security implementation) and updated as necessary * Ensure Privacy Threshold Assessments (PTA) and Privacy Impact Assessments (PIA) are conducted as required * Review cyber intelligence threats reports, including but not limited to SOC MARs, SARs, and DHS/CISA Emergency Directives, in order to identify threats to the information system and develop mitigations * Provide subject matter expertise and recommendations as part of RMF process activities and development of related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials) * Evaluate cloud service providers' security posture and develop associated recommendations for restrictions, conditions and control responsibility parsing * Write Plan of Action and Milestones (POA&M's) and Risk Based Decisions (RBD's) for the System Security Plan (SSP) controls within the NASA Risk Information Security Compliance System (RISCS) tool. * Ensure contingency plans and system controls are reviewed and tested in accordance with the Agency requirements. * Analyze system logs to identify potential issues and perform routine audits of systems and applications. * Ensure critical vulnerabilities that require immediate attention are remediated, as identified in the Security Operation Center (SOC) Mitigation Action Recommendation (MAR). * Ensure the installation of security/vulnerability patch updates, operating system level patches and upgrades to include new versions. * Provide IT security support to communication systems as needed and serve as a technical resource to Information System Security Officer(s) (ISSO) and other IT professionals * The contractor shall assist in the development and updating of the System Security Plan, Contingency Plan, Disaster Recovery Plans, Risk Assessment Report, annual review package, work instructions, policies, and procedural guides affecting the overall IT and security posture of the environment * Support the Assessment and Authorization (A&A) process by preparing associated documentation, building, and tracking Plan of Action and Milestones (POA&M), and monitoring A&A activities ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)