> Markdown version of [/jobs/ext/2874423-information-system-security-officer-mid](https://www.wearedevelopers.com/jobs/ext/2874423-information-system-security-officer-mid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer, Mid - **Company:** Booz Allen Hamilton Inc. - **Location:** Washington, DC, United States - **Experience:** Experienced - **Salary:** $62,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Information Security Management, Systems Architecture, Software Vulnerability Management, SARS Software Products, Cloud Platform System, Office365, Cybercrime - **Published:** September 13, 2026 - **Apply:** https://www.careerjet.com/job/usa926face5ecb71a87d9713eb6c362e5f/eaa ## About the Role * 5+ years of experience in information security, including system security, compliance, or ISSO responsibilities * Experience facilitating system authorization activities in accordance with steps 1-4 of the RMF * Experience creating and maintaining A&A documentation such as FIPS-199, SSPs, POA&Ms, and SARs * Experience with cloud environments such as AWS, Azure, M365, and SaaS applications, and associated security controls * Knowledge of federal cybersecurity frameworks and standards, including NIST SP 800-53, Risk Management Framework (RMF), and FISMA * Knowledge of system architecture, security controls, and secure system lifecycle practices to ensure controls are effectively designed and implemented across system environments * Ability to communicate effectively with both technical and non-technical stakeholders, translating complex security requirements into actionable guidance * Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements * Bachelor's degree Nice If You Have: * Experience with continuous monitoring tools and vulnerability management platforms * Bachelor's degree in a Cybersecurity, Information Systems, CS, or Engineering field * CISSP, CISM, CAP, Security+, or similar Industry Certification ## Description Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this "cyber noise", how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as an information security risk specialist to help break down complex threats into manageable plans of action. As an information security risk specialist on our team, you'll work with government agencies to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You'll get technical and personnel details from SMEs, engineers, and system owners to assess the entire threat landscape. Then, you'll help your team guide your client through a plan of action with presentations, whitepapers, and milestones. You'll work on translating security concepts for your client so they can make the best decisions to secure their mission-critical systems. This is your opportunity to take an active role in information security while growing your skills in cloud computing. Work with us as we protect our nation's mission-critical systems. Join us. The world can't wait. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)