Information System Security Officer-ISSO

Sigmatech, Inc.
Aberdeen Proving Ground, MD, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Systems Engineering Audit Trail Cyber Security Information Systems Monitoring of Systems Identity and Access Management Information Security Management Package Development Process Security Software Software Vulnerability Management Information Technology Vulnerability Analysis

Job description

Sigmatech, Inc. is seeking an experienced Information System Security Officer (ISSO) to provide cybersecurity, risk management, and compliance support to Army programs located at Aberdeen Proving Ground. The incumbent will support all phases of the Risk Management Framework (RMF) process, ensuring assigned information systems meet all Department of War (DoW) and Army cybersecurity requirements., The ISSO will perform the following major duties:

  • Serve as the primary cybersecurity subject matter expert for assigned systems.
  • Support system owners through all RMF steps, to include security categorization, control implementation, assessment, and authorization.
  • Develop, review, and maintain cybersecurity documentation, including System Security Plans (SSPs), Security Controls Traceability Matrices (SCTMs), Plans of Action and Milestones (POA&Ms), and Continuous Monitoring plans.
  • Conduct and document vulnerability assessments, risk evaluations, and compliance reviews.
  • Ensure application of DISA Security Technical Implementation Guides (STIGs) and DoD cybersecurity policies.
  • Manage system accounts, audit logs, incident reporting procedures, and privileged access in accordance with DoD requirements.
  • Utilize tools such as ACAS, HBSS, eMASS, and Army-specific cybersecurity platforms to support system monitoring and reporting.
  • Coordinate cybersecurity activities with system administrators, engineers, program managers, and external assessors.

Requirements

Do you have experience in Vulnerability management?, Do you have a Bachelor’s degree?, * U.S. citizenship.

  • Active DoD Secret clearance or higher and ability to maintain required security certifications.
  • Occasional travel may be required for program support or assessments.

  • Bachelor’s degree or equivalent in Computer Science, Information Systems Engineering or equivalent. Four (4) additional years of relevant experience or military experience substituted for education.
  • Minimum of five (5) years of experience in information systems security with extensive demonstrated proficiency in creating, reviewing, and updating eMASS packages including post accreditation/throughout the continuous monitoring stage.
  • IAM Level I or II certification meeting DoD 8570/8140 requirements (e.g., Security+ CE, CAP, CASP+, CISSP).
  • Demonstrated experience supporting RMF processes within a DoD, Army, or federal IT environment.
  • Knowledge of NIST Special Publications, DoD cybersecurity directives, and DISA STIGs.
  • Experience maintaining cybersecurity documentation and preparing systems for assessment and authorization.
  • Ability to analyze vulnerabilities, determine risk impacts, and recommend corrective actions.
  • Strong communication skills, both written and verbal, with the ability to interface with technical and non-technical personnel.

Preferred Experience

  • Direct experience supporting Army programs at Aberdeen Proving Ground.
  • Proficiency using eMASS for package development and updates.
  • Familiarity with secure configuration management, auditing practices, and cybersecurity tools such as ACAS and HBSS.
  • Background working in a program office or engineering environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all