> Markdown version of [/jobs/ext/3544117-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/3544117-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Innovative Defense Technologies - **Location:** Fall River, MA, United States - **Experience:** Experienced - **Salary:** $90,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Cyber Security, Information Systems, Linux, Domain Name System (DNS), File Server, Identity and Access Management, Information Security Management, Networking Hardware, Log Files, Role-Based Access Control, Red Hat Enterprise Linux, Security Software, Security Information and Event Management, Information Security Management System, Tanium Platform Expertise, Selinux, SolarWinds (Software), National Industrial Security Program Operating Manual (NISPOM), Splunk, Scap Compliance Checker, Event Viewer, Wsus, Plan of Action and Milestones - **Published:** October 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8865056/information-system-security-officer-isso ## About the Role * Bachelor's degree in Information Systems or Cybersecurity, or equivalent full-time professional experience * 3+ years of professional experience within Information Security or related roles. * Required Certification: Security+ CE, or equivalent Level I or II IAT/IAM DoD 8140 certification * Ability to travel up to 10% of the time needed * Experience with Assessment & Authorization efforts for DCSA ATO management, including hands on eMASS experience * Experience with RMF Continuous Monitoring Tooling and Systems (ACAS/Tenable, STIGViewer, SCAP Compliance Checker, etc.) * Proficiency with SIEM tools (Wazuh, Splunk, SolarWinds Security Event Manager) * Experience with Cybersecurity tools (Tenable Security Center, Trellix ePO, Tanium, WSUS, RedHat Satellite) * Ability to manage users on both Linux and Windows environments, role-based access control (RBAC), security policies (GPO's, SELinux, etc.), domain management (Active Directory, DNS, File Server, etc.), STIG/hardening actions, Troubleshooting (Event Viewer, top, netstat, systemctl, etc.) * Familiarity with National Industrial Security Program Operating Manual (NISPOM), The 32 Code of Federal Regulations Part 117 and Defense Counterintelligence and Security Agency Assessment and Authorization Process Manual (DAAPM) requirement What Makes You Stand Out: * Preferred Certifications: CySA+, CASP+ CE, CISA, CISM, CISSP * Experience writing policy and procedure documentation * Experience in working on classified systems in a DCSA accredited environment * DCSA Authorization and Assessment Experience * NIST 800-53 Security Control Experience * Experience with tactical systems, virtualization ## Description The Information System Security Officer (ISSO) is a key member of the security team that will support the Assessment and Authorization (A&A) process for information systems under the jurisdiction of the Defense Counterintelligence and Security Agency (DCSA). The Fall River ISSO is responsible for ensuring that the information system complies with the security requirements and controls specified in the DCSA Assessment and Authorization Guide (DAAG) and other applicable policies and regulations., * Familiarity with the Defense Counterintelligence Security Agency (DCSA) Assessment and Authorization Guide (DAAG) roles and responsibilities for the ISSO, as outlined in Section 3.7 * Coordinate with the Information System Security Manager (ISSM) and Facility Security Officer (FSO) to ensure the highest level of cybersecurity compliance for classified information systems * Maintain the Information Systems (IS) security program and policies for assigned areas of responsibility IAW the DCSA DAAG, assigned NIST 800-53 controls, and other guidance as assigned by the ISSM. * Review and analyze all audit data at least weekly to ensure user activity adheres to operational security policy and procedures * Review of network device System Log (syslog) information to correlate to system level activity across multiple information systems. * Support ISSM oversight of operational IS security implementation policy and Risk Management Framework (RMF) guidelines to the system administrators * Support ISSM in the development and documentation of the Plan of Action and Milestones (POA&M) and produce actions to mitigate identified risks * Perform Continuous Monitoring (ConMon) tasks as assigned by the ISSM and documented within the System Security Plan * Perform comprehensive investigations of security incidents and ensure proper measures are taken post discovery of the incident/event * Administration of STIG compliance as it relates to Operating Systems and applications * Facilitate and track all Information System Account requests and expirations for Internal Users and Visitor accounts * Responsible for the preparation and demonstration of compliant classified IS's in advance of a DCSA assessments * Identity and Authorization Management, including user, group, and role on both Windows and Linux systems. * Actively participate in the development and implementation of effective IS security ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)