> Markdown version of [/jobs/ext/505680-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/505680-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** DEMASE TECHNICAL SERVICES, LLC - **Location:** Oak Ridge, TN, United States - **Experience:** Expert - **Salary:** $75,001.0 - $175,230.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Information Security Management, Smartsuite, Security Content Automation Protocol, Virtualization Technology, Software Vulnerability Management, SARS Software Products, Information Technology, Tenable Nessus, Nessus, Nutanix, Vulnerability Analysis, Vmware - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=64e6ff6ef3be0383 ## About the Role Do you have experience in Vulnerability management?, This role requires an active DOE Q security clearance (or equivalent DoD TS)., * Active DOE Q Clearance * Five-plus (5+) years of cybersecurity experience supporting classified systems * Bachelor's degree in computer science, information systems, engineering, or related field (or equivalent experience) Preferred Qualifications * Strong working knowledge of: * RMF and NIST 800-series publications * System accreditation and authorization processes * Security controls implementation and validation * Hands-on experience with eMASS * Ability to interpret security findings and drive remediation efforts * Strong documentation, communication, and stakeholder coordination skills * Knowledge of STIGs, SCAP, Nessus, or similar scanning tools * Experience supporting DOE/NNSA environments * Familiarity with virtualization platforms (Nutanix, VMware, etc.) * CISSP, CISM, CAP, or Security+ certification ## Description The Information System Security Officer (ISSO) is responsible for ensuring the security, compliance, and authorization of classified and unclassified information systems in a DOE Q-cleared environment. The ISSO supports system accreditation, continuous monitoring, and enforcement of cybersecurity controls in accordance with NIST, DOE, and federal requirements., * Serve as the primary cybersecurity authority for assigned information systems * Implement, manage, and maintain RiskManagement Framework (RMF) processes from system categorization through ATO * Ensure systems comply with NIST SP 800-53, NIST SP 800-37, DOE Orders, and site-specific security policies * Develop, maintain, and update system security documentation including: * System Security Plans (SSPs) * Security Assessment Reports (SARs) * Plans of Action & Milestones (POA&Ms) * Manage vulnerability assessments, security control testing, and remediation activities * Utilize and maintain compliance artifacts within eMASS (or equivalent GRC tools) * Coordinate with system owners, administrators, auditors, and Authorizing Officials * Conduct continuous monitoring, audit preparation, and security reviews * Oversee incident response coordination and reporting for security events * Provide security guidance for system changes, upgrades, and new deployments * Support insider threat, configuration management, and change control processes * Participate in CCB, security working groups, and compliance briefings, DeMase Technical Services, LLC is committed to providing reasonable accommodation to applicants with disabilities where appropriate. Determinations on requests for reasonable accommodation will be made on a case-by-case basis. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)