> Markdown version of [/jobs/ext/3363597-information-system-security-officer-iii](https://www.wearedevelopers.com/jobs/ext/3363597-information-system-security-officer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer III - **Company:** ORBIS INC. - **Location:** San Diego, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Microsoft Azure, Bash Shell, Configuration Management, Cyber Security, Information Systems, Linux, Identity and Access Management, Information Security Management, Information Technology Audit, Python (Programming Language), Log Analysis, McAfee VirusScan, Windows PowerShell, Systems Development Life Cycle, Red Hat Enterprise Linux, Security Information and Event Management, Software Deployment, Scripting, Information Technology, Nessus, Operating System Security, Splunk, Scap Compliance Checker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9205347/information-system-security-officer-iii ## About the Role * Clearance: Must possess an active, TS/SCI and be a United States citizen. * Education: Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field. (Significant operational experience and advanced certifications may substitute for the degree). * Experience: A minimum of six (6) years of dedicated experience coordinating and implementing security changes, conducting vulnerability analysis, and managing continuous monitoring activities. * Technical Experience: Demonstrable hands-on experience utilizing ACAS (Tenable/Nessus), HBSS (Trellix/McAfee), Splunk (or similar SIEM), and STIG Viewer. * Certifications: Must possess and maintain a current DoD 8140/8570 IAM Level II certification (e.g., CAP, CASP+ CE, CISM, CISSP, GSLC, CCISO, or HCISPP). * Strong working knowledge of Windows and Linux/Red Hat operating system security configurations and Active Directory group policies. * Ability to work effectively in a fast-paced environment, balancing multiple RMF package deadlines and continuous monitoring requirements simultaneously., * Certifications in specific operating systems or security tools (e.g., Linux+, Microsoft Certified Azure Security Engineer, Splunk Core Certified Power User). * Prior experience serving as an ISSO for a Navy Research, Development, Test, and Evaluation (RDT&E) environment. * Direct experience writing custom scripts (PowerShell, Python, Bash) to automate security compliance checking and log analysis. ## Description Position Overview ORBIS requires an Information System Security Officer III (ISSO III) to serve as a tactical cybersecurity expert supporting the NSWC Corona CCAM contract. Working under the direction of the ISSM, the ISSO III is responsible for the day-to-day implementation, monitoring, and maintenance of security controls across assigned information systems. This key personnel role is heavily involved in the technical aspects of the RMF lifecycle and continuous monitoring programs. Operational Cybersecurity & RMF Responsibilities: * Execute daily, weekly, and monthly cybersecurity operations for assigned networks, enclaves, and Platform IT systems. * Coordinate directly with system engineers, developers, and administrators to ensure security configurations are applied during the system development lifecycle. * Conduct comprehensive vulnerability assessments utilizing the Assured Compliance Assessment Solution (ACAS/Nessus) and analyze the results to identify critical flaws. * Apply and verify Security Technical Implementation Guides (STIGs) using the SCAP Compliance Checker (SCC) and manual STIG Viewer reviews. * Develop, compile, and upload high-quality artifacts into eMASS to demonstrate the successful implementation of NIST 800-53 security controls. * Draft and update essential RMF documentation, including Information System Contingency Plans (ISCP), Incident Response Plans (IRP), and hardware/software inventories. * Assist the ISSM in creating, updating, and managing Plan of Action and Milestones (POA&M) entries, documenting steps taken to remediate identified vulnerabilities. * Perform daily reviews of system audit logs, Security Information and Event Management (SIEM) alerts, and firewall traffic to identify anomalous or malicious activity. * Enforce account management policies, ensuring that user access, privileged access, and administrative roles are granted according to the principle of least privilege. * Support cyber incident response activities, executing containment procedures, preserving evidence, and assisting in root-cause analysis. * Monitor systems for compliance with Information Assurance Vulnerability Alerts (IAVAs), ensuring patches and updates are tested and deployed within mandated timeframes. * Participate in Configuration Control Board (CCB) meetings to evaluate the security impact of proposed network changes, software installations, or hardware modifications. * Conduct physical security walk-throughs and environmental control checks for facilities housing classified or sensitive information systems. * Assist in the preparation and execution of formal command cyber inspections and assist the NQV during official validation events. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)