Information Systems Security Officer (ISSO) Mid-Level

United Launch Alliance
Centennial, CO, United States
4 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$104,087.0 - $173,479.0
Working hours
Regular working hours

Tech stack

Multitier Architecture Microsoft Windows Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security System Configuration Linux Identity and Access Management Key Management Network Security SAP (Applications)
+8 more
Security Content Automation Protocol Virtualization Technology Data Processing Information Technology Tenable Nessus Patch Management Plan of Action and Milestones Vulnerability Analysis

Job description

RMF / ATO Support

  • Execute and document all RMF activities across the full lifecycle in accordance with DoDI 8510.01, NIST SP 80053, CNSSI 1253, JSIG/ICD 503, and customer specific guidance.
  • Develop and maintain RMF artifacts including the SSP, SAP/SAR, POA&Ms, Contingency Plans, IR Plans, and related IA documentation.
  • Support ATO package preparation and submission using government customer RMF/IA tools for evidence upload, workflow tracking, and assessor interactions.
  • Implement, assess, and validate security controls; support control tailoring and inheritance strategies.

Continuous Monitoring & Compliance

  • Perform continuous monitoring using government approved compliance scanning tools:
  • Vulnerability scanning tools
  • STIG/SRG-based configuration validation
  • Automated compliance assessments
  • Maintain system baselines, secure configurations, asset inventories, and IA-related change documentation.
  • Support audit readiness and assist with customer inspections, CCRI-type events, and periodic cybersecurity evaluations.
  • Track, manage, and drive closure of POA&Ms and risk items.

Secure Operations & Incident Response

  • Provide day-to-day IA support for classified systems, including boundary analysis, system configuration reviews, and data handling oversight.
  • Support event detection and response activities using government customer log aggregation tools, ensuring accurate log capture, retention, and reporting.
  • Participate in incident response coordination with Contractor Program Security Officer (CPSO) in accordance with customer and organizational procedures.
  • Guide engineering and operations teams on secure design principles, system changes, and cybersecurity impacts.

Governance, Risk & Compliance

  • Maintain risk tracking, document deviations and mitigations, and communicate system risk posture to IA leadership and stakeholders.
  • Support policy compliance, user training, secure handling, insider threat awareness, and governance activities.
  • Coordinate with AOs, SCAs, customer cybersecurity offices, and program security personnel.

Requirements

Minimum of 4 years of related work experience, * Active TS/SCI with CI Poly and ability to maintain eligibility. U.S. Citizenship required

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field; equivalent experience considered
  • Four years of directly related exempt work experience may be used to satisfy the bachelor’s degree requirement
  • 4+ years of IA/cybersecurity experience with 3+ years directly supporting RMF/ATO for DoD/IC systems
  • Current DoD 8570/8140 Tier II certification or higher
  • Hands-on experience with NIST SP 800-53, DoDI 8510.01, CNSSI 1253, JSIG/ICD 503, and STIG/SRG application
  • Proficiency in vulnerability and compliance tools: Tenable Nessus, SCAP, DISA STIG Viewer, log/monitoring, and familiarity with patch management
  • Experience developing and maintaining SSP, SAR/SAP, POA&M, and RMF evidence; strong technical writing skills
  • Knowledge of network security, Windows/Linux hardening, virtualization, endpoint protection, identity & access management, encryption/key management, and secure configuration baselines

Preferred Qualifications

  • Additional cybersecurity certifications (CAP, CEH, GSEC, GSLC)
  • Experience supporting Defense and Intelligence Community programs
  • Familiarity with secure cloud and hybrid environments (e.g., DoD Cloud SRG, IL2-IL6, GovCloud, IC ITE)
  • Prior involvement in customer-led cybersecurity inspections or assessments

Benefits & conditions

We offer our employees competitive pay and benefits including:

  • 401(k) match plus an additional employer contribution
  • Discretionary annual incentive bonus for eligible employees
  • Generous paid time off
  • Flexible work environments

Additionally, most salaried ULA team members work a “9/80 schedule,” meaning they enjoy every other Friday off.

Benefits and work schedules may vary for union-represented hourly positions and are described in the applicable collective bargaining agreement.

About the company

ULA is a participant in the federal E-Verify Program. Posters in PDF format pertaining to this program can be accessed by clicking on the links identified below. E-Verify Participation poster (English / Spanish) and Right to Work Poster (English / Spanish).

Colorado Equal Pay for Equal Work Act requires covered employees to follow a post selection notification process. A hired candidate may opt out of this process by notifying the hiring manager in writing at the time the offer is accepted ULA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, national origin, disability, protected veteran status or any other categories protected by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Loading talks and stories from around this role…