Information System Security Officer (ISSO) II

Amatriot Group, LLC
Albuquerque, NM, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$109,500.0 - $110,000.0
Working hours
Regular working hours
Job source

Tech stack

Audit Trail Configuration Management Cyber Security Information Systems Firmware Information Security Management SAP (Applications) Information Technology

Job description

The Information System Security Officer (ISSO) II is responsible for maintaining the operational security posture of assigned information systems through close collaboration with the Information System Security Manager (ISSM) and Information Security Officer (ISO). This role supports day-to-day cybersecurity operations for Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) environments, including assessment and authorization activities for Department of Defense (DoD) agencies., Information System Security

  • Maintain the operational security posture of assigned information systems.
  • Manage the day-to-day security operations of assigned systems.
  • Support physical and environmental protection, personnel security, incident handling, and security training and awareness.
  • Monitor assigned information systems and their operating environments.
  • Assess the security impact of system changes and provide recommendations to the ISSM.
  • Conduct continuous monitoring activities for assigned authorization boundaries.
  • Prepare reports on the status of security safeguards applied to computer systems.
  • Perform ISSO duties in support of internal and external customers.

Authorization and Compliance

  • Assist the ISSM in fulfilling assigned duties and responsibilities.
  • Prepare, review, and update authorization packages.
  • Develop and update authorization documentation.
  • Ensure compliance with approved security authorization packages through periodic system reviews.
  • Assist Department of Defense, national agency, and contractor organizations with assessment and authorization (A&A) efforts.
  • Execute the cybersecurity portion of self-inspections, including security coordination and review of system assessment plans.

Configuration and Change Management

  • Implement configuration management across authorization boundaries.
  • Coordinate hardware, software, and firmware changes with the ISSM and AO/DAO prior to implementation.
  • Notify the ISSM of changes that may affect the authorization determination of information systems., * Ensure approved procedures are followed for clearing, sanitizing, and destroying hardware and media.
  • Monitor system recovery processes to verify security features and procedures are properly restored and functioning.
  • Ensure information system security documentation is current and accessible to authorized personnel.
  • Ensure audit records are collected, reviewed, documented, and anomalies are identified.
  • Identify cybersecurity vulnerabilities and assist with implementing countermeasures.
  • Attend required technical and security training related to assigned duties.

Requirements

  • Bachelor’s degree and two (2) years of relevant experience [Required]; or
  • Associate degree and four (4) years of relevant experience [Required]; or
  • Six (6) years of relevant experience in lieu of a degree [Required]., * Two (2) to five (5) years of related experience, particularly developing RMF packages or bodies of evidence [Required].
  • Prior experience as a System Administrator, Network Administrator, or Information System Security Officer (ISSO) [Required].
  • Special Access Program (SAP) experience [Required]., * Active TS/SCI clearance [Required].
  • Must be willing to obtain a CI Polygraph [Required]

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all