Information System Security Officer (ISSO)

Amentum Services, Inc.
Sunnyvale, CA, United States
16 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$175,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Information Security Management Cloud Services Software Requirements Analysis Information Security Management System SARS Software Products Plan of Action and Milestones

Job description

  • Develop and maintain detailed and accurate System Security Plans (SSP), including security documentation for component and interface specifications, to support appropriate cybersecurity and privacy throughout the information systems’ life cycle
  • Assist the Information System Owner (ISO) and Information System Security Manager (ISSM) in ensuring that all components of the information system are appropriately updated and patched in accordance with Federal and NASA requirements
  • Support the Government with identifying and prioritizing essential system functions or sub-systems required to support essential capabilities or business functions for restoration or recovery after a system failure or during a system recovery event based on overall system requirements for continuity and availability
  • Provide technical guidance to address the adequacy and effectiveness of information security policies, procedures, and practices
  • Ensure that cybersecurity design and development activities are properly documented (providing a functional description of security implementation) and updated as necessary
  • Ensure Privacy Threshold Assessments (PTA) and Privacy Impact Assessments (PIA) are conducted as required
  • Review cyber intelligence threats reports, including but not limited to SOC MARs, SARs, and DHS/CISA Emergency Directives, in order to identify threats to the information system and develop mitigations
  • Provide subject matter expertise and recommendations as part of RMF process activities and development of related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials)
  • Evaluate cloud service providers’ security posture and develop associated recommendations for restrictions, conditions and control responsibility parsing
  • Write Plan of Action and Milestones (POA&M’s) and Risk Based Decisions (RBD’s) for the System Security Plan (SSP) controls within the NASA Risk Information Security Compliance System (RISCS) tool.
  • Ensure contingency plans and system controls are reviewed and tested in accordance with the Agency requirements.
  • Analyze system logs to identify potential issues and perform routine audits of systems and applications.
  • Ensure critical vulnerabilities that require immediate attention are remediated, as identified in the Security Operation Center (SOC) Mitigation Action Recommendation (MAR).
  • Ensure the installation of security/vulnerability patch updates, operating system level patches and upgrades to include new versions.
  • Provide IT security support to communication systems as needed and serve as a technical resource to Information System Security Officer(s) (ISSO) and other IT professionals
  • The contractor shall assist in the development and updating of the System Security Plan, Contingency Plan, Disaster Recovery Plans, Risk Assessment Report, annual review package, work instructions, policies, and procedural guides affecting the overall IT and security posture of the environment
  • Support the Assessment and Authorization (A&A) process by preparing associated documentation, building, and tracking Plan of Action and Milestones (POA&M), and monitoring A&A activities

Requirements

  • Must have an active Top Secret US Government Clearance, with the ability to obtain an SCI Clearance. Please note US Citizenship is required to maintain a Top Secret Clearance.
  • Bachelor of Science degree with 5 years of professional experience in cybersecurity design and development activities
  • Strong oral and written communication skills

Desired qualifications:

  • SCI clearance eligibility
  • Experience in NASA Security or served as an ISSO in other agencies.
  • Experience in NASA Risk Information Security Compliance System and Assessment and Authorization.
  • Experience with Cloud Services and classified networks.
  • Certification level to meet DoD 8140 IAT or DoD 8570 IAT Level II certification or higher.

Benefits & conditions

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

About the company

Amentum is a leading provider of engineering, scientific, and program management support services to some of the top agencies in the U.S. Government, including NASA, Defense Advanced Research Projects Agency (DARPA), the Department of Homeland Security and the Intelligence Community.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · World Congress 2026 Europe

Videos

See all

Related articles

See all