Information System Security Officer (ISSO) - TS/SCI

Strategic Business Systems, Inc.
Jessup, MD, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Xacta Amazon Web Services Cloud Computing Security Cyber Security Identity and Access Management Information Security Management Zero Trust Network Access Software Vulnerability Management Cloud Platform System RSA Archer Platform Opsworks

Job description

SBS is seeking experienced to support Amazon Web Services (AWS) Federal customers operating within highly secure, classified cloud environments. This position is responsible for leading Risk Management Framework (RMF) activities, maintaining Authorization to Operate (ATO) packages, implementing continuous monitoring strategies, and ensuring compliance with NIST and DoD cybersecurity requirements across multiple security domains.

The ideal candidate possesses a strong background in RMF, cloud security, and AWS-native security services while partnering with engineering teams to maintain secure cloud environments supporting Department of Defense and Intelligence Community missions.

  • Develop, maintain, and update RMF documentation supporting IATT and ATO packages.
  • Author and maintain:
  • System Security Plans (SSPs)
  • Security Control Family Plans (AC, IA, SC, SI, etc.)
  • POA&Ms
  • Control implementation statements
  • Continuous Monitoring documentation
  • Support the full RMF lifecycle in accordance with DoDI 8510.01 and NIST SP 800-53 Rev. 5.

  • Monitor security posture across AWS environments supporting IL2, IL4, Secret, and TS workloads.
  • Assess cloud environments against NIST 800-53 security controls.
  • Configure and monitor AWS security services including:
  • GuardDuty
  • Security Hub
  • AWS Config
  • IAM
  • AWS Organizations / SCPs
  • Assist engineering teams in implementing secure cloud architectures.

  • Review vulnerability findings and support remediation efforts.
  • Maintain POA&Ms and continuous monitoring activities.
  • Work with third-party security tools including:
  • Palo Alto
  • ACAS
  • Elastic
  • Ensure compliance with customer cybersecurity policies and accreditation requirements.

  • Partner with cloud engineers, ISSOs, ISSEs, architects, and customer security teams.
  • Participate in security assessments and authorization reviews.
  • Provide guidance during audits and compliance activities.
  • Support ongoing improvements to cloud security posture and automation.

Requirements

  • 5+ years of Information Assurance, Cybersecurity, or Information System Security experience.
  • Minimum 2 years supporting RMF and NIST SP 800-53.
  • Minimum 1 year supporting AWS cloud security environments.
  • Experience creating and maintaining complete ATO packages.
  • Experience with SSPs, POA&Ms, Continuous Monitoring, and Control Implementation Statements.
  • Working knowledge of AWS security services.
  • Strong understanding of vulnerability management and security compliance.

  • Experience with eMASS, Xacta, Keyhole, or equivalent GRC platforms.
  • Experience supporting DoD IL2/IL4/Secret/TS cloud environments.
  • Familiarity with AWS Landing Zone Accelerator (LZA).
  • Experience implementing Zero Trust security principles.
  • DoD 8570/8140 IAM Level II or IAT Level III certification.
  • One or more of the following:
  • CISSP
  • CISM
  • CAP
  • CASP+

  • Excellent communication and documentation skills.
  • Strong analytical and troubleshooting abilities.
  • Ability to work independently in classified environments.
  • Experience supporting highly regulated Federal or Intelligence Community customers.

Benefits & conditions

Strategic Business Systems, Inc. (SBS) delivers AWS-aligned mission-critical cloud, cybersecurity, software engineering, and data modernization solutions to the U.S. Department of Defense, the Intelligence Community, and federal civilian agencies.

We hire engineers, architects, and consultants who want to do hands-on work on high-impact national-security programs while collaborating directly with AWS Professional Services. Our culture is technical, lean, and clearance-friendly: we invest in certifications, retain talent through long-duration prime engagements, and provide a comprehensive benefits package., COMPENSATION & BENEFITS

SBS offers a comprehensive total-rewards package, including a market competitive salary along with:

  • Comprehensive medical, dental, and vision coverage; HSA-eligible plan options available

  • 401(k) retirement plan with company match (vesting schedule per Plan Document)

  • Paid Time Off, federal holidays, and floating holiday for personal observance

  • Annual professional development support for AWS certifications, training, and conferences

  • Employee referral program where applicable and documented by program policy

  • Life, AD&D, and short- / long-term disability insurance

  • Telework and flexible-schedule support where mission and contract permit

  • Mission-focused federal contractor supporting national-security customers

is a national Information Technology services company headquartered in the Washington, D.C. metropolitan area. SBS provides IT infrastructure design, integration, and operational services. Our expertise spans the full spectrum of infrastructure technologies, including networking, servers, data storage, disaster recovery, cybersecurity, and internet technologies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all