Information Systems Security Officer (ISSO)

Metron, Inc.
Reston, VA, United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Linux Desktop Environments Identity and Access Management Windows Servers Software Systems Software Vulnerability Management SAPBasis Information Technology National Industrial Security Program Operating Manual (NISPOM) Cisco
+1 more
Plan of Action and Milestones

Job description

Metron is seeking a capable Information Systems Security Officer (ISSO) to own the cybersecurity posture and authorization lifecycle of multiple classified and unclassified information systems. Working closely with the ISSM, CISO, system administrators, program leadership, and government customers, the ISSO manages day-to-day security operations, maintains authorization and accreditation documentation, and keeps systems compliant and mission ready.

This role suits a mid-level practitioner with a solid RMF foundation and hands-on classified system experience who is ready to take ownership of authorization packages with the support of an experienced ISSM and CISO. It is well suited to a strong system administrator or information assurance professional stepping into a dedicated ISSO role, and offers meaningful room to grow within an expanding classified program portfolio.

Core Responsibilities

  • Manage the Assessment and Authorization (A&A) lifecycle for assigned systems in accordance with RMF, JSIG, NIST SP 800-53, DISA STIG, and DoD/DCSA policy, under the direction of the ISSM, and maintain readiness for recurring assessments.
  • Develop and maintain SSPs, SCTMs, STIG packages, POA&Ms, risk assessments, and eMASS records, ensuring documentation reflects the current architecture and security posture.
  • Evaluate proposed system changes for cybersecurity, compliance, and authorization impact, and prepare systems for internal reviews, customer assessments, and inspections.
  • Execute and document continuous monitoring (ConMon) and vulnerability management across assigned classified enclaves, tracking findings through remediation and closure.
  • Review configuration, audit, access, and security-control evidence against applicable baselines and STIGs, and drive corrective actions under the POA&M process.
  • Administer user and privileged access based on role, need-to-know, and least privilege, and enforce requirements for removable media, data transfers, classified information handling, and secure equipment movement.
  • Support COMSEC accountability, incident investigation and reporting (policy violations, unauthorized access, data spills), and classified communications link operations including SIPRNet, in coordination with the ISSM.
  • Serve as the primary cybersecurity point of contact for assigned systems, coordinating with program managers, vendors, and government representatives including SCAs and AOs, and providing status on risk, compliance, and remediation.

Requirements

  • Active Top Secret clearance (with current SSBI or Tier 5 investigation).
  • Minimum of 3 years of experience in a cybersecurity, system administration, or information assurance role supporting classified systems under the DoD RMF, including hands-on administration of Windows server and desktop environments in classified domains.
  • Hands-on experience contributing to RMF authorization activities and artifacts, such as SSPs, SCTMs, POA&Ms, and eMASS records.
  • Active DoD 8140 IAM Level II certification or higher (CASP+ CE, CAP, CISM, or CISSP).
  • Working knowledge of NIST SP 800-53 security controls in classified system environments.
  • Experience performing continuous monitoring, vulnerability management, or cybersecurity hygiene activities across classified network enclaves., * Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Prior experience in a dedicated ISSO role, or independently managing or co-owning RMF authorization packages.
  • Experience supporting DCSA authorization processes and interfacing directly with SCAs or AOs in DCSA or DARPA contexts.
  • Experience managing multiple authorization packages or secure environments simultaneously, including SCI or SAP environments.
  • Experience with Linux operating systems; system hardening and STIG compliance experience.
  • Familiarity with NISPOM, DFARS 252.204-7012, and FISMA requirements; basic network administration (Cisco or equivalent).

Benefits & conditions

Perks and Benefits:

  • Medical, Dental and Vision Insurance
  • Accompanying FSA and HSA options
  • Additional Voluntary Benefits
  • Paid Time Off
  • 9 Observed Holidays and 2 Floating Holidays
  • Paid Parental Leave
  • Tuition Reimbursement
  • Professional Development Reimbursement
  • Annual Salary Reviews
  • Profit Sharing
  • 401(k) Traditional and Roth Options
  • Gym and Fitness Reimbursement
  • Employee Assistance Program
  • Employee Referral Program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Loading talks and stories from around this role…