Information System Security Officer III

ORBIS INC.
San Diego, CA, United States
3 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Microsoft Azure Bash Shell Configuration Management Cyber Security Information Systems Linux Identity and Access Management Information Security Management Information Technology Audit Python (Programming Language) Log Analysis
+14 more
McAfee VirusScan Windows PowerShell Systems Development Life Cycle Red Hat Enterprise Linux Security Information and Event Management Software Deployment Scripting Information Technology Nessus Operating System Security Splunk Scap Compliance Checker Plan of Action and Milestones Vulnerability Analysis

Job description

Position Overview ORBIS requires an Information System Security Officer III (ISSO III) to serve as a tactical cybersecurity expert supporting the NSWC Corona CCAM contract. Working under the direction of the ISSM, the ISSO III is responsible for the day-to-day implementation, monitoring, and maintenance of security controls across assigned information systems. This key personnel role is heavily involved in the technical aspects of the RMF lifecycle and continuous monitoring programs.

Operational Cybersecurity & RMF Responsibilities:

  • Execute daily, weekly, and monthly cybersecurity operations for assigned networks, enclaves, and Platform IT systems.
  • Coordinate directly with system engineers, developers, and administrators to ensure security configurations are applied during the system development lifecycle.
  • Conduct comprehensive vulnerability assessments utilizing the Assured Compliance Assessment Solution (ACAS/Nessus) and analyze the results to identify critical flaws.
  • Apply and verify Security Technical Implementation Guides (STIGs) using the SCAP Compliance Checker (SCC) and manual STIG Viewer reviews.
  • Develop, compile, and upload high-quality artifacts into eMASS to demonstrate the successful implementation of NIST 800-53 security controls.
  • Draft and update essential RMF documentation, including Information System Contingency Plans (ISCP), Incident Response Plans (IRP), and hardware/software inventories.
  • Assist the ISSM in creating, updating, and managing Plan of Action and Milestones (POA&M) entries, documenting steps taken to remediate identified vulnerabilities.
  • Perform daily reviews of system audit logs, Security Information and Event Management (SIEM) alerts, and firewall traffic to identify anomalous or malicious activity.
  • Enforce account management policies, ensuring that user access, privileged access, and administrative roles are granted according to the principle of least privilege.
  • Support cyber incident response activities, executing containment procedures, preserving evidence, and assisting in root-cause analysis.
  • Monitor systems for compliance with Information Assurance Vulnerability Alerts (IAVAs), ensuring patches and updates are tested and deployed within mandated timeframes.
  • Participate in Configuration Control Board (CCB) meetings to evaluate the security impact of proposed network changes, software installations, or hardware modifications.
  • Conduct physical security walk-throughs and environmental control checks for facilities housing classified or sensitive information systems.
  • Assist in the preparation and execution of formal command cyber inspections and assist the NQV during official validation events.

Requirements

  • Clearance: Must possess an active, TS/SCI and be a United States citizen.
  • Education: Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field. (Significant operational experience and advanced certifications may substitute for the degree).
  • Experience: A minimum of six (6) years of dedicated experience coordinating and implementing security changes, conducting vulnerability analysis, and managing continuous monitoring activities.
  • Technical Experience: Demonstrable hands-on experience utilizing ACAS (Tenable/Nessus), HBSS (Trellix/McAfee), Splunk (or similar SIEM), and STIG Viewer.
  • Certifications: Must possess and maintain a current DoD 8140/8570 IAM Level II certification (e.g., CAP, CASP+ CE, CISM, CISSP, GSLC, CCISO, or HCISPP).
  • Strong working knowledge of Windows and Linux/Red Hat operating system security configurations and Active Directory group policies.
  • Ability to work effectively in a fast-paced environment, balancing multiple RMF package deadlines and continuous monitoring requirements simultaneously., * Certifications in specific operating systems or security tools (e.g., Linux+, Microsoft Certified Azure Security Engineer, Splunk Core Certified Power User).
  • Prior experience serving as an ISSO for a Navy Research, Development, Test, and Evaluation (RDT&E) environment.
  • Direct experience writing custom scripts (PowerShell, Python, Bash) to automate security compliance checking and log analysis.

Benefits & conditions

ORBIS offers an excellent benefits package and a competitive salary in a professional atmosphere.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all