> Markdown version of [/jobs/ext/3436819-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/3436819-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Mantech International Corporation - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, Unix, Cloud Computing, Cyber Security, System Configuration, Linux, Information Security Management, Oracle Databases, SQL Databases, Software Vulnerability Management, Virtual Computing, Information Technology, Patch Management, Cisco, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9141744/information-system-security-officer ## About the Role * Bachelor's degree preferably in IT, Cyber Security, Computer Science, Information Systems Management, Engineering, or similar field of study with 4+ years of information systems security experience, or an Associates degree with 6 additional years of relevant experience, or High School Diploma with 11+ years' experience in lieu of degree * Security+ Certification * 3+ years' experience with Risk Management Framework (RMF), ICD 503, NIST SP800-53, JSIG, or DJSIG * Knowledge and experience with current authorization practices, specifically within the DoD, * Masters degree preferably in IT, Cyber Security, Computer Science, Information Systems Management, Engineering, or similar field of study * Experience with security efforts related to modern Windows, Cloud computing, Linux, UNIX, Cisco, SQL or Oracle databases, and virtual computing * Experience implementing and using various Cyber Security tools including vulnerability assessment, patch management, audit collection, audit review, audit management, and end point protection Clearance Requirements: * Must have an active Top Secret clearance with the ability to obtain an SCI Physical Requirements: * The person in this position must be able to remain in a stationary position 50% of the time. Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers, via email, phone, and or virtual communication, which may involve delivering presentations. ## Description * Maintain Assessment & Authorization (A&A) documentation in accordance with JSIG, NIST SP 800-37, and NIST SP 800-53, including SSPs, Contingency Plans, and Incident Response procedures * Track compliance deficiencies using Plans of Action and Milestones (POA&M) through mitigation or risk acceptance, delivering quarterly status updates to the ISSM and SCA * Implement and execute the Continuous Monitoring strategy to ensure ongoing compliance with authorization packages * Oversee audit log collection systems and perform weekly reviews to maintain system integrity * Manage hardware and software inventories, ensuring all deployed assets remain actively vendor-supported * Maintain security tools, patch management processes, and vulnerability management programs in coordination with the Cybersecurity team * Assess proposed system configuration changes as part of the Change Control Board (CCB) to evaluate security impacts * Facilitate annual security awareness and role-based training, personnel account verification, and general ISSM support ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager)