Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Experteer Overview In this role you will support the ISSM across multiple environments to ensure information assurance and RMF compliance. You will drive secure authorization processes and continuous monitoring while collaborating with engineering teams and program managers. You’ll translate security requirements into actionable guidance and uphold least-privilege controls to protect critical systems. This onsite role offers TS/SCI-level access in a mission-focused setting with opportunities to influence security posture at scale. Compensation / Benefits * Assist the ISSM with information assurance efforts across environments * Perform ISSO responsibilities per JSIG and regulations * Lead RMF activities: control oversight, evidence collection, assessment support, POA&M management, continuous monitoring * Maintain security authorization artifacts (SSP, narratives, diagrams, control inheritance, CM plan, incident handling, contingency artifacts, procedures) * Operate continuous monitoring: vulnerability management, config compliance, patch coordination, scan triage, risk acceptance, remediation verification * Review and approve security-relevant changes via configuration/change control; validate security configs after major upgrades * Support incident response and reporting: investigations, containment actions, evidence preservation, lessons learned * Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, audit compliance * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, automatable) Tasks * Active Top Secret clearance with SCI eligibility * 5 years with BS/BA; 3 years with MS/MA (4 years additional relevant experience may be considered in lieu of BS) * Security+ or equivalent (DoD 8570 IAM Level II) * Experience with SAP assessments and authorizations * 3+ years experience with Authority to Operate (ATO) process, continuous monitoring, POA&Ms, Security Authorizations (SA), NIST 800-37/800-53 Rev4/Rev5; working with ISO and PM * Experience with SCAP, STIGs, and other compliance tools * Proven written and verbal communication skills; ability to work well with team members * Active TS clearance with ability to obtain SCI Key requirements * overtime * shift differential * discretionary bonus
Requirements
via vulnerability management, config compliance, patch coordination, scan triage, risk acceptance, remediation verification * Review and approve security-relevant changes via configuration/change control; validate security configs after major upgrades * Support incident response and reporting: investigations, containment actions, evidence preservation, lessons learned * Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, audit compliance * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, automatable) Tasks * Active Top Secret clearance with SCI eligibility * 5 years with BS/BA; 3 years with MS/MA (4 years additional relevant experience may be considered in lieu of BS) * Security+ or equivalent (DoD 8570 IAM Level II) * Experience with SAP assessments and authorizations * 3+ years experience with Authority to Operate (ATO) process, continuous aaa reviews, POA&Ms, Security Authorizations (SA), NIST 800-37/800-53 Rev4/Rev5; working with ISO and PM * Experience with SCAP, STIGs, and other compliance tools * Proven written and verbal communication skills; ability to work well with team members * Active TS clearance with ability to obtain SCI Key requirements * overtime * shift differential * discretionary bonus
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?