Draper Logo

Draper

Information System Security Officer

Posted One Month Ago
Be an Early Applicant
In-Office
Cambridge, MA, USA
75K-156K Annually
Junior
In-Office
Cambridge, MA, USA
75K-156K Annually
Junior
Support continuous monitoring and authorization of classified information systems. Conduct audits, continuous monitoring, incident response, vulnerability assessments, and configuration management using STIG/SCAP/Nessus under ISSM direction. Ensure user clearances and maintain security documentation and compliance.
The summary above was generated by AI

Overview:

Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful and usable solutions. From military defense and space exploration to biomedical engineering, lives often depend on the solutions we provide. Our multidisciplinary teams of engineers and scientists work in a collaborative environment that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit www.draper.com.

Job Description Summary:

The Information System Security Officer 1 (ISSO) supports the continuous monitoring and authorization efforts of multiple classified information systems under the direction of the Information System Security Manager (ISSM). Performing a variety of technical, and non-technical Cyber Security functions.

Job Description:

Duties/Responsibilities
• Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM.
• Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the security authorization package.
• Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
• Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the IS.
• Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
• Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
• Formally notify the ISSM and AO/DAO when changes occur that might affect system authorization.
• Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
• Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
• With supervision, Conduct Audits and Continuous Monitoring (ConMon) activities using available technical and non-technical processes, Reports Audit and ConMon findings, Conduct incident response steps as directed.
• With supervision, manage configuration baselines of both hardware and software, Identify system architecture flaws using industry standard tools (e.g. STIG, SCAP, Nessus) that will be flowed to the ISSM for review.
• Performs other duties as assigned.
Skills/Abilities
• Understanding of information security concepts (e.g. RMF, DIACAP)
• Awareness of audit technologies or capabilities (e.g. Splunk, event viewer)
• Understands Information Technology basics.
• Awareness of network type designations (e.g. WAN, LAN) and associated infrastructure (e.g. Servers, switches, firewalls).
Education
• Requires a bachelor's degree in Information Technology or a related field.
• Equivalent industry experience may be substituted.
• Ability to acquire an IAM I/IAT II Certification within 6 months of start date.
Experience:  
• 1-3 years year relevant industry experience is required,
• Preferred experience with RMF (NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-Relevant Tools.

Additional Job Description:

Applicants selected for this position will be required to obtain and maintain a government security clearance.

Current in scope Top Secret security clearance is required.

Connect With Draper for Future Opportunities! If you don't find the right posting in our Career Opportunities, you may submit your resume for future consideration.

Job Location - City:

Cambridge

Job Location - State:

Massachusetts

Job Location - Postal Code:

02139-3563

The US base salary range for this full-time position is

$75,000.00 - $156,000.00

Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Union ranges will be in compliance with the collective bargaining agreement's approved rates by location and role. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.  Please note that the compensation details listed in US role postings reflect the base salary only, and does not include bonuses or benefits.

Our work is very important to us, but so is our life outside of work. Draper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. If this specific job opportunity and the chance to work at a nationally renowned R&D innovation company appeals to you, apply now www.draper.com/careers.

Draper is committed to creating an inclusive environment. We understand the value of inclusivity and its impact on a high-performance culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, national origin, veteran status, or genetic information. Draper is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, please contact [email protected].

HQ

Draper Cambridge, Massachusetts, USA Office

555 Technology Square, Cambridge, MA, United States, 02139

Similar Jobs

16 Days Ago
Remote or Hybrid
US
140K-175K Annually
Mid level
140K-175K Annually
Mid level
Information Technology
Performs IT audits and cybersecurity control validation for complex systems, applications, enclaves, and classified or unclassified networks. Assesses vulnerabilities, risks, security requirements, and mitigation effectiveness against Federal and DoD standards. Provides technical evaluations and recommends security improvements while balancing business needs with security concerns. Requires experience with RMF, DODI 8500.2 or NIST SP 800-53, eMASS, network implementation, and an active DoD Secret clearance.
Top Skills: Dodi 8500.2EmassMicrosoft AccessExcelMS OfficeMicrosoft PowerpointMicrosoft WordNetwork SecurityNist Sp 800-53Risk Management Framework (Rmf)
3 Days Ago
In-Office
Hanscom AFB, MA, USA
132K-141K Annually
Senior level
132K-141K Annually
Senior level
Information Technology • Professional Services • Cybersecurity • Defense
Maintains the security posture of DoD information systems supporting Collateral, SCI, and SAP environments. Performs continuous monitoring, authorization package development, configuration management, vulnerability identification, compliance assessments, audit review, incident handling, media sanitization, and security training. Coordinates system changes with ISSM and authorization officials, supports RMF assessment and authorization activities, and ensures physical, personnel, environmental, and operational security requirements are met.
Top Skills: CybersecurityNetworkingOperating SystemsRisk Management Framework (Rmf)Special Access Programs (Sap)
8 Days Ago
In-Office
Bedford, MA, USA
Senior level
Senior level
Professional Services • Consulting • Cybersecurity • Defense
Manages day-to-day information system security operations for DoD Special Access Programs, Collateral, and TS/SCI environments. Responsibilities include maintaining authorization packages, continuous monitoring, configuration management, audit review, incident handling, vulnerability mitigation, security documentation, self-inspections, and RMF assessment and authorization support. The role coordinates with ISSMs, ISOs, authorizing officials, and government and contractor organizations while ensuring compliance with security procedures and authorization requirements.
Top Skills: Configuration ManagementNetworkingOperating SystemsRisk Management Framework (Rmf)Sensitive Compartmented Information (Sci)Special Access Programs (Sap)

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account