> Markdown version of [/jobs/ext/616456-cmmc-information-security-system-officer-isso](https://www.wearedevelopers.com/jobs/ext/616456-cmmc-information-security-system-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CMMC - Information Security System Officer (ISSO) - **Company:** Quindar Inc. - **Location:** Arvada, CO, United States - **Experience:** Experienced - **Salary:** $95,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Business Systems, Cyber Security, Information Systems, Continuous Integration, Information Security Management, Information Technology Audit, Intrusion Detection Systems, Network Security, Security Information and Event Management, Software Vulnerability Management, Containerization, Kubernetes, Information Technology, Devsecops, Vulnerability Analysis - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3380613fa4b39c2a ## About the Role Do you have experience in Technical Proficiency?, Do you have a Bachelor's degree?, * Citizenship: US Citizenship * Clearance: Eligibility for a US Government Security Clearance * Education: Bachelor's degree in Information Security, Computer Science, or a related field. Experience: * 2+ years of experience in information security, working with Federal Regulations * Proven experience in leading the management and implementation of an Information Security Program. Technical Skills: * Strong understanding of security frameworks and standards for NIST SP 800-171 and DevSecOps. * Proficiency in security tools and technologies, such as SIEM, IDS/IPS, STIG Hardening, and vulnerability management solutions. * Exposure to technologies and concepts including Kubernetes Containerization, AWS GovCloud Environments and Tooling, CI/CD pipelines, and Secure Network Architecture. Soft Skills: * Excellent communication and interpersonal skills. * Strong analytical and problem-solving abilities. Ability to manage multiple projects and priorities in a fast-paced environment. ITAR REQUIREMENTS To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. ## Description The Information Systems Security Officer (ISSO) is responsible for enforcing and maintaining information security policies, standards, and procedures to ensure the confidentiality, integrity, and availability of information systems. The ISSO will uphold requirements in NIST SP 800-171 to protect Quindar Business Systems that process, transmit, or store Controlled Unclassified Information (CUI) and maintain Cybersecurity Maturity Model Certification (CMMC) 2.0 accreditation. The ISSO will coordinate directly with the Quindar ISSM, FSO, System Administrators, Leadership, and the General User community to foster strong security culture and ensure compliance with governing Federal Regulations., * Operations Support + Review user requests in conjunction with ISSM and System Administrators to determine security impacts of software additions or configuration changes to systems. + Onboard users to systems, including development and delivery of training and briefings of Roles and Responsibilities operating on systems. * Risk Management and Assessment: + Conduct regular risk assessments and vulnerability assessments to identify potential security threats. + Implement risk mitigation strategies and manage the risk management framework. * Continuous Monitoring and Audit Management: + Prepare for and execute both self-assessments and external assessments with Government Security Control Assessors in support of achieving and maintaining CMMC accreditation. + Execute Continuous Monitoring activities of employed security controls to ensure comprehensive and effective implementation over time, including but not limited to analyzing user/system audit logs, malware protections, vulnerability reporting, and access reviews. * Incident Response and Management: + Develop and maintain an Incident Response Plan, partnering with Government Customers/Prime/Subcontractors for reporting procedures. + Lead incident response activities, including investigation, containment, and remediation of security incidents. + Investigate and adjudicate SIEM events. * System Security Plans (SSPs): + Maintain System Security Plans and collecting all required artifacts (Compliance and Vulnerability reports, documented Policies/Procedures, etc.) + Ensure that SSPs are regularly reviewed, updated, and compliant with regulatory requirements. * Collaboration and Communication: + Work closely with System Administrators, compliance, and other departments to ensure cohesive and comprehensive security strategies. + Serve as a point of contact for security-related issues and provide guidance and support to other teams. * Continuous Improvement: + Stay up-to-date with the latest security trends, technologies, and regulatory requirements. + Continuously improve security measures and processes to protect information systems effectively. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)