ISSO

Kforce Inc.
Huntsville, AL, United States
about 2 months ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Xacta Cyber Security Information Systems Disaster Recovery Software Vulnerability Management Information Technology Nessus RSA Archer Platform Plan of Action and Milestones Vulnerability Analysis

Job description

We are seeking a Senior Information Systems Security Officer (ISSO) to support mission-critical federal and defense systems within a highly secure environment. This individual will serve as the principal cybersecurity advisor to system owners, business stakeholders, and information security leadership, ensuring systems maintain compliance with federal cybersecurity requirements while supporting operational mission objectives.

The ideal candidate has extensive experience supporting Risk Management Framework (RMF) activities, Authorization to Operate (ATO) processes, cybersecurity compliance efforts, vulnerability management, and continuous monitoring programs within complex government environments., Serve as the primary cybersecurity advisor to the Information System Owner (ISO), Business Process Owner, ISSM, and cybersecurity leadership Ensure implementation, maintenance, and effectiveness of security controls throughout the system lifecycle Apply RMF principles and oversee compliance activities supporting authorization and accreditation requirements Guide systems through the Authority to Operate (ATO) lifecycle, including documentation development, review, submission, and maintenance Develop, review, maintain, and update cybersecurity documentation including: System Security Plans (SSPs) Contingency Plans Security Assessment documentation Policies and procedures Supporting authorization artifacts Create, update, and manage Plans of Action & Milestones (POA&Ms) based on vulnerability and compliance findings Conduct security control reviews and validate compliance with applicable federal and organizational requirements Perform and support network self-inspections, security reviews, and compliance assessments Track remediation activities and coordinate corrective actions for identified vulnerabilities and deficiencies Monitor security posture through continuous monitoring activities and vulnerability management processes Coordinate with engineers, system administrators, developers, and security teams to ensure security requirements are properly implemented Evaluate cybersecurity risks and provide recommendations to reduce operational and security exposure Prepare compliance reports, risk assessments, status updates, and executive-level briefings Support audits, inspections, security assessments, and external reviews Provide guidance regarding security architecture, operational security requirements, and system hardening activities Assist with developing and maintaining contingency planning and disaster recovery documentation, Xacta eMASS NIST 800-53 SSP Development POA&M Management Vulnerability Management ACAS Nessus STIG Compliance Security Assessments Continuous Monitoring Risk Analysis Audit Readiness Information Assurance Cybersecurity Governance Compliance Management

Requirements

Bachelor’s Degree in Information Assurance, Cybersecurity, Information Technology, Computer Science, Engineering, or a related field 10+ years of cybersecurity, information assurance, ISSO, RMF, or compliance experience Experience serving as an ISSO, Information Assurance professional, or cybersecurity compliance lead Strong knowledge of Risk Management Framework (RMF) Experience supporting Authority to Operate (ATO) activities and security authorization processes Experience developing and maintaining SSPs, POA&Ms, security assessment documentation, and compliance artifacts Knowledge of NIST 800-53 security controls and federal cybersecurity requirements Experience conducting vulnerability assessments and coordinating remediation efforts Familiarity with Security Test & Evaluation (ST&E) activities Strong understanding of cybersecurity governance, risk management, and compliance principles Experience supporting continuous monitoring programs and audit readiness initiatives Excellent written, verbal, organizational, and interpersonal communication skills Ability to work independently and provide guidance to technical and non-technical stakeholders

Preferred Qualifications Experience using Xacta or similar GRC platforms Experience using eMASS or other federal compliance management systems Experience supporting DoD, Intelligence Community, or other federal environments Experience supporting classified systems and secure operational environments Experience with vulnerability management tools and compliance reporting solutions Experience performing security control assessments and risk analysis activities Familiarity with incident response, auditing, and cybersecurity operations Knowledge of DISA STIGs, NIST standards, and federal security policies, Strong cybersecurity leadership within complex environments Ability to balance security requirements with mission objectives Experience guiding systems through accreditation and compliance processes Strong documentation and communication skills Ability to collaborate effectively with system owners, engineers, security personnel, and executive leadership Commitment to maintaining secure, compliant, and resilient information systems supporting critical operations

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all