Information System Security Officer (ISSO)

MAG DS Corp dba MAG Aerospace
Cumberland County, NC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Xacta Microsoft Windows Cloud Computing Cyber Security Information Systems Custom Software Linux Federal Information Processing Standards (FIPS) Identity and Access Management Information Security Management Networking Hardware Websense
+1 more
Information Technology

Job description

The MAG Team is seeking to hire an experienced Information Systems Security Officer to support the Special Operations community based out of Ft. Liberty (formerly Ft. Bragg), NC!

In this role, you will provide a variety of services leveraging the Risk Management Framework (RMF) accreditation. Services are associated with validation, approval, and sustainment of cybersecurity accreditation packages. Additionally, you will performs and analyze a range of Information Security Systems Officer activities and assist with the development and implementation of security policies., Duties include, but are not limited to :

  • Gather and translate customer requirements, interact with stakeholders from many areas, and lead efforts to ensure customer products and recommendations will meet customer information security policies in an ever-changing technical environment
  • Categorize the IT and the information processed, store, and transmitted by the system based on an impact analysis due to a loss of Confidentiality, Integrity, and Availability (CIA) impacts
  • Select an initial set of baseline security controls for the Information System (IS) based on the security categorization; overlay tailoring and supplementing the security control baseline as needed based on an organizational assessment of risk and local conditions
  • Assess the security control using the appropriate methods and procedures to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome
  • Authorize the IS based on the determination of the risk to the organizational operations, organizational assets, or to individuals resulting from the operation of the IS and the decision that this risk is acceptable
  • Monitor the security of the IS on a continuous basis including assessing control effectiveness, documenting changes to the system, conducting security impact analyses of the associated changes, and reporting the security status of the system to appropriate organizational officials on a regular basis
  • Review, prepare and update RMF authorization packages
  • Conduct assessments of information security controls to measure the effectiveness of controls and identify any gaps
  • Manage remediation efforts and report on the status of control deficiencies
  • Provide security expertise to business units and key stakeholders
  • Provide timely status updates/reporting on assessments and assigned projects

Requirements

Minimum Requirements

Knowledge and Skills

  • In compliance with DoD Cyber Workforce 8570.01
  • Experience in Information Assurance / Cybersecurity, including development, integration, and implementation of cyber security and program protection standards for networking, computers, and custom applications
  • Thorough knowledge of the Department of Defense 8510.01 Risk Management Framework (RMF) for DoD Information Technology, DoD Instruction 8500.1 Cyber Security, DoD Directive 8140.01, Cyberspace Workforce Management, NIST 800 Special Publications, Federal Information Processing Standards (FIPS), and knowledge of current authorization practices, particularly within the DoD
  • Experience in creating and maintaining the security configuration baselines for Windows and Linux platforms, networking equipment, cloud technologies, and custom applications (i.e., Minimum Benchmarks: CIS, STIGS)
  • Provide subject matter expertise, advice and assistance in the planning, implementation, and accreditation of technology and solutions
  • Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Management Level IAM Level II

The minimum years of related experience required: 5+, * The minimum level of education required is: BS in Computer Science or Information Technology (or equivalent experience), * Familiar with DIA assessments and accreditation documentation within the XACTA management platform

  • Familiar with eMASS - USSOCOM ENTERPRISE MISSION ASSURANCE SUPPORT SERVICES platform
  • Meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Management Level (IAM Level III)
  • Ability to read, review, and consolidate ACAS scans, DISA STIGS, and Websense results
  • Excellent interpersonal skills, including the ability to work on multi-functional teams
  • Display detailed knowledge and understanding of multiple technology infrastructures
  • Ability to serve as a principal advisor on all matters, technical and otherwise, involving the security of an IS
  • Exhibit individual initiative to influence events and achieve goals. Be proactive and a self-starter, going beyond specific job responsibilities to ensure goals and achieved or exceeded
  • Travel as necessary for customer projects, technology expositions, and corporate meetings

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

58 sec

Securing uncontaminated AI training data and mandating Linux authentication

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all