Information Security Systems Operator (ISSO)

V2X Inc
Barstow, CA, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Computer Engineering Identity and Access Management Information Security Management Information Systems Security Architecture Professional EPolicy Orchestrator Software Vulnerability Management SC Clearance Information Technology Nessus Splunk
+2 more
Scap Compliance Checker Plan of Action and Milestones

Job description

Information System Security Officer (ISSO) with extensive experience supporting classified and unclassified enterprise networks within the U.S. Department of War (DoW)/federal defense environment. Skilled in implementing and maintaining information assurance and cybersecurity controls in accordance with NIST RMF, CNSSI, and DoD/IC directives. Demonstrated expertise in vulnerability management, system hardening, security assessment and authorization (A&A), continuous monitoring, and incident response. Proven ability to collaborate with system owners, engineers, and mission stakeholders to develop secure architectures, author and maintain security documentation (SSP, POA&M, SCTM, etc.), and ensure continuous compliance with government and contractual requirements. Strong communicator with a track record of supporting complex, mission-critical systems and enabling warfighter and national security objectives while managing cyber risk.

Responsibilities

Responsibilities:

  • Conducts regular security assessments and audits on I.T. devices and information system assigned to identify vulnerabilities, security gaps, and non-compliance with security policies and standards in support of U.S. Army’s Warfighter Training& Readiness Solutions ( W-TRS) program

  • Performs risk analysis to evaluate the potential impact of identified vulnerabilities on the security and operations of training Devices

  • Determines the likelihood of a security breach and the potential consequences

  • Ensures that all DoD and U.S. Army security policies, procedures, and standards are properly implemented in all training devices

  • Prepares for and respond to security incidents involving training devices

  • Creates and maintains detailed RMF body of evidence, documentation of all security assessments, audits, incidents, and remediation efforts

Qualifications

Required Qualifications:

  • Conduct regular security assessments and audits on IT devices / Information Systems to identify vulnerabilities, security gaps, and non-compliance with security policies and standards, using both manual inspections and automated tools to scan for vulnerabilities

  • Participate in the Risk Governance process to provide security risks, mitigations, and input on other technical risk. Prepares and presents reports on the security posture to senior management and other stakeholders

  • Create and maintain detailed RMF Assess and Authorization (A&A) documentation, incident reports, findings from device / information system examinations, summaries, and other situational awareness information

  • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs)

  • Experience with creating / managing plans of actions and milestones (POA&Ms) or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc

  • ACAS/Nessus vulnerability scans, review audit logs in Splunk to detect suspicious or unauthorized activity, and that all modules are functioning / detecting for HBSS/ TRELLIX

  • Stay abreast of the latest security threats, trends, and technologies

  • Ability to provide continuous evaluations and improve the security measures in place to address evolving security challenges

  • Familiar with all DoD Cybersecurity guidance, NIST Special Publications, and U.S. Army Information Technology / Cybersecurity Regulations

Requirements

  • Experience working with DoD / U.S. Army / Federal Government

  • Experience with software/tools: ACAS / Nessus, Splunk, ePolicy Orchestrator - HBSS/TRELLIX, SCAP Compliance Checker (SCC), STIG Viewer, eMASS

  • Experience as an ISSO

Education/Experience:

  • High School Diploma or Equivalent with 6+ years of experience or

  • A.A. in Engineering, Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or related field with 4+ years of experience or

  • B.S. in Engineering, Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or related field with 2+ years of experience or

  • Masters in Engineering, Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or related field with 1+ years of experience

Certification(s):

  • 8140/8570 DoD Certification; Foundation-Intermediate / Information Assurance Manager I (IAM I)

Clearance Required:

  • Active Secret Clearance of the ability to obatin a Secret clearance within 6 months of hire.

About the company

Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $4.5B company and 16,000 people work alongside our clients, here and abroad, to tackle their most complex challenges with integrity, respect, responsibility, and professionalism., At V2X, we are deeply committed to both equal employment opportunity, including protection for Veterans and individuals with disabilities, and fostering an inclusive and diverse workplace. We ensure all individuals are treated with fairness, respect, and dignity, recognizing the strength that comes from a workforce rich in diverse experiences, perspectives, and skills. This commitment, aligned with our core Vision and Values of Integrity, Respect, and Responsibility, allows us to leverage differences, encourage innovation, and expand our success in the global marketplace, ultimately enabling us to best serve our clients.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role β€” technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder Β· LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 Β· LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Β· Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 Β· LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler Β· LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all