Information Systems Security Officer II/III

Xsite Llc
San Diego, CA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$95,000.0 - $141,000.0
Working hours
Regular working hours
Job source

Tech stack

Configuration Management Cyber Security Information Systems Information Security Management Network Diagrams Software Vulnerability Management SARS Software Products C4i SC Clearance Information Technology Nessus Plan of Action and Milestones

Job description

  • Support Risk Management Framework (RMF), Assessment & Authorization (A&A), and Authorization to Operate (ATO) activities for Navy/DoD information systems.
  • Develop, review, maintain, and update cybersecurity documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Security Categorization documentation, Privacy Impact Assessments, and related A&A artifacts.
  • Support continuous monitoring, annual security reviews, control validation, and audit-readiness activities.
  • Coordinate with system owners, engineers, administrators, Security Control Assessors, Authorizing Officials, and other stakeholders to support cybersecurity compliance and risk management.
  • Track, document, and support remediation of vulnerabilities, STIG findings, POA&M items, and other cybersecurity risks.
  • Use cybersecurity and information assurance tools such as eMASS, ACAS/Nessus, STIG Viewer, and related DoD/Navy systems as required.
  • Support configuration management and baseline change activities to ensure cybersecurity impacts are identified, documented, and addressed.
  • Assist with cybersecurity inputs for system changes, boundary updates, hardware/software lists, network diagrams, and authorization packages.
  • Maintain awareness of applicable DoD, Navy, and federal cybersecurity policies, including RMF, NIST SP 800-53, DoDI 8510.01, and DoD 8140/8570 workforce requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, Business, Management, or a related technical or managerial field preferred. Additional relevant cybersecurity, military, Navy, RMF, A&A, or information assurance experience may be considered in lieu of degree.
  • 3-10 years of practical experience in cybersecurity, information assurance, engineering, test and evaluation, RMF, A&A, C&A, or related information system security support.
  • Experience supporting RMF, A&A, ATO lifecycle, cybersecurity compliance, or Navy/DoD information system security activities.
  • Experience preparing, maintaining, or reviewing cybersecurity artifacts and compliance documentation in support of ATO requirements.
  • Experience with Information Assurance tools such as eMASS and ACAS/Nessus.
  • Working knowledge of RMF, ATO requirements, POA&M tracking, vulnerability management, security controls, and information system security posture maintenance.
  • Active U.S. Secret clearance preferred; ability to obtain and maintain required clearance is required.
  • Strong written and verbal communication skills, with the ability to coordinate across technical teams, Government stakeholders, and program leadership., * Prior experience supporting PMW/A 170, PEO C4I, NAVWAR, NIWC, Navy PNT systems, or other Navy C4I/cybersecurity programs.
  • Current DoD 8140/8570-compliant certification such as Security+, CAP, CASP+, CISSP, CISM, GSLC, or equivalent.
  • Experience supporting classified and/or mission-critical Navy or DoD systems.
  • Experience with POA&M management, vulnerability remediation coordination, annual security reviews, continuous monitoring, and ATO sustainment.
  • Familiarity with CYBERSAFE, Cross Domain Solution documentation, Navy authorization packages, or Security Control Assessor coordination.
  • Experience supporting system boundary validation, hardware/software baselines, configuration control, or Baseline Change Requests.

Benefits & conditions

5.05.0 out of 5 stars 4250 Pacific Highway, San Diego, CA 92110 Hybrid work $95,000 - $141,000 a year - Full-time, Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance
  • Life insurance, * Seven paid company holidays annually, including New Year’s Day, Memorial Day, Independence Day, Labor Day, Veterans Day, Thanksgiving Day, and Christmas Day.
  • 100% employer-paid employee coverage for Medical, Dental, Vision, and Basic Life Insurance.
  • Employees enrolled in XSITE’s High Deductible Health Plan are also eligible for a Health Savings Account with employer contributions.
  • Eligibility to participate in XSITE’s 401(k) retirement plan with up to a 6% employer match.
  • Eligibility to receive tuition reimbursement of up to $5,250 per year for job-related education.
  • University of San Diego Education Benefits, including 10% tuition discount on select online degree programs and 25% discount on certificate programs.
  • Cell phone stipend.
  • Hybrid work environment.
  • Additional employee add-on benefits offered through ADP.

About the company

XSITE LLC is looking for an Information Systems Security Officer (ISSO) to join our team in San Diego, CA in support of the anticipated PMW/A 170 office/contract. This position is contingent upon contract award and Government approval, with award anticipated within the next few weeks.

We are a Service-Disabled Veteran-Owned Small Business headquartered in San Diego. We provide full-spectrum systems and systems-of-systems engineering and integration services and solutions for space, C5ISR, cyber, and enterprise information systems. Our core capabilities include AI/ML, Software Development & Sustainment, Systems Engineering, including MBSE, and Modeling & Simulation., Please note: This position is contingent upon contract award and Government approval. XSITE is proactively building its candidate pipeline for an anticipated award expected within the next few weeks.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all