INFORMATION SYSTEM SECURITY OFFICER

CCS, LLC
Scott Air Force Base, IL, United States
17 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$65,000.0 - $76,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Information Security Management Software Engineering Software Vulnerability Management Information Technology

Job description

This role works directly with Department of Defense stakeholders, cybersecurity engineers, system administrators, software developers, enterprise architects, and program leadership to maintain the cybersecurity posture of assigned information systems. It is an opportunity to apply Risk Management Framework expertise to support mission-critical systems while ensuring compliance with Department of Defense cybersecurity requirements and continuous authorization objectives.

Work is primarily performed on-site at Scott Air Force Base, Illinois, supporting government and contractor teams in mission-focused environments., Client is seeking an Information System Security Officer (ISSO) to support Department of Defense information systems by managing cybersecurity authorization activities, maintaining Risk Management Framework compliance, and supporting continuous monitoring. This position serves as a key member of the cybersecurity team responsible for maintaining Authorization to Operate packages, developing security documentation, coordinating assessments, and ensuring compliance with Department of Defense cybersecurity policies and National Institute of Standards and Technology guidance., Develop, maintain, and update System Security Plans (SSPs) for assigned systems. Manage Plans of Action and Milestones (POA&Ms) from identification through remediation and closure. Compile, maintain, and submit Authorization to Operate (ATO) packages. Conduct continuous monitoring activities in accordance with the Risk Management Framework (RMF). Utilize Enterprise Mission Assurance Support Service (eMASS) for Governance, Risk, and Compliance workflow management. Coordinate with Information System Security Engineers (ISSEs), Security Operations personnel, and system owners to validate security controls. Develop Security Assessment Plans (SAPs) and support Security Assessment Report (SAR) activities. Draft supply chain risk management documentation. Support cybersecurity architecture and RMF planning activities. Participate in security reviews, audits, and inspections. Develop and maintain cybersecurity documentation and system artifacts. Support vulnerability remediation and compliance reporting. Ensure assigned systems comply with Department of Defense cybersecurity policies and National Institute of Standards and Technology Special Publication 800-53 Revision 5.

Requirements

Active Secret or Top Secret security clearance. Three to five years of Risk Management Framework and Authorization to Operate experience within Department of Defense or federal environments. Hands-on experience with Enterprise Mission Assurance Support Service (eMASS). Working knowledge of National Institute of Standards and Technology Special Publication 800-53 Revision 5 and Department of Defense Risk Management Framework processes. Demonstrated ability to independently author System Security Plans and manage Plans of Action and Milestones. Strong written, verbal, analytical, and problem-solving skills. Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Information Systems, Software Engineering, Data Science, or equivalent experience., Experience with Enterprise Mission Assurance Support Service Reporter (eMASSer) or similar automation tools. Exposure to cloud-hosted or hybrid authorization boundaries. Familiarity with the Department of Defense Risk Management Framework Knowledge Service. Certified Ethical Hacker (CEH) or equivalent Department of Defense 8140 certification. Experience supporting mission-critical Department of Defense systems.

About the company

CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States. we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County. We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:22 min

Understanding software engineering as more than just coding

Lilia Gargouri Lilia Gargouri · World Congress 2026 Europe

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all