Information Systems Security Officer (ISSO)...

Kaizen Approach, Inc
Annapolis Junction, MD, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Systems Engineering Configuration Management Communications Protocols Cyber Security Information Systems Firmware Identity and Access Management Information Security Management Public Key Infrastructure Software Requirements Analysis Network Switches Network Routers
+5 more
Software Security Firewalls (Computer Science) Information Technology Network Server User Identification

Job description

Kaizen Approach is currently seeking an Information Systems Security Officer (ISSO) to provide support for a program, organization, system, or enclave’s information assurance program. In this role, the ISSO will support proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies while maintaining the operational security posture of information systems or programs. The position involves assisting with management of security aspects of information systems, performing day-to-day security operations, evaluating security solutions for processing classified information, and conducting vulnerability and risk assessment activities to support security authorization. The ISSO will provide configuration management for information systems security software, hardware, and firmware, manage system changes, and assess the security impact of those changes. This role also includes preparing and reviewing security documentation such as System Security Plans, Risk Assessment Reports, Certification and Accreditation packages, and System Requirements Traceability Matrices, and supporting security authorization activities in compliance with the NIST Risk Management Framework.

Requirements

  • Must have the ability to support a program, organization, system, or enclave’s information assurance program by supporting senior Information Systems Security Officers and the Information System Security Manager in implementing, proposing, coordinating, enforcing, and ensuring compliance with information systems security policies, standards, and methodologies, while maintaining the appropriate operational Cybersecurity posture.

  • Must possess the ability to assist with and perform the management of security aspects of information systems, including performing day-to-day security operations, maintaining the operational security posture of systems or programs, and obtaining system authorization for information systems under assigned purview.

  • Must be capable of developing, maintaining, updating, and reviewing System Security Plans and other Cybersecurity documentation, including documentation required for security authorization in accordance with ODNI and DoD policies.

  • Must have the ability to evaluate and assist in the evaluation of security solutions to ensure they meet security requirements for processing classified information and to support security authorization activities.

  • Must possess the ability to provide configuration management for security-relevant information system software, hardware, and firmware, manage and control system changes, assess the security impact of those changes, and maintain records for workstations, servers, routers, firewalls, intelligent hubs, network switches, and system upgrades.

  • Must be capable of planning and coordinating the implementation of information technology security programs and policies, tracking and ensuring appropriate user identification and authentication mechanisms for information systems, and ensuring ongoing compliance with system security policy.

  • Must have the ability to provide daily oversight and direction to contractor Information Systems Security Officers and to interact with customers, information technology staff, and high-level corporate officers to define and achieve required Cybersecurity objectives.

  • Must have eight years of combined work-related experience in the fields of information technology, cybersecurity, or security authorization, or twelve years of combined work-related experience if no bachelor’s degree is held, including experience in at least two areas such as current security tools, hardware and software security implementation, communication protocols, or encryption tools and techniques, and familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services.

  • Must have a bachelor’s degree in Computer Science, Cyber Security, or IT Engineering, or four additional years of work-related experience may be substituted for the degree, and must be DoD 8570 compliant with IAM I.

  • Active TS/SCI clearance with Polygraph is required.

Salary Range: A variety of factors can impact the final salary offered, including, but not limited to, geographic location, Federal Government contract labor categories and wage rates, relevant work experience, specialized skills and competencies, education, and certifications.

Benefits & conditions

At Kaizen Approach, we truly care about our team, offering flexibility for a balanced life, competitive compensation, and a robust benefits package that supports you and your family. We prioritize well-being with premium healthcare, financial and family support, retirement planning, and ongoing learning. With 4 weeks of PTO, 11 holidays, gifted 401k, profit sharing, and paid training, we’re committed to your growth and happiness-both at work and beyond!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · WWC 2021

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · WWC Europe 2026

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all