> Markdown version of [/jobs/ext/3615330-information-systems-security-officer-isso-mid-level](https://www.wearedevelopers.com/jobs/ext/3615330-information-systems-security-officer-isso-mid-level). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) Mid-Level - **Company:** United Launch Alliance - **Location:** Centennial, CO, United States - **Experience:** Experienced - **Salary:** $104,087.0 - $173,479.0 - **Contract:** Permanent contract - **Skills:** Multitier Architecture, Microsoft Windows, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, System Configuration, Linux, Identity and Access Management, Key Management, Network Security, SAP (Applications), Security Content Automation Protocol, Virtualization Technology, Data Processing, Information Technology, Tenable Nessus, Patch Management, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 8, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88560288/1 ## About the Role Minimum of 4 years of related work experience, * Active TS/SCI with CI Poly and ability to maintain eligibility. U.S. Citizenship required * Bachelor's degree in Cybersecurity, Computer Science, or related field; equivalent experience considered + Four years of directly related exempt work experience may be used to satisfy the bachelor's degree requirement * 4+ years of IA/cybersecurity experience with 3+ years directly supporting RMF/ATO for DoD/IC systems * Current DoD 8570/8140 Tier II certification or higher * Hands-on experience with NIST SP 800-53, DoDI 8510.01, CNSSI 1253, JSIG/ICD 503, and STIG/SRG application * Proficiency in vulnerability and compliance tools: Tenable Nessus, SCAP, DISA STIG Viewer, log/monitoring, and familiarity with patch management * Experience developing and maintaining SSP, SAR/SAP, POA&M, and RMF evidence; strong technical writing skills * Knowledge of network security, Windows/Linux hardening, virtualization, endpoint protection, identity & access management, encryption/key management, and secure configuration baselines Preferred Qualifications * Additional cybersecurity certifications (CAP, CEH, GSEC, GSLC) * Experience supporting Defense and Intelligence Community programs * Familiarity with secure cloud and hybrid environments (e.g., DoD Cloud SRG, IL2-IL6, GovCloud, IC ITE) * Prior involvement in customer-led cybersecurity inspections or assessments ## Description RMF / ATO Support * Execute and document all RMF activities across the full lifecycle in accordance with DoDI 8510.01, NIST SP 80053, CNSSI 1253, JSIG/ICD 503, and customer specific guidance. * Develop and maintain RMF artifacts including the SSP, SAP/SAR, POA&Ms, Contingency Plans, IR Plans, and related IA documentation. * Support ATO package preparation and submission using government customer RMF/IA tools for evidence upload, workflow tracking, and assessor interactions. * Implement, assess, and validate security controls; support control tailoring and inheritance strategies. Continuous Monitoring & Compliance * Perform continuous monitoring using government approved compliance scanning tools: + Vulnerability scanning tools + STIG/SRG-based configuration validation + Automated compliance assessments * Maintain system baselines, secure configurations, asset inventories, and IA-related change documentation. * Support audit readiness and assist with customer inspections, CCRI-type events, and periodic cybersecurity evaluations. * Track, manage, and drive closure of POA&Ms and risk items. Secure Operations & Incident Response * Provide day-to-day IA support for classified systems, including boundary analysis, system configuration reviews, and data handling oversight. * Support event detection and response activities using government customer log aggregation tools, ensuring accurate log capture, retention, and reporting. * Participate in incident response coordination with Contractor Program Security Officer (CPSO) in accordance with customer and organizational procedures. * Guide engineering and operations teams on secure design principles, system changes, and cybersecurity impacts. Governance, Risk & Compliance * Maintain risk tracking, document deviations and mitigations, and communicate system risk posture to IA leadership and stakeholders. * Support policy compliance, user training, secure handling, insider threat awareness, and governance activities. * Coordinate with AOs, SCAs, customer cybersecurity offices, and program security personnel.