Information Systems Security Officer

Anduril Anduril · Defense · Costa Mesa, CA · Corporate Technology : Classified Systems : Classified Infrastructure

The Information Systems Security Officer (ISSO) at Anduril Industries, a defense technology company, is responsible for securing classified, closed, or air-gapped environments where Anduril products are deployed. This role involves documenting security controls, performing security functions, applying technology standards in secure environments, assisting with technical solutions for contractual obligations, tailoring NIST 800-53 controls, defining and conducting security scanning, and orchestrating feature development for compliance. The position requires expertise in secure systems and networks per NIST RMF, JSIG, participating in security risk assessments, recommending security solutions, developing access controls, maintaining accreditation documentation, managing security posture, participating in Authorization and Accreditation (A&A) processes, leading incident response, conducting audits, and collaborating with government security officials. A U.S. Top Secret security clearance is mandatory.

What you'd actually do

  1. Provide expertise in documenting security controls that apply to respective systems to meet cybersecurity framework requirements..
  2. Perform required security functions on an iterative basis to meet requirements and deliver results.
  3. Apply technology standards from the commercial space in classified, air-gapped environments.
  4. Assist the ISSM, fellow ISSOs, and other members of the Classified Infrastructure team to understand key stakeholders’ needs and provide complex technical solutions to meet contractual obligations.
  5. Tailor NIST 800-53 controls to determine applicability to the network environment and oversee the implementation of Continuous Monitoring for respective programs.

Skills

Required

  • Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards.
  • Participate and assist in security risk assessments, vulnerability assessments, and audits to identify and mitigate threats.
  • Speak to and recommend security solutions, such as IDS/IPS, encryption protocols, and secure communications technologies.
  • Develop and enforce access controls, encryption strategies, and other technical measures to safeguard systems.
  • Maintain and update System Security Plans (SSPs), POA&Ms, and other accreditation documentation.
  • Manage the organization’s security posture, ensuring compliance with internal policies and external regulatory frameworks.
  • Participate in the Authorization and Accreditation (A&A) processes to obtain/maintain system Authority to Operate (ATO).
  • Able to assist, even lead, incident response efforts, including investigation, root cause analysis, containment, and reporting.
  • Conduct regular audits, continuous monitoring, and risk assessments to ensure ongoing compliance and system resilience.
  • Collaborate with government security officials, stakeholders, and teams to address security gaps and improve controls.
  • Currently possesses and is able to maintain an active U.S. Top Secret security clearance.

Nice to have

  • Experience with industry standard tools such as Splunk, DISA STIGs, and SCC.
  • The ability to understand programming/scripting languages, i.e. Python, Powershell, Bash
  • An understanding of Linux Red Hat operating systems and SELinux policy.

What the JD emphasized

  • NIST RMF
  • JSIG
  • Authorization and Accreditation (A&A)
  • U.S. Top Secret security clearance