> Markdown version of [/jobs/ext/601129-information-system-security-officer-iii](https://www.wearedevelopers.com/jobs/ext/601129-information-system-security-officer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer III - **Company:** Athena Technology Group - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Configuration Management, Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, Navsea, Vulnerability Analysis - **Published:** June 16, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8978487/information-system-security-officer-iii ## About the Role Secret Clearance Level * Bachelors degree * Six (6) years of experience coordinating and enacting required security changes within various levels of an organization, ensuring compliance with published policies; conducting cybersecurity vulnerability and threat analysis; and supporting cyber incident response by isolating potentially affected assets, initial investigation and data collection, through status updates/reporting * Industry-specific knowledge, IAM-II level certifications - CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO, HCISP; IAT-II level certifications - CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP ## Description We are seeking an Information System Security Officer to join our team. You will play a key part in ATG's technical support for Naval Surface Warfare Center Philadelphia Division (NSWCPD) specializing in cybersecurity support, validation support, IT and cyber policy writing and program implementation support. Our team will provide direct support cybersecurity policy, A&A artifacts, validation and security posture reviews., * Assist the Information System Security Managers (ISSM) in executing their duties and responsibilities. * Ensure compliance with all NAVSEA, DON, and DoD cybersecurity policies. * Ensure relevant Cybersecurity (CS) policy and procedural documentation is current and accessible to properly authorized individuals. * Coordinate cybersecurity processes and activities for assigned systems. * Maintain and report Assess Only (AO) and Assessment and Authorization (A&A) status to Program Managers, Information System Owners, and ISSMs. * Provide oversight of Security Plans for assigned systems throughout their lifecycle. (CDRL A006) * Manage and maintain Plan of Actions and Milestones (POA&M), ensuring vulnerabilities are properly tracked, mitigated, and where possible, remediated. * Assist with the identification of security control baselines and applicable overlays. * Coordinate the validation of security controls with Navy Qualified Validators (NQV). * Perform Risk Management Framework (RMF) Standard Operating Procedure (SOP) reviews. * Adjudicate findings from Package Submitting Officer (PSO). (CDRL A001) * Register and maintain systems in Enterprise Mission Assurance Support Service (eMASS). * Plan and coordinate security control testing during Risk Assessments and Annual Security Reviews. * Report changes in system security posture to the ISSM. * Ensure the execution of Continuous Monitoring related requirements as defined in the System Level Continuous Monitoring (SLCM) Strategy. * Review all data produced by Continuous Monitoring activities, update the eMASS record as necessary, and escalate to leadership for action, if required. * Correlate findings from non-RMF vulnerability assessments (e.g., Development Test (DT)/Operational Test (OT), penetration testing, Command Cyber Operational Readiness Inspection (CCORI), etc.) to RMF controls for tracking, ensuring a holistic risk assessment ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)