Information Systems Security Officer (ISSO) (Cyber Test Engineer - Mid LCAT)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
Ennoble First is seeking an Information Systems Security Officer (ISSO) to support the assessment, implementation, and sustainment of security controls for developmental and operational cybersecurity tools in a mission-critical environment. The ISSO evaluates security configurations, identifies risks, and provides actionable recommendations to ensure systems comply with federal security requirements and achieve and maintain Authorization to Operate (ATO). This role works closely with engineers, vendors, and government stakeholders to translate cybersecurity policy and risk into secure, operational solutions. Primary Responsibilities
- Assess and document security configurations for developmental and operational systems and tools
- Conduct tools assessments and configuration analysis against vendor guidance, best practices, and government security requirements
- Support implementation, oversight, and sustainment of security controls in accordance with RMF
- Apply and evaluate controls from NIST 800-53, FedRAMP, ICD 503, RMF, and DoD Information Levels
- Support system authorization activities including initial ATOs and ongoing continuous monitoring
- Perform risk analysis and document findings, recommendations, and mitigation strategies
- Coordinate with engineers, SMEs, subcontractors, and vendors to assess security impacts of system changes
- Develop and deliver security documentation, briefings, and artifacts to support stakeholder decision-making
Requirements
- 3+ years of experience as an Information System Security Officer (ISSO) or Information System Security Analyst (ISSA)
- Experience implementing and maintaining security controls for IT systems and cybersecurity tools
- Experience conducting configuration assessments and risk analysis
- Experience supporting RMF processes and security authorization activities
- Experience with eMASS or Xacta IA Manager
-
Active TS/SCI clearance; willingness to take a polygraph exam Education
- Associate’s degree and 5+ years of experience supporting IT projects and activities, or
- Bachelor’s degree and 3+ years of experience supporting IT projects and activities, or
-
Master’s degree and 1+ year of experience supporting IT projects and activities Certifications
- Active DoD 8570 Information Assurance Technician (IAT) Level II certification (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, CND, or SSCP)
-
Must obtain a DoD 8570 Cybersecurity Service Provider (CSSP) - Infrastructure Support certification (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND) prior to start date Desired Qualifications
- Experience with DoD STIGs, SCAP, ACAS, and configuration assessment tools
- Experience assessing security impacts of new COTS tools, upgrades, or configuration changes
- Experience drafting or reviewing CONOPS, system topologies, and vulnerability scan results
- Familiarity with tools such as Ansible, Terraform, Splunk, or STIG Viewer
- Knowledge of cloud-native security tools and Zero Trust concepts
- Strong written, verbal, and presentation skills
- Ability to work effectively in a fast-paced, collaborative environment
- AWS, Azure, or GCP certification, Access Authorization, Amazon Web Services (AWS), Ansible, Best Practices, CCNA - Cisco Certified Network Associate, Cloud Computing, Code of Federal Regulations, Commercial Off-the-Shelf (COTS), CompTIA Security+, Computer Network Defense (CND), Computer Security, Concept of Operations (CONOPS), Decision Support, Defense Intelligence, DoD Directive 8140, DoD Directive 8570, DoD Information Assurance - IA, Documentation, EEO Regulations, GCP (Good Clinical Practices), GSEC - GIAC Security Essentials Certification, Government, Government Requirements, Homeland Security, IAT - Information Assurance Technical, Information Technology & Information Systems, International Classification of Diseases (ICD), Internet Security, Microsoft Windows Azure, Operations Security (OPSEC), Presentation/Verbal Skills, Risk, Risk Analysis, SSCP - Systems Security Certified Practitioner, Security Analysis, Security Compliance, Sensitive Compartmented Information (SCI), Splunk, Systems Analysis, Team Player, Technical Support, Testing, Top Secret Clearance, Topology, Trademarks, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD), Vendor/Supplier Evaluation, Vulnerability Scanners, Writing Skills
Benefits & conditions
Salary range: $110,000 - $140,000 The Ennoble First pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered include responsibilities of the role, education, experience, knowledge, skills, internal equity, alignment with market data, applicable bargaining agreement (if any), or other law, with Ennoble First to boost your career. Ennoble First is a high-energy, technology-driven employer with people-centered values fostering continuous learning. We are a rapidly growing company. To support our expansion plans and achieve our growth objectives we are always seeking talented IT professionals. We believe an outstanding company to work for is an exceptional company to work with. By combining a great environment with great minds, we produce great results. Ennoble First promotes an all inclusive innovation friendly environment.
About the company
We are Ennoble First. The people supporting and securing some of the most complex government, defense, and intelligence projects across the country. We ensure today is safe and tomorrow is smarter. Our work has meaning and impact on the world around us, but also on us, and that’s important. Ennoble First is your place. You make it your own by embracing autonomy, seizing opportunity, and being trusted to deliver your best every day. We think. We act. We deliver.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Best Paying Jobs in Technology