nInformation Systems Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Requirements
- Must have a current Top-Secret clearance with the ability to obtain a TS/SCI security clearance.\n
- A Security+ CE is required. \n
- Must have or be able to obtain within six months of hire, a DoD 8570 IAT Level III certification (CISSP, CASP+, CISA, GCED, GICSP, CGRC, etc.).\n
- Bachelor’s degree in Cybersecurity, Information Technology, Information Systems or a related field from an accredited college or university and 8+ years of experience or equivalent combination of work experience and education.\n
- 2+ years of experience as an ISSO or ISSM.\n
- 1-2 years of experience securing cloud-native environments, including AWS and Kubernetes, with knowledge of container security, IAM, logging, monitoring, vulnerability management and compliance requirements.\n
- Experience maintaining Authority to Operate (ATO) packages within eMASS or XACTA and supporting RMF activities for classified systems.\n
- Experience conducting ACAS vulnerability scanning, vulnerability remediation tracking and POA&M management.\n
- Experience reviewing security logs, audit records, and compliance evidence to support. Continuous Monitoring (ConMon) requirements.\n
- Experience implementing and maintaining security controls in accordance with NIST 800-53 and DoD cybersecurity requirements.\n
- Experience with Linux operating systems and command-line administration.\n
- Experience with virtualized environments and hypervisors.\n
- Knowledge of XACTA or eMASS.\n
- Knowledge of the A&A process for DoD information systems.\n
- Knowledge of NISPOM, DCSA A&A; Process Manual, JSIG, ICD 503/703, STIGs, RMF and associated NIST publications.\n
- Knowledge of incident handling and response procedures, including data spills involving unclassified and classified systems.\n
- Previous experience within the U.S. Department of Defense highly desired. \n
- Expected travel up to 10% (1-2 trips/year). \n
Benefits & conditions
The Information Systems Security Officer (ISSO) is responsible for implementing and maintaining cybersecurity controls for DoD classified information systems in compliance with RMF, NIST 800-53, STIGs, National Industrial Security Program Operating Manual (NISPOM), Joint Special Access Program Implementation Guide (JSIG) and related cybersecurity requirements. This role supports the full Assessment and Authorization (A&A) lifecycle, including maintaining Authority to Operate (ATO) packages in eMASS/XACTA, conducting Continuous Monitoring (ConMon), reviewing security logs and audit evidence, managing Assured Compliance Assessment Solution (ACAS) vulnerability scans, tracking remediation activities and Plan of Action Milestones (POA&Ms) and supporting incident response procedures. The ISSO will administer security within Linux, virtualized and cloud-native environments, including AWS and Kubernetes, while collaborating with system administrators, engineers and government stakeholders to ensure compliance and operational security.\n Requirements:\n \n The physical demands and work environment described here are representative of those that must be met by an employee to successfully perform the essential functions of the job. Reasonable accommodations may be made to individuals with disabilities to perform the essential functions.\n \n, * Experience with Splunk, ACAS/Tenable, VMware vSphere/ESXi, and enterprise vulnerability management programs.\n
- Experience supporting Security Control Assessments (SCAs) and (ConMon) activities.\n
\n Salary Range: $125K-$150K\n \n Based on your qualifications, you will be placed in Level I-V.\n \n An essential qualification for this position is successfully obtaining a security clearance issued by the Federal Government, which may require successful completion of a background check.\n \n We use E-Verify to electronically confirm the employment eligibility of newly hired employees.\n \n AUSGAR’s salary range is dependent upon a variety of factors, which include experience, skills, education, certifications and geographical location. Our salary range includes a base salary and excellent benefits package as part of our total compensation.\n \n
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on jobs.military.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Paying Jobs in Technology
The Overflow: Security and Privacy
Highest Paying Tech Companies for Developers