Information Systems Security Officer

McLaughlin Research Corporation
Middletown, RI, United States
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Xacta Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Technology Plan of Action and Milestones

Job description

We are seeking an experienced Information Systems Security Officer (ISSO) to support cybersecurity compliance and accreditation activities supporting a Department of Defense (DoD) cloud environment. The ideal candidate will possess extensive experience navigating the Navy Authorization to Operate (ATO) process and will serve as a cybersecurity resource responsible for guiding the system through the DoD Risk Management Framework (RMF) lifecycle.

This position will work closely with government stakeholders, engineering teams, cloud architects, and program leadership to achieve and maintain authorization while ensuring compliance with DoD cybersecurity requirements., * Lead cybersecurity activities throughout the DoD Risk Management Framework (RMF) lifecycle.

  • Manage the development, review, and maintenance of RMF artifacts and authorization documentation.
  • Serve as the primary ISSO supporting the achievement of a Navy Authorization to Operate (ATO).
  • Coordinate directly with government Authorizing Officials (AO), Information System Security Managers (ISSM), validators, and cybersecurity representatives.
  • Build and maintain effective working relationships with Navy cybersecurity organizations to facilitate the authorization process.
  • Utilize eMASS to manage security controls, documentation, findings, and authorization packages.
  • Coordinate Security Technical Implementation Guide (STIG) implementation and validation across Windows, Linux, networking, and cloud environments.
  • Conduct security control assessments against NIST SP 800-53 requirements.
  • Support vulnerability management, POA&M development, and continuous monitoring activities.
  • Collaborate with engineering teams to implement secure cloud architectures within Azure Government and/or AWS GovCloud.
  • Assist with DoD Cloud Security Requirements Guide (SRG) compliance activities.
  • Support future Secret-level accreditation efforts and classified system expansion.
  • Provide cybersecurity guidance throughout system design, implementation, and operational phases.
  • Develop executive-level status reports and communicate cybersecurity risks to technical and non-technical stakeholders.

Requirements

  • Active Secret Security Clearance
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience)
  • 5+ years supporting DoD cybersecurity programs
  • Demonstrated experience implementing the DoD Risk Management Framework (RMF)
  • Extensive experience with Navy Authorization to Operate (ATO) processes
  • Strong working knowledge of:
  • NIST SP 800-53
  • DoD RMF
  • Security Controls Assessment process
  • POA&M management
  • Continuous Monitoring
  • Experience using eMASS
  • Active DoD CAC (preferred) or ability to obtain eMASS access
  • Experience implementing and remediating Security Technical Implementation Guides (STIGs)
  • Familiarity with Microsoft Azure Government and/or AWS GovCloud
  • Understanding of FedRAMP security requirements and cloud compliance
  • Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG)
  • Excellent communication and documentation skills

Highly Desired Qualifications:

  • Extensive experience obtaining Navy ATOs
  • Existing relationships within Navy cybersecurity organizations
  • Current Navy CAC with Flank Speed access
  • Ability to access SIPRNet on a regular basis
  • Experience supporting Secret or higher classified information systems
  • Xacta experience
  • TS/SCI Security Clearance
  • CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certifications

About the company

McLaughlin Research Corporation is a full life cycle engineering and technical services company, partnering with our customers to support a wide range of Department of Defense weapon, combat, and sensor system programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on mrcds.hua.hrsmart.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all