> Markdown version of [/jobs/ext/284642-cloud-security-specialist-isso](https://www.wearedevelopers.com/jobs/ext/284642-cloud-security-specialist-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CLOUD SECURITY SPECIALIST/ISSO - **Company:** Quantum Research International, Inc. - **Location:** Huntsville, AL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, CompTIA Security+, Information Systems, ECMAScript, Information Security Management, Raw Data, Information Technology Security Auditing, Security Content Automation Protocol, Microsoft SharePoint, Information Security Management System, HybridCloud, Information Technology, Nessus, CIS Benchmarks, Vulnerability Analysis - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fb76f7592f494ad5 ## About the Role Do you have experience in Risk management?, Do you have a Bachelor's degree?, * Minimum of a Bachelor of Science (BS) degree in Computer Science, Information Systems or five (5) years of comparable work experience * 4 years of verifiable ISSO experience * Knowledge and practical experience of DoD 8510 and NIST 800-53 Risk Management Framework implementation * Candidate must be compliant with DoD 8140; DoD Cyber Workforce Framework (DCWF) Code 722, Information System Security Manager, at the intermediate level. Requires CompTIA Security+ CE or other training and education requirements as identified in DoDM 8140.03 * Fundamental knowledge of DISA Enterprise Mission Assurance Support Service (eMASS) * Security Clearance: Active Secret with the ability to obtain and maintain a Top Secret Desired Skills and Qualifications * Self-starter with the ability to independently identify, prioritize, and execute required tasks * ISC2 CISSP Certification * AWS/Azure experience ## Description Quantum Research is seeking an experienced Security Specialist / Information System Security Officer (ISSO) to support the an Army Program maintained within the Army's Enterprise Cloud Management Agency (ECMA). The mid-level ISSO will be responsible for maintaining the system's overall security posture IAW DoD RMF requirements. This role includes facilitating and participating in Configuration Control Board (CCB) meetings, evaluate proposed system and architecture changes to confirm security baselines are maintained through approved change management processes, and executing continuous monitoring activities such as reviewing system audits logs, general/privileged user account reviews, RMF documentation creation/maintenance, vulnerability response (CTOs/IAVAs), Information System Contingency Plan (ISCP) Table-Top exercises, and security control artifact development. The ISSO will maintain oversight of configuration management, security scanning and remediation activities, manage the Plan of Action and Milestones (POA&M), and provide cybersecurity guidance to infrastructure team members and on-site personnel to ensure compliance and risk reduction., * Develop and maintain ATO related documentation to include Configuration Management Plan (CMP), Account Management Plan (AMP), Information System Contingency Plan (ISCP), Incident Response Plan (IRP), Business Impact Analysis (BIA), Privacy Impact Analysis (PIA), System Security Plan (SSP), and Concept of Operations (CONOPS). * Identify the correct applicable Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) for technologies used within the Information System (IS). * Communicate and coordinate with the government System Owner (SO) and/or government ISSM to ensure the system operates within the conditions of the established ATO. * Advise the program on IS security requirements, ensuring alignment with RMF, applicable NIST Guidelines/Standards, and DISA STIG/SRG compliance. * Provide security design guidance and analysis to project stakeholders across all RMF phases to ensure alignment with security control requirements. * Oversee daily system security operations by monitoring control effectiveness, validating access controls, reviewing security audit logs, tracking vulnerabilities, responding to CTOs/IAVAs within government customer's SharePoint site, and coordinating remediation efforts to maintain an acceptable security posture. * Act as the Configuration Management (CM) facilitator and voting CCB member, overseeing change control processes and participating in formal decision-making for system modifications affecting security posture and compliance. * Prepare Security Impact Assessments (SIAs) for all System Change Requests (SCRs) to support Configuration Control Board (CCB) review and decision-making. * Perform annual account reviews and approve all general and privileged user account requests prior to creation, ensuring proper authorization, access justification, and compliance IAW approved policies and procedures. * Review technical security assessments, analyze vulnerabilities, and risk data using ACAS, Nessus, and SCAP scan results to identify system vulnerabilities, non-compliance, and appropriate mitigation strategies. * Coordinate and manage security incident response activities in accordance with established policies and procedures. * Serve as the IS primary POC when communicating with the Security Control Assessor (SCA). * Create and maintain Plan of Action and Milestone (POA&M) items within eMASS. ## Related Videos - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Extreme Rules Lawyering with the ECMAScript Specifications](https://www.wearedevelopers.com/videos/100116-extreme-rules-lawyering-with-the-ecmascript-specifications) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing Clarity to Event Streams: Enabling Analytics and AI Through Rich Metadata](https://www.wearedevelopers.com/videos/1616-bringing-clarity-to-event-streams-enabling-analytics-and-ai-through-rich-metadata) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Oh CommonJS! Why are you mESMing with me?](https://www.wearedevelopers.com/videos/1059-oh-commonjs-why-are-you-mesming-with-me) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)