> Markdown version of [/jobs/ext/736337-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/736337-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** The Charles Stark Draper Laboratory Inc - **Location:** Cambridge, MA, United States - **Experience:** Starter - **Salary:** $75,000.0 - $156,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Firmware, Identity and Access Management, Information Security Management, Security Content Automation Protocol, Systems Architecture, Software Vulnerability Management, Firewalls (Computer Science), Information Technology, Nessus, Splunk, Network Server, Event Viewer - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6ef15087e9e9b453 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Understanding of information security concepts (e.g. RMF, DIACAP) * Awareness of audit technologies or capabilities (e.g. Splunk, event viewer) * Understands Information Technology basics. * Awareness of network type designations (e.g. WAN, LAN) and associated infrastructure (e.g. Servers, switches, firewalls)., * Requires a bachelor's degree in Information Technology or a related field. * Equivalent industry experience may be substituted. * Ability to acquire an IAM I/IAT II Certification within 6 months of start date. Experience: * 1-3 years year relevant industry experience is required, * Preferred experience with RMF (NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-Relevant Tools. ## Description The Information System Security Officer 1 (ISSO) supports the continuous monitoring and authorization efforts of multiple classified information systems under the direction of the Information System Security Manager (ISSM). Performing a variety of technical, and non-technical Cyber Security functions., * Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM. * Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the security authorization package. * Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties. * Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the IS. * Conduct periodic reviews of information systems to ensure compliance with the security authorization package. * Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change. * Formally notify the ISSM and AO/DAO when changes occur that might affect system authorization. * Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly. * Ensure all IS security-related documentation is current and accessible to properly authorized individuals. * With supervision, Conduct Audits and Continuous Monitoring (ConMon) activities using available technical and non-technical processes, Reports Audit and ConMon findings, Conduct incident response steps as directed. * With supervision, manage configuration baselines of both hardware and software, Identify system architecture flaws using industry standard tools (e.g. STIG, SCAP, Nessus) that will be flowed to the ISSM for review. * Performs other duties as assigned. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)