Information Systems Security Officer (ISSO)

PeopleTec Inc.
Huntsville, AL, United States
10 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Amazon Web Services Systems Engineering Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Information Systems DevOps Infrastructure as a Service (IaaS)
+15 more
Identity and Access Management Information Security Management Information Systems Security Architecture Professional Platform as a Service (PAAS) Cloud Services Zero Trust Network Access Software Vulnerability Management Cyber Threat Analysis Containerization Kubernetes Information Technology Devsecops Serverless Computing Docker Vulnerability Analysis

Job description

This is a Senior Information Systems Security Officer (ISSO) position responsible for overseeing risk management, security compliance, and cybersecurity operations for the cloud-based information systems supporting the Guam Defense System (GDS). This role serves as a key technical and compliance advisor, ensuring systems conform to the Risk Management Framework (RMF), National Institute of Standards and Technology (NIST) guidelines, and DoD Cloud Computing Security Requirements Guide (SRG) for Impact Level 6 (IL6) data., * Lead and coordinate Risk Management Framework (RMF) Steps 1-6 for GDS, ensuring successful Assessment & Authorization (A&A) cycles and securing/maintaining Authorities to Operate (ATOs).

  • Author and maintain comprehensive cybersecurity documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and boundary diagrams.
  • Design and execute continuous monitoring strategies for GDS cloud environments to capture, analyze, and report real-time compliance and threat vectors.
  • Perform regular vulnerability scans and configurations checks of cloud infrastructure, containerized environments, and serverless applications. Analyze results and collaborate with GDS cloud engineers to prioritize and execute remediation plans.
  • Deploy and utilize enterprise security tools to detect, investigate, and mitigate vulnerabilities and advanced persistent threats (APTs).
  • Support incident response teams during active security events. Lead post-incident forensic investigations, root-cause analyses, and the implementation of permanent remediation measures.
  • Provide expert security architecture recommendations to engineering and DevOps teams implementing DevSecOps pipelines, automated infrastructure-as-code (IaC) deployments, and Zero Trust architectures.
  • Track and report cybersecurity risks, system compliance drift, and mitigation progress directly to GDS program leadership and government Authorizing Officials (AOs).

Requirements

  • Minimum of nine (9) years of progressive experience in cybersecurity, information assurance, systems engineering, or related IT fields.
  • At least seven (7) years of direct experience serving as an ISSO or ISSM within a cleared DoD or Intelligence Community (IC) environment.
  • Minimum of three (3) years of hands-on experience securing and managing cloud-based systems (AWS, Azure, or GCP), specifically within federal, defense, or high-security hybrid/multicloud environments (IL5/IL6).
  • Proven experience implementing RMF (NIST SP 800-37, 800-53, 800-137) for tactical, strategic, or defense systems.
  • Mastery of RMF, NIST SP 800-series, CNSSI 1253, and DoD 8500-series instructions.
  • Strong understanding of cloud service models (IaaS, PaaS, SaaS), shared responsibility models, identity and access management (IAM), secure virtual networking, encryption standards (at rest and in transit), and container security (Kubernetes, Docker).
  • Proficiency with enterprise vulnerability management, log aggregation, and system assessment tools.
  • Familiarity with the operational environment of Integrated Air and Missile Defense (IAMD) systems, Joint All-Domain Command and Control (JADC2) initiatives, and cross-domain solution (CDS) implementation is highly preferred.
  • Exceptional written and verbal communication skills, with the ability to translate complex technical vulnerabilities into business/mission risk for senior military leaders.
  • Strong analytical, troubleshooting, and problem-solving skills in high-stakes, fast-paced environments.
  • Candidate must hold an active certification meeting the DoDM 8140.03 IAM Level III requirement:
  • CISSP (Certified Information Systems Security Professional)
  • GISP (Global Information Security Professional)
  • CASP+ (CompTIA Advanced Security Practitioner)
  • Or equivalent IAM Level III-approved certification.
  • Candidate must also hold at least one (1) active cloud security or cloud architecture certification from a major provider or recognized organization:
  • CCSP ((ISC)² Certified Cloud Security Professional)
  • AWS Certified Security - Specialty
  • AWS Certified Solutions Architect - Associate
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Google Professional Cloud Security Engineer
  • Ability to travel
  • Must be a U.S. Citizen
  • Active Secret security clearance is required at the time of hire, with the ability to obtain Top-Secret/SCI.

Education Requirements :

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related technical discipline is preferred. Master’s degree in a related technical or business field is highly desirable.

About the company

PeopleTec, Inc. is an employee-owned small business founded in Huntsville, AL that provides exceptional customer support by employing and retaining a highly skilled workforce.

Culture: The name “PeopleTec” was deliberately chosen to remind us of our core value system - our people. Our company’s foundation was built on placing our employees and customers first. With an award-winning atmosphere, we have matured into a company that boasts the best and brightest across multiple technical fields.

Career: At PeopleTec, we value your long-term goals. Whether it’s through our continuing-education opportunities, our robust training programs, or our “People First” benefits package, PeopleTec truly believes that our best investments are our people.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all