ISSO
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a highly motivated Information System Security Officer (ISSO) to support and enhance the cybersecurity posture of Department of Defense (DoD) information systems. The ISSO will ensure compliance with the DoD Risk Management Framework (RMF) and NIST 800-37 security requirements. This role involves close collaboration with system owners, engineers, and cybersecurity professionals to implement, document, and maintain security controls in accordance with federal standards.
Work Environment & Clearance Requirements:
- May require access to classified information and familiarity with secure facility operations.
- Must hold a current DoD security clearance at the required level.
- Must be eligible for access to Special Access Programs (SAP), if needed.
WHAT YOU WILL DO:
- Serve as the ISSO for one or more Department of Defense (DoD) information systems.
- Develop, implement, and maintain RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms).
- Ensure systems are operated, maintained, and decommissioned in compliance with DoD cybersecurity policies and procedures.
- Conduct regular system security reviews and continuous monitoring activities.
- Participate in security incident response, reporting, and remediation efforts.
- Collaborate with Information System Owners (ISOs), Information System Security Managers (ISSMs), and Authorizing Officials (AOs) to achieve and maintain Authorization to Operate (ATO).
- Support internal and external audits, inspections, and cybersecurity assessments.
- Apply security updates and patches in accordance with Security Technical Implementation Guides (STIGs) and Information Assurance Vulnerability Management (IAVM) requirements.
- Utilize tools such as eMASS, ACAS, Nessus, and HBSS to support compliance, vulnerability management, and reporting
Requirements
- Clearance Level: Top Secret & Active Security+ Certificate
- Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field. A combination of equivalent experience and relevant cybersecurity certifications may be considered.
- Experience: Minimum of 3+ years of cybersecurity experience in a Department of Defense (DoD) or Federal environment.
- Frameworks & Standards: Strong knowledge of DoD 8510 Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, and experience using eMASS.
- Tools & Technologies: Familiarity with DISA STIGs, ACAS, Nessus, or Tenable.sc.
- Security Operations: Understanding of continuous monitoring processes and the vulnerability management lifecycle.
- Compliance & Authorization: Experience supporting Assessment & Authorization (A&A) packages and working with Authorizing Officials (AOs).
- Regulatory Knowledge: Knowledge of SCAP compliance, FISMA metrics, and federal cybersecurity reporting requirements
Certifications (DoD 8570/8140 Baseline Requirements Level I / II):
- Security+ CE (CompTIA)
- CGRC (ISC2 Certified Governance, Risk And Compliance)
- GSLC (GIAC Security Leadership Certification)
- CISM (Certified Information Security Manager)
- CISSP (Associate or Full)
- CASP+ (CompTIA) Note: Must maintain certification to remain compliant with DoD 8570.01-M / DoD 8140. Must satisfy one or more certification requirements
About the company
At HumanIT, we are fueled by honesty, integrity, and hard work. Our mission is to confront our clients’ most significant IT challenges head-on, providing superior solutions built on cutting-edge cybersecurity standards, advanced technology concepts, and modern business practices. By doing so, we enable our clients to focus on their core applications and services that drive their business forward. At HumanIT, we recognize and value your skills, experience, and education. Let your new adventure begin today!
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Overflow: Security and Privacy
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.