> Markdown version of [/jobs/ext/2675756-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2675756-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Leidos, Inc. - **Location:** Huntsville, AL, United States (Remote available) - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Computing Platforms, Audit Trail, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, System Configuration, Linux, Monitoring of Systems, Identity and Access Management, Information Security Management, Linux System Administration, Security Content Automation Protocol, Enterprise Software Applications, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Splunk, Vulnerability Analysis - **Published:** September 1, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88200758/1 ## About the Role * Bachelor's degree coupled with 4+ years of relevant cybersecurity, information technology, information assurance, or information systems security experience, or a Master's degree with 2+ years of relevant experience. Additional relevant experience may be considered in lieu of a degree consistent with Leidos job-level requirements. * Must meet, or be capable of meeting, applicable DoD 8140/DoD Cyber Workforce Framework (DCWF) qualification requirements for the assigned work role through approved certification, education, training, or experience. * Possess working knowledge of the Risk Management Framework (RMF) and implementation and assessment of cybersecurity controls within regulated or classified environments. * Demonstrated experience performing information system security assessments, compliance auditing, vulnerability assessment, system hardening, or security configuration management. * Possess working knowledge of Windows and/or Linux operating systems and associated security configurations. * Direct experience interpreting and applying cybersecurity requirements such as NIST SP 800-53, DISA STIGs, DCSA/DoW security requirements, or comparable government cybersecurity standards. * Ability to analyze technical security findings, identify risk, recommend corrective actions, and communicate security requirements to both technical and nontechnical stakeholders. * Demonstrated ability to develop and maintain detailed cybersecurity documentation and objective evidence supporting system compliance. * Possess strong organizational, analytical, written, and verbal communication skills with the ability to independently manage multiple cybersecurity activities and priorities. * Able to work collaboratively with Information Technology, system administrators, engineers, program management, physical security, and other cybersecurity personnel. Relevant Experience Considered Relevant experience may include a combination of: * Cybersecurity, information assurance, information systems security, system administration, system hardening, or Information Technology. * RMF compliance, security control implementation or assessment, continuous monitoring, or maintenance of authorization packages. * DCSA Assessment and Authorization Guide (DAAG), NISPOM, NIST SP 800-53, DISA STIG, or comparable government cybersecurity requirements. * Administration or security assessment of Windows, Linux, Active Directory, Group Policy, Delinea, or comparable enterprise technologies. * Vulnerability scanning, security configuration assessment, audit log analysis, or security monitoring. * Technical support of classified information systems, laboratories, engineering environments, or other regulated computing environments. * Project or program management experience involving technical, cybersecurity, compliance, or information system activities. Preferred Qualifications: * Experience supporting DCSA-authorized classified information systems and maintaining systems through the RMF authorization and continuous monitoring lifecycle. * Experience developing and maintaining RMF authorization artifacts within eMASS. * Hands-on experience performing STIG, SCAP, vulnerability, and configuration compliance assessments. * Experience with cybersecurity and monitoring tools such as Splunk, Trellix, Tenable/ACAS, SCAP, STIG Viewer, or comparable technologies. * Experience assessing security configurations across Windows and Linux environments, including Active Directory, Group Policy, and identity or privileged-access management technologies. * Experience supporting DCSA assessments, authorization activities, inspections, or cybersecurity readiness reviews. * Experience analyzing cybersecurity findings, developing remediation strategies, and coordinating corrective actions with system administrators, engineers, and program personnel. * Knowledge of cybersecurity incident response activities, including identification, preservation, containment, eradication, recovery, and reporting. * Industry cybersecurity certifications such as CISSP, CISM, CISA, CySA+, Security+, or other certifications relevant to the assigned DoD 8140/DCWF work role. ## Description As the Information System Security Officer (ISSO), you will be responsible for supporting our Classified Information System Cybersecurity/Information Assurance Program. You will report to the Information System Security Manager (ISSM) on all aspects of classified information system security compliance., The ISSO is responsible for the day-to-day cybersecurity oversight and compliance of classified information systems, supporting the maintenance of system authorizations and continued compliance with applicable DCSA, DoD, and organizational security requirements. You will: * Perform ongoing security monitoring and compliance assessments of classified information systems and report identified deficiencies, risks, and noncompliance to the ISSM and appropriate stakeholders. * Support the Risk Management Framework (RMF) lifecycle, including development, review, and maintenance of authorization artifacts and the system Body of Evidence (BoE). * Evaluate implementation and effectiveness of security controls and maintain supporting evidence required for continuous monitoring, assessments, and authorization activities. * Perform technical security assessments, including Security Technical Implementation Guide (STIG), Security Content Automation Protocol (SCAP), vulnerability scanning, and configuration reviews. * Analyze security findings and vulnerabilities, coordinate remediation activities with system administrators and engineering teams, and validate corrective actions. * Review Configuration Management (CM) requests within delegated authority for hardware, software, system configuration, and security-relevant changes. Ensure changes are appropriately documented, assessed for security impact, and processed through the Configuration Control Board (CCB). * Provide cybersecurity guidance to system administrators, engineers, program personnel, and system owners regarding secure configurations, system changes, and implementation of security requirements. * Conduct periodic technical and administrative assessments to validate continued compliance with approved security plans, procedures, and authorization requirements. * Support security incident response activities, including investigation, documentation, evidence preservation, containment, corrective actions, and reporting. * Support sanitization, declassification, transfer, and release of information system hardware and media in accordance with applicable security requirements and Authorizing Official (AO) guidance. * Develop, review, and maintain cybersecurity documentation, procedures, system security plans, assessment artifacts, and other technical documentation. * Evaluate and support implementation of new cybersecurity processes, technologies, and tools to improve system security, compliance, and operational effectiveness. * Provide cybersecurity education and guidance to system users, administrators, and program personnel as required. * Support DCSA assessments, security reviews, inspections, and other internal or external cybersecurity assessment activities. ## Related Videos - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)