Information Systems Security Officer (ISSO) Mid-Level
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
RMF / ATO Support
- Execute and document all RMF activities across the full lifecycle in accordance with DoDI 8510.01, NIST SP 80053, CNSSI 1253, JSIG/ICD 503, and customer specific guidance.
- Develop and maintain RMF artifacts including the SSP, SAP/SAR, POA&Ms, Contingency Plans, IR Plans, and related IA documentation.
- Support ATO package preparation and submission using government customer RMF/IA tools for evidence upload, workflow tracking, and assessor interactions.
- Implement, assess, and validate security controls; support control tailoring and inheritance strategies.
Continuous Monitoring & Compliance
- Perform continuous monitoring using government approved compliance scanning tools:
- Vulnerability scanning tools
- STIG/SRG-based configuration validation
- Automated compliance assessments
- Maintain system baselines, secure configurations, asset inventories, and IA-related change documentation.
- Support audit readiness and assist with customer inspections, CCRI-type events, and periodic cybersecurity evaluations.
- Track, manage, and drive closure of POA&Ms and risk items.
Secure Operations & Incident Response
- Provide day-to-day IA support for classified systems, including boundary analysis, system configuration reviews, and data handling oversight.
- Support event detection and response activities using government customer log aggregation tools, ensuring accurate log capture, retention, and reporting.
- Participate in incident response coordination with Contractor Program Security Officer (CPSO) in accordance with customer and organizational procedures.
- Guide engineering and operations teams on secure design principles, system changes, and cybersecurity impacts.
Governance, Risk & Compliance
- Maintain risk tracking, document deviations and mitigations, and communicate system risk posture to IA leadership and stakeholders.
- Support policy compliance, user training, secure handling, insider threat awareness, and governance activities.
- Coordinate with AOs, SCAs, customer cybersecurity offices, and program security personnel.
Requirements
Minimum of 4 years of related work experience, * Active TS/SCI with CI Poly and ability to maintain eligibility. U.S. Citizenship required
- Bachelor’s degree in Cybersecurity, Computer Science, or related field; equivalent experience considered
- Four years of directly related exempt work experience may be used to satisfy the bachelor’s degree requirement
- 4+ years of IA/cybersecurity experience with 3+ years directly supporting RMF/ATO for DoD/IC systems
- Current DoD 8570/8140 Tier II certification or higher
- Hands-on experience with NIST SP 800-53, DoDI 8510.01, CNSSI 1253, JSIG/ICD 503, and STIG/SRG application
- Proficiency in vulnerability and compliance tools: Tenable Nessus, SCAP, DISA STIG Viewer, log/monitoring, and familiarity with patch management
- Experience developing and maintaining SSP, SAR/SAP, POA&M, and RMF evidence; strong technical writing skills
- Knowledge of network security, Windows/Linux hardening, virtualization, endpoint protection, identity & access management, encryption/key management, and secure configuration baselines
Preferred Qualifications
- Additional cybersecurity certifications (CAP, CEH, GSEC, GSLC)
- Experience supporting Defense and Intelligence Community programs
- Familiarity with secure cloud and hybrid environments (e.g., DoD Cloud SRG, IL2-IL6, GovCloud, IC ITE)
- Prior involvement in customer-led cybersecurity inspections or assessments
Benefits & conditions
We offer our employees competitive pay and benefits including:
- 401(k) match plus an additional employer contribution
- Discretionary annual incentive bonus for eligible employees
- Generous paid time off
- Flexible work environments
Additionally, most salaried ULA team members work a “9/80 schedule,” meaning they enjoy every other Friday off.
Benefits and work schedules may vary for union-represented hourly positions and are described in the applicable collective bargaining agreement.
About the company
ULA is a participant in the federal E-Verify Program. Posters in PDF format pertaining to this program can be accessed by clicking on the links identified below. E-Verify Participation poster (English / Spanish) and Right to Work Poster (English / Spanish).
Colorado Equal Pay for Equal Work Act requires covered employees to follow a post selection notification process. A hired candidate may opt out of this process by notifying the hiring manager in writing at the time the offer is accepted ULA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, national origin, disability, protected veteran status or any other categories protected by law.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…