Information System Security Officer, (ISSO)

Cinteot Inc.
Fort Meade, MD, United States
17 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Systems Engineering Configuration Management CompTIA Security+ Cyber Security Information Systems Information Security Management Information Systems Security Architecture Professional Software Vulnerability Management SARS Software Products Information Technology Vulnerability Analysis

Job description

The Information System Security Officer (ISSO) provides senior-level cybersecurity engineering and compliance support to the Defense Information Systems Agency (DISA) Internet Enterprise (IE) under the CTAS Task Order. This role is responsible for ensuring mission systems achieve and sustain Authorization to Operate (ATO) through implementation of the Risk Management Framework (RMF) and transition from legacy DIACAP requirements. The ISSO - Level 3 acts as both a technical and compliance leader, bridging vulnerability management, STIG/SRG application, and documentation development to create complete and accurate accreditation packages. This position serves as a senior-level resource, providing mentorship to mid-level and junior ISSOs, while interfacing with Government stakeholders, Information System Security Managers (ISSMs), and Authorizing Officials (AOs)., The ISSO is expected to perform duties that span both hands-on technical tasks and high-level compliance oversight. Core responsibilities include:

  • Leading the development, maintenance, and validation of RMF and A&A artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), configuration management records, and testing documentation.
  • Implementing and validating compliance with DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to maintain technical baselines across supported systems.
  • Managing and analyzing results from vulnerability scanning and compliance tools such as ACAS, HBSS, and CMRS, and ensuring timely remediation of findings in accordance with IAVM directives.
  • Preparing and submitting comprehensive accreditation packages in eMASS, ensuring accuracy, completeness, and timeliness of submissions to meet contract and PWS requirements.
  • Conducting and documenting Security Test and Evaluation (ST&E) activities, ensuring objective assessment of control implementation and risk posture.
  • Supporting and preparing for Command Cyber Readiness Inspections (CCRI), Security Assessment Visits (SAV), and Cooperative Vulnerability Penetration Assessments (CVPA) by creating corrective action plans, briefing results, and tracking closure of findings.
  • Providing mentorship and guidance to junior ISSOs, ensuring proper interpretation of DoD cybersecurity policy and consistent application of standards across the team.
  • Contributing to recurring deliverables such as Policy Compliance Reports, Risk Assessment Reports, and Directorate-level cybersecurity briefings, ensuring all outputs meet QASP Acceptable Quality Levels (AQLs)., Information Systems Security Officer The Opportunity: Join a team of communications and systems engineers supporting engineering, sustainment, and management of communications …
  • 7 days ago +

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, or related field.
  • Must hold and maintain an appropriate DoD 8140.03 / 8570.01-M certification baseline for this labor category (e.g., Security+, CISSP, CISM, or equivalent as required).
  • At least 7 years of experience in cybersecurity engineering, RMF/DIACAP accreditation, and compliance documentation in DoD environments.
  • Expertise in the application of DISA STIGs/SRGs, ACAS/HBSS vulnerability analysis, and eMASS package preparation.
  • Strong written and verbal communication skills, with demonstrated experience producing accreditation documentation and presenting risk findings to senior stakeholders.

Desired Qualifications:

  • Master’s degree in Cybersecurity or related discipline.
  • Experience supporting DISA programs and preparing for CCRI inspections.
  • Advanced certifications such as CISSP-ISSAP or CISM.

Clearance Requirement: Active Top Secret

Benefits & conditions

  • Complete Insurance Coverage
  • Blue Cross Medical, Delta Dental, Vision, Life
  • 401k with Company Contribution
  • Tuition Reimbursement
  • Generous Paid Time Off (including your birthday!)

Cinteot is an Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

About the company

Cinteot Inc. is a small IT services company that specializes in cybersecurity, Big Data/databases, software development, systems testing, STIG Compliance training, closed-circuit television/security cameras and access controls, and construction/facilities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:08 min

Introduction to speakers and model-based systems engineering goals

Daniel Siegl +1 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

5:05 min

Bridging the gap to production systems engineering

Luca Palmieri · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all