Information System Security Officer (ISSO)

The JAAW Group
Hill Air Force Base, UT, United States
11 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Configuration Management Cyber Security Identity and Access Management Information Security Management Network Segmentation Security Information and Event Management Software Vulnerability Management SARS Software Products Cloud Platform System
+7 more
Information Technology Nessus CIS Benchmarks Splunk Scap Compliance Checker Docker Vulnerability Analysis

Job description

The JAAW Group LLC, a Service-Disabled Veteran-Owned Small Business (SDVOSB), is seeking an Information System Security Officer (ISSO) to support secure, mission-critical Department of Defense systems at Hill Air Force Base. This role is responsible for maintaining the cybersecurity posture and compliance of classified information systems while supporting Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG), and authorization activities.

The ISSO will work closely with the Information System Security Manager (ISSM), Security Engineers, system administrators, and other technical teams to implement security controls, conduct continuous monitoring, manage vulnerabilities, maintain cybersecurity documentation, and ensure systems remain compliant with applicable DoD security requirements.

Responsibilities

  • Support the implementation and maintenance of cybersecurity controls for classified information systems.
  • Assist the ISSM with RMF and JSIG accreditation and authorization activities.
  • Perform continuous monitoring, vulnerability assessments, risk analysis, and security compliance reviews.
  • Track vulnerabilities and remediation activities through Plans of Action and Milestones (POA&Ms).
  • Develop, maintain, and update cybersecurity documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and continuous monitoring documentation.
  • Support Authorization to Operate (ATO) activities and ongoing system authorization requirements.
  • Verify user security clearances, access authorizations, and need-to-know requirements.
  • Review audit records and system security events for potential cybersecurity concerns.
  • Support implementation and validation of DISA STIGs, CIS benchmarks, and other security configuration requirements.
  • Participate in configuration control and change management processes to evaluate cybersecurity impacts.
  • Coordinate vulnerability remediation activities with system administrators, engineers, and other technical teams.
  • Support cybersecurity incident reporting, documentation, and response activities.
  • Assist with security requirements for cloud environments, including encryption, identity and access management, and network segmentation.
  • Maintain accurate security records and documentation in support of audits, assessments, and authorization activities.

Requirements

  • Active Secret security clearance required prior to onboarding; Top Secret preferred.
  • U.S. citizenship required.
  • DoD 8570/8140 IAT Level II certification, or ability to obtain the required certification within 3 months of hire.
  • 3+ years of experience as an ISSO or in a comparable information assurance or cybersecurity compliance role.
  • Strong working knowledge of RMF and JSIG processes and requirements.
  • Experience supporting cybersecurity compliance, continuous monitoring, vulnerability management, and risk assessment activities.
  • Familiarity with DISA STIGs and security compliance tools such as SCAP Compliance Checker and Evaluate-STIG.
  • Experience with vulnerability assessment tools such as Nessus and ACAS.
  • Familiarity with SIEM platforms such as Splunk.
  • Experience supporting RMF documentation and authorization activities, including SSPs, POA&Ms, and ATO packages.
  • Familiarity with eMASS or similar cybersecurity compliance management systems.
  • Working knowledge of AWS and/or Microsoft Azure security concepts.
  • Strong written and verbal communication, organization, and documentation skills., * Active Top Secret security clearance with SCI eligibility.
  • 5+ years of ISSO, information assurance, or cybersecurity compliance experience.
  • DoD IAM Level II certification, such as CASP+ or CISSP.
  • Bachelor’s or Master’s degree in Cybersecurity, Information Assurance, Computer Science, or a related field.
  • AWS or Microsoft Azure security certifications.
  • Experience with Microsoft Defender, Trellix, or similar endpoint security technologies.
  • Experience supporting SOC or NOC operations.
  • Familiarity with container security technologies, including Docker and Kubernetes.
  • Experience supporting Department of Defense or other classified government environments.

Benefits & conditions

The JAAW Group offers a competitive benefits package designed to support our employees and their families, including:

  • Medical, dental, and vision insurance
  • 401(k) retirement plan with employer matching
  • Paid time off and paid sick leave
  • Paid holidays
  • Employer-paid life insurance
  • Employee Assistance Program (EAP)
  • Voluntary supplemental insurance options

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all