> Markdown version of [/jobs/ext/2833618-information-systems-security-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2833618-information-systems-security-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security / Information System Security Officer (ISSO) - **Company:** ASTRION, INC. - **Location:** Columbia, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Audit Trail, Automation of Tests, Configuration Management, Cyber Security, Information Systems, Information Security Management, Internet Protocol, Network Security, Local Security Policy, Microsoft PowerPoint, Information Security Management System, National Industrial Security Program Operating Manual (NISPOM) - **Published:** September 10, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88289689/1 ## About the Role * Bachelor's degree with 2-4 years of experience. * Experience in supporting U.S. Government clients. * Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment. * A CAP, CISM, CySA, or CISSP certification is required. * S. citizenship with active Top Secret eligibility and the ability to maintain such eligibility., * Proficiency with Secure Internet Protocol Network establishment and maintenance. * Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA). * Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans. ## Description Astrion has an exciting opportunity for an experiencedInformation Systems Security Officer (ISSO). The ISSO supports the ISSM by verifying implementation of required security controls, conducting continuous monitoring and self-inspections, tracking corrective actions, supporting user access and training requirements, and ensuring classified systems are operated in accordance with the approved SSP, NISPOM Rule, CSA guidance, and local security procedures; this position is located in Columbia Maryland., * Information System Security Officer - responsible for supporting the day-to-day security oversight of classified information systems and ensuring users, systems, and processes remain compliant with NISPOM Rule, DCSA/CSA guidance, approved security documentation, and local procedures. * Ensure compliance - with the approved System Security Plan (SSP), security policies, procedures, and system-specific requirements. * Support the ISSM - in maintaining the classified information system security program. * Coordinate and conduct system self-inspections and document results. * Track, validate, and report corrective actions to the ISSM * Support continuous monitoring activities, including review of audit logs, account activity, configuration changes, vulnerability status, and system security posture. * Assist with configuration management and identify security-relevant changes that may require ISSM review or reauthorization. * Ensure users receive required system security briefings, training, user agreements, and access authorizations before system access is granted. * Monitor user compliance with classified system rules, including password/authentication protection, need-to-know, media handling, removable media restrictions, and reporting requirements. * Support incident response for data spills, suspected compromises, audit anomalies, unauthorized activity, or other reportable security concerns * Assist with maintaining authorization documentation, including SSPs, POA&Ms, risk assessments, security assessment results, contingency plans, configuration records, and authorization artifacts. * Coordinate with the ISSM, FSO/AFSO, Insider Threat Program, IT, program leadership, and Government security representatives as required. * Ensure classified systems are operated only within their approved authorization boundary, classification level, caveats, and accredited configuration ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)