HumanResourcely.
FreeJob description · senior

Information System Security Officer (ISSO) job description.

An Information System Security Officer implements and maintains the security posture of assigned information systems, ensuring compliance with applicable security frameworks and regulatory requirements. They conduct risk assessments, manage authorization documentation, monitor for incidents, and coordinate with security leadership to protect sensitive data and systems.

9 responsibilities·5 required + 3 preferred·US + AU
Ready to send

The Information System Security Officer (ISSO) job description · $29

The full editable .docx — role summary, 9 worked responsibilities, qualifications, and skills, formatted for your letterhead. Delivered to your inbox within 24 hours — usually instantly.

Preview
HumanResourcely · Vol. I
Information System Security Officer (ISSO) — Job Description

Role: Information System Security Officer (ISSO)    Reports to: Information System Security Manager (ISSM)

An Information System Security Officer implements and maintains the security posture of assigned information systems, ensuring compliance with applicable security frameworks and regulatory requirements. They conduct risk assessments, manage authorization documentation, monitor for incidents, and coordinate with security leadership to protect sensitive data and systems.

1. Key responsibilities
  • Implement and maintain information system security policies and procedures
  • Ensure systems comply with applicable security frameworks such as NIST RMF or FISMA
  • Conduct risk assessments and vulnerability scans on assigned systems
Full document with email opt-in
Composition

What's inside the document.

01Role summary

One-paragraph plain-English explanation of the role's outcome and scope.

02Responsibilities

9 responsibilities phrased the way the work is actually done.

03Required qualifications

5 qualifications a candidate must have to perform on day 30.

04Preferred qualifications

3 qualifications that would make a candidate excellent in year two.

05Skills

6 skill chips you can copy directly into your ATS.

06Reporting line

Information System Security Manager (ISSM)

What you receive

A complete document set.

  • Word document (.docx) — fully editable
  • PDF — signature-ready
  • Google Docs — one-click copy to your Drive
  • 12 months of updates to this document
  • Commercial-use licence for internal and client work
Responsibilities at a glance

The work, not the title.

  • Implement and maintain information system security policies and procedures
  • Ensure systems comply with applicable security frameworks such as NIST RMF or FISMA
  • Conduct risk assessments and vulnerability scans on assigned systems
  • Prepare and maintain security authorization (ATO) documentation
  • Monitor systems for security incidents and coordinate incident response
  • Manage user access controls and periodic account provisioning reviews
  • Coordinate security audits and support compliance inspections
  • Provide security awareness training and guidance to system users
  • Report security posture and risks to the Information System Security Manager
Qualifications

Required — and what would make a candidate excellent.

Required
  • Bachelor's degree in information security, computer science, or related field
  • 3-5+ years experience in information systems security
  • Relevant certification such as Security+ or CISSP as required by employer or contract
  • Working knowledge of NIST RMF, FISMA, or equivalent security frameworks
  • Ability to obtain and maintain required security clearance as applicable
Preferred
  • Experience supporting federal or DoD information systems
  • CISSP, CAP, or CISM certification
  • Familiarity with continuous monitoring and vulnerability management tools
Skills
Risk Management Framework (RMF)Vulnerability assessmentSecurity complianceIncident responseAccess control reviewSecurity documentation
How to use this template

Eight steps from download to publish.

  1. 01Open the Information System Security Officer (ISSO) job description in Word or your one-click Google Docs copy.
  2. 02Replace placeholders for company name, reporting line, and location with your specifics.
  3. 03Tighten the summary to one paragraph that names the team's outcome, not just the role.
  4. 04Edit the responsibilities to match the actual scope of the seat — aim for 6 to 8 items, not 12.
  5. 05Separate required qualifications from preferred. Required is what a candidate must have to do the work on day 30; preferred is what would make them excellent in year two.
  6. 06Add salary range guidance using BLS, Payscale, or your own band data — do not copy generic figures.
  7. 07Have the hiring manager and one peer read it. Cut anything that wouldn't survive a candidate question.
  8. 08Publish to your ATS, intranet, and external careers page.
When to use this template

The right document at the right moment.

Use this Information System Security Officer (ISSO) job description any time you are opening or reopening a seat at this level. The senior band sets the calibration — copy the document, tighten it to your specific scope, and circulate to the hiring panel before the first interview.

The reporting line (Information System Security Manager (ISSM)) and skills list are starting points. Override either if your org structure or stack differs from the norm — the template is a draft, not a contract.

FAQ

Honest answers before you download.

What's the difference between an ISSO and an ISSM?
An ISSO handles day-to-day security implementation and monitoring for assigned systems, while an ISSM has broader program-level oversight and reports risk decisions to leadership.
Is a security clearance required for this role?
Many ISSO positions, especially federal or defense contracts, require an active or eligible-to-obtain security clearance; requirements vary by employer and contract.
Legal note

This Information System Security Officer (ISSO) job description is a professionally drafted starting point for your hiring process and is not legal advice. Hiring practice varies by jurisdiction (e.g. pay-transparency laws differ across US states and AU jurisdictions). Adapt this document for your specific location and have employment counsel review any clauses you add before publishing. Salary varies by region, employer type, and experience. Reference BLS or current industry surveys for ranges. Full disclaimer.