Information Systems Security Officer

Geodesicx Inc
Charleston, SC, United States
9 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Desktop Computing Security Content Automation Protocol Verification and Validation (Software) Software Vulnerability Management SARS Software Products Documentation System Information Technology Nessus Operational Systems Plan of Action and Milestones
+1 more
Vulnerability Analysis

Job description

The Information Systems Security Officer (ISSO) Contractor will serve as a primary cybersecurity technical advisor and Risk Management Framework (RMF) executor in support of the Program Manager Advanced Amphibious Assault (PM AAA) Information Systems Security Manager (ISSM). This role is critical to ensuring the cybersecurity posture and successful accreditation of all systems and sub-systems on current and future United States Marine Corps (USMC) Amphibious Combat Vehicle (ACV) variants, with a specific focus on deployed Command, Control, Communications, and Computers (C4) systems.

This is an Assessment and Authorization (A&A) focused role. The candidate will steer accreditation efforts, develop comprehensive RMF documentation, and drive Authority to Operate (ATO) packages through the Department of Defense (DoD) lifecycle in accordance with the Risk Management Framework (DoDI 8510.01). The ISSO will act as the ISSM’s right hand, managing the tactical execution of the cybersecurity program, ensuring operational systems and networks remain compliant, secure, and fully accredited.

Responsibilities

  • Lead the planning, coordination, and execution of A&A events, including RMF ATO efforts for current and future PM AAA Vehicle Variants and support software.
  • Develop, review, endorse, and maintain A&A documentation System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms) in accordance with DoD, Department of Navy (DoN), and Marine Corps policies.
  • Upload all artifacts and maintain system information repositories within Enterprise Mission Assurance Support Service (eMASS).
  • Support periodic security events including the Annual Security Review (ASR), Independent Verification and Validation (IV&V), and Annual Federal Information Security Modernization Act (FISMA) Reviews.
  • Advise the ISSM in ensuring information ownership responsibilities and baselines are established for ACV C4 systems (including accountability, access approvals, and special handling).
  • Perform required compliance assessments for C4 systems deployed on PM AAA Family of Vehicles (FoVs); review, document, and maintain all results.
  • Assess, mitigate, track, and document vulnerabilities on the Information Technology (IT) Security POA&M.
  • Initiate protective or corrective measures required to maintain the accredited security posture of deployed C4 systems, enforcing DoD, DON, and local Privacy Act policies.

Requirements

  • Clearance: Active U.S. Government Security Clearance (Secret or higher)
  • RMF Expertise: Proven, hands-on experience preparing and walking DoD RMF accreditation packages (ATOs) through the complete lifecycle in accordance with DoDI 8510.01, NIST SP 800-53 Rev 5, CNSSI 1253, and ICD 503.
  • A&A Tooling: Direct experience utilizing eMASS and/or Marine Corps Compliance and Authorization Support Tool (MCCAST) to build, track, and submit system artifacts and ATO packages.
  • Vulnerability Scanning & Compliance: Demonstrated capability implementing, verifying, and operating mandatory DoD compliance tools, specifically:
  • Assured Compliance Assessment Solution (ACAS) / Nessus
  • Security Content Automation Protocol (SCAP) Compliance Checker (SCC)
  • Host Based Security System (HBSS) / Endpoint Security Solutions (ESS)
  • STIG & IAVM: Extensive experience applying, documenting, and mitigating Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Information Assurance Vulnerability Management (IAVM) notices.

Desired Skills

  • Prior experience supporting USMC System Commands (MARCORSYSCOM) or specifically Portfolio Acquisition Executive-Marine Corps (PAE-MC) / PM AAA.
  • Familiarity with the ACV platform, tactical C4 systems, or ground combat vehicle architectures.
  • Experience securing and accrediting embedded systems, tactical edge networks, and standalone tactical variants.
  • Familiarity with Marine Corps specific cybersecurity workflows (e.g., MCSC SEAL CYB Branch interactions).
  • Strong verbal and written communication skills to effectively translate complex technical vulnerabilities into executive-level risk assessments for the ISSM and Program Manager.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:31 min

MS-DOS era and the rise of desktop computing standardization

Joel Spolsky · WWC 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

56 sec

Taking the leap into desktop and mobile applications

Brian Morrison · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all