Junior Information System Security Officer (ISSO)

ASEC Inc
Ridgecrest, CA, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
2 years minimum
Compensation
$90,000.0 - $110,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows CompTIA Security+ Cyber Security Information Systems Linux Information Security Management Networking Hardware SAP (Applications) Software Vulnerability Management SARS Software Products Information Technology Scap Compliance Checker
+2 more
Plan of Action and Milestones Vulnerability Analysis

Job description

  • Support the implementation and enforcement of cybersecurity policies, standards, and procedures in alignment with DoD RMF requirements.
  • Perform vulnerability assessments using tools such as ACAS, SCAP Compliance Checker, and DISA STIG benchmarks to identify and remediate security gaps.
  • Apply and validate DISA STIG configurations across Windows, Linux, and network devices to ensure compliance with DoD security standards.
  • Assist in continuous monitoring activities, including reviewing audit logs, tracking POA&M items, and supporting security control assessments.
  • Contribute to the development and maintenance of RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and related artifacts supporting ATO efforts.
  • Coordinate with system owners, engineers, and ISSMs to track vulnerabilities, implement mitigations, and support remediation timelines.
  • Review and verify compliance of hardware and software against NIAP Common Criteria certifications and the DISA Approved Products List (APL).
  • Support preparation of security authorization packages and interface agreements (MOAs/MOUs) for interconnected systems.
  • Conduct risk assessments and assist in identifying mitigation strategies to protect classified and unclassified DoD information systems.
  • Participate in cybersecurity working groups and cross-functional meetings to ensure alignment with program milestones and mission objectives.
  • Provide user awareness support and assist with incident response documentation and reporting activities.

This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary., * Supporting continuous monitoring, security audits, risk assessments, and mitigation planning

  • Reviewing technologies for compliance with NIAP Common Criteria and the DISA Approved Products List (APL).
  • Familiarity with ICD 705, DoD 5205.07/5205.07-M (Vol 1-4), SAP policy, and JSIG requirements.

Requirements

Join a mission-focused cybersecurity team protecting critical DoD information systems. As a Junior Information System Security Officer (ISSO), you’ll play a hands-on role in vulnerability management, RMF compliance, and continuous monitoring, gaining valuable experience while directly supporting a mission-critical program. If you’re detail oriented, technically driven, and ready to grow in a high-impact security environment, this is your opportunity to make a difference., What You’ll Bring:

  • CompTIA Security + is required. BS degree in Information Technology, Cybersecurity, Computer Science, or related area of study, desired. The following certifications are highly desired: CISSP, SecurityX (formerly CASP+), CISM, or GSLC. Please upload copies of any relevant IT certifications you hold.

2-3 years of experience in the following technical areas is preferred:

  • Information Assurance / Cybersecurity (IA/CS) within DoD environments.
  • Risk Management Framework (RMF) in accordance with DoDI 8510.01.
  • Implementation of security controls aligned with CNSSI 1253, NIST SP 800-53, and JSIG
  • Conducting vulnerability assessments using ACAS, DISA STIGs, and SCAP Compliance Checker with automated benchmarks., * Ability to build positive, collaborative relationships across teams and with external partners.
  • Effective communicator with strong verbal and written skills.
  • Proactive, self-directed work style with the ability to operate independently.
  • Analytical thinker with proven problem-solving capabilities.
  • Highly organized, with the ability to balance competing priorities in a fast-paced environment.

Benefits & conditions

  • The anticipated annual salary range for this position is $90,000 - $110,000, commensurate with an individual’s experience, qualifications, and skill set. ASEC is committed to providing fair and equitable compensation. The low end of this salary range is accounting for a candidate that meets or exceeds all of the listed requirements., * 100% employee-owned company. Learn more about our Employee Stock Ownership Plan (ESOP) here!
  • Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
  • 401(k) with company match
  • Tuition assistance for undergraduate and graduate education
  • Veteran-friendly employer
  • Thriving employee culture

About the company

ASEC is committed to providing access and reasonable accommodation in its services, activities, programs, and employment opportunities in accordance with the Americans with Disabilities Act and other applicable laws., ASEC offers meaningful, mission-driven work within a culture that supports your professional and personal growth. We partner with our government customers to deliver innovative solutions across engineering, information technology, training, and logistics. Above all, we are committed to doing what’s right for the Warfighter-plain and simple. Explore what makes ASEC different by visiting our website.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:24 min

Installing premium packages using the Store CLI

Noraa Junker Noraa Junker · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all