> Markdown version of [/jobs/ext/487483-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/487483-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Signal - **Location:** Millersville, MD, United States - **Experience:** Experienced - **Salary:** $115,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, System Configuration, Firmware, Identity and Access Management, Information Security Management, Internet Service Provider, Log Analysis, Windows Servers, Network Architecture, Network Administration, Cloud Services, Security Information and Event Management, Virtualization Technology, Software Vulnerability Management, Backup and Restore, SC Clearance, Information Technology, Scap Compliance Checker, Vulnerability Analysis - **Published:** June 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7a22b373bd186cb7 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, * Citizenship: Must be a U.S. Citizen. * Security Clearance: Active Secret clearance preferred. Must be eligible to obtain and maintain a DoD Secret clearance and be capable of meeting all requirements for access to classified information. * Education & Experience: Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, Computer Science, or a related field, plus 3+ years of relevant cybersecurity, information assurance, or systems administration experience; or an equivalent combination of education, professional certifications, and 7+ years of directly related experience supporting cybersecurity compliance, information systems security, or secure enterprise environments. * Certification: Must possess an active CompTIA Security+ certification (or equivalent DoD 8140/8570-approved IAT Level II certification) at the time of hire or within 6 months of employment. * Compliance Knowledge: Demonstrated experience implementing or maintaining security controls aligned with NIST SP 800-53, NIST SP 800-171, RMF, CMMC, or comparable information security frameworks. Experience supporting cybersecurity compliance activities, audits, assessments, or authorization efforts is highly desired. * Technical Writing: Ability to provide clear, concise feedback to the ISSM regarding system performance and compliance gaps. Preferred Skills & Experience * Classified Systems Experience: Experience supporting classified information systems operating under NISPOM, RMF, and DCSA requirements is highly desirable. * DoD / Federal IT Experience: Previous experience working with DoD or other Federal IT systems is strongly preferred. * DCSA Training: Completion of coursework regarding the Risk Management Framework (RMF) for Contractors or other relevant courses. * STIG Excellence: Familiarity with the SCAP Compliance Checker and manual STIG checklists. * eMASS: Hands-on experience submitting and managing A&A packages using eMASS. * CMMC Experience: Experience supporting CMMC Level 2 assessment preparation, evidence collection, control validation, POA&M management, or remediation activities. * Experience Protecting CUI: Hands-on experience protecting Controlled Unclassified Information (CUI) through the implementation of NIST SP 800-171 controls. * System / Network Administration: Experience serving as a system or network administrator, or in similar role, in a federal or highly regulated industry. * Operating Systems & Infrastructure: Experience administering Windows Server, Active Directory, virtualization platforms, enterprise networking equipment, and endpoint security solutions. * Preferred Certifications: CISSP, CASP+, CISM, CAP, CCP, or other advanced cybersecurity certifications., * Cybersecurity, Information Assurance, or related: 3 years (Required) License/Certification: * CompTIA Security+ (or equivalent) certification (Preferred) ## Description The ISSO serves as the primary technical administrator for company information systems and networks while supporting the Information System Security Manager (ISSM) in maintaining compliance with applicable DoD cybersecurity requirements., * Security Controls Implementation and Maintenance: Maintain the operational security posture for both a networked DoD Information System and a dedicated CUI network environment through the implementation and maintenance of security controls based on NIST SP 800-53, NIST SP 800-171, RMF requirements, and other security frameworks. * Execution of Procedures: Implement and enforce the security plans and procedures authored by the ISSM to ensure adherence to DoD standards. * Audit & Continuous Monitoring: Perform regular system audits, log analysis, and physical security checks to ensure no unauthorized changes or breaches have occurred. Monitor EDR, SIEM, and other security tools for alerts, anomalous activity, and indicators of compromise. Investigate and respond to potential security incidents as appropriate. * System Configuration & Vulnerability Management: Develop and maintain secure configuration baselines throughout system lifecycle. Work with the ISSM to perform automated vulnerability scans and correct any identified deficiencies. Execute changes to information systems consistent with Configuration Control Board decisions. * Security Control Assessment / Audit Support: Participate in periodic security control assessments, vulnerability assessments, penetration testing activities, and remediation efforts, as applicable. Validate that controls are operating as intended and maintain a robust collection of evidence. Support activities related to external security audits/assessments (e.g., C3PAO assessments, DIBCAC reviews, etc.) and the reporting of compliance metrics (e.g., SPRS scoring). * Risk Management: Assist the ISSM in identifying, documenting, and mitigating information system risks. Participate in periodic risk assessments and provide recommendations regarding technical and procedural safeguards. * System & Network Administration: Own the administration duties of system and network resources including, but not limited to, the following: * Identity and access management for both logical and physical security * Administering and maintaining network infrastructure, security appliances, and associated management systems * Testing and applying software/firmware patches and updates * Troubleshooting technical and operational issues * System/data backups and testing * Implementing and managing encryption * Endpoint compliance oversight * Performing log reviews and analysis * Completing change management security reviews * POA&M Execution: Carry out actions as required by Plans of Action & Milestones (POA&Ms) in a timely manner. Provide the ISSM with evidence needed to demonstrate closure of POA&Ms. * SSP Support: Support the regular maintenance of all system security plans (SSPs) by participating in annual reviews and providing up-to-date information regarding security controls implemented, current system configurations, and other details as needed. Work with the ISSM to proactively update SSPs to reflect major changes in the environment such as personnel changes, changes in technologies, etc. * A&A Support: Assist the ISSM in maintaining Assessment and Authorization (A&A) packages within eMASS, including artifact collection, control implementation evidence, remediation tracking, and package updates. * Incident Response & Reporting: Primary responder to all incidents and outages involving the company's IT and network assets. Coordinate with the ISSM during incident response and reporting activities. Provide timely updates to the ISSM and executive leadership regarding ongoing response and recovery activities. Ensure accurate information is provided to the ISSM for incident reporting within the required timeframe as directed by DFARS 252.204-7012. Serve as a technical liaison with external parties, as needed, during incident response, investigation, and recovery. Ensure preservation of forensic evidence/logs as directed by the ISSM or other designated officials. * Physical Safeguarding: Support the safeguarding of classified information systems, storage media, and associated physical security controls in coordination with the Facility Security Officer (FSO) and ISSM. * IT Vendor Management: Serve as the primary liaison with third-party IT vendors such as ISPs, hardware/software providers, cloud service providers (CSPs), etc. Function as the main technical POC for the company's MSSPs. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)