Information Systems Security / Information System Security Officer (ISSO)

ASTRION, INC.
Columbia, MD, United States
13 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Word Microsoft Excel Audit Trail Automation of Tests Configuration Management Cyber Security Information Systems Information Security Management Internet Protocol Network Security Local Security Policy Microsoft PowerPoint
+2 more
Information Security Management System National Industrial Security Program Operating Manual (NISPOM)

Job description

Astrion has an exciting opportunity for an experiencedInformation Systems Security Officer (ISSO). The ISSO supports the ISSM by verifying implementation of required security controls, conducting continuous monitoring and self-inspections, tracking corrective actions, supporting user access and training requirements, and ensuring classified systems are operated in accordance with the approved SSP, NISPOM Rule, CSA guidance, and local security procedures; this position is located in Columbia Maryland., * Information System Security Officer - responsible for supporting the day-to-day security oversight of classified information systems and ensuring users, systems, and processes remain compliant with NISPOM Rule, DCSA/CSA guidance, approved security documentation, and local procedures.

  • Ensure compliance - with the approved System Security Plan (SSP), security policies, procedures, and system-specific requirements.
  • Support the ISSM - in maintaining the classified information system security program.
  • Coordinate and conduct system self-inspections and document results.
  • Track, validate, and report corrective actions to the ISSM
  • Support continuous monitoring activities, including review of audit logs, account activity, configuration changes, vulnerability status, and system security posture.
  • Assist with configuration management and identify security-relevant changes that may require ISSM review or reauthorization.
  • Ensure users receive required system security briefings, training, user agreements, and access authorizations before system access is granted.
  • Monitor user compliance with classified system rules, including password/authentication protection, need-to-know, media handling, removable media restrictions, and reporting requirements.
  • Support incident response for data spills, suspected compromises, audit anomalies, unauthorized activity, or other reportable security concerns
  • Assist with maintaining authorization documentation, including SSPs, POA&Ms, risk assessments, security assessment results, contingency plans, configuration records, and authorization artifacts.
  • Coordinate with the ISSM, FSO/AFSO, Insider Threat Program, IT, program leadership, and Government security representatives as required.
  • Ensure classified systems are operated only within their approved authorization boundary, classification level, caveats, and accredited configuration

Requirements

  • Bachelor’s degree with 2-4 years of experience.
  • Experience in supporting U.S. Government clients.
  • Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment.
  • A CAP, CISM, CySA, or CISSP certification is required.
  • S. citizenship with active Top Secret eligibility and the ability to maintain such eligibility., * Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

3:58 min

Mitigating diverse browser quirks and unsupported clipboard metadata formats

Markus Over Markus Over

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

Videos

See all

Related articles

See all