Information System Security Officer

ASEC Inc
Fallon, NV, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Information Systems Monitoring of Systems SAP (Applications) Security Content Automation Protocol Information Technology SolarWinds (Software) Splunk Vulnerability Analysis

Job description

As the ISSO, you will provide mission-critical support by:

  • Proposing, coordinating, implementing, and enforcing information system security policies, standards and methodologies.
  • Conducting vulnerability assessments using automated benchmarks and tools such as Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs), and Security Content Automation Protocol (SCAP) Compliance Checker.
  • Utilizing SolarWinds or Splunk to perform advanced system monitoring, security event analysis, and continuous compliance activities.
  • Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides (STIGs).
  • Performing security control continuous monitoring, reviewing system security plans and associated artifacts, security audits, risk analysis and developing mitigation strategies for DoD information systems.
  • Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL).
  • Preparing certification letters and Memoranda of Agreement (MoA) with system owners for interface and networking implementations.
  • Providing guidance of cross-functional cybersecurity efforts ensuring alignment with organizational and program goals and milestones.
  • Collaborating on documentation for Information System Authority to Operate (ATO) decisions, including SSPs, SOPs, POA&Ms, and Knowledge Articles.
  • Conducting comprehensive risk assessments and vulnerability analyses to identify and mitigate potential threats to satellite communication infrastructures.
  • Position may require flexibility in working hours.

This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary., * Security controls and implementation delineated in Committee of National Security Systems Instruction (CNSSI) 1253 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and the Joint Special Access Program Implementation Guide (JSIG).

  • Performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), the Security Content Automation Protocol (SCAP) Compliance Checker, incorporating automated Benchmarks.
  • Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides.
  • Performing security control continuous monitoring, security audits, risk analysis and developing mitigation strategies for DoD information systems.
  • Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL).
  • Knowledge of the Intelligence Community Directive (ICD) 705, DoD 5205.07, and DOD 5205.07-M Volumes 1-4, Special Access Program (SAP) Policy, and the Joint Special Access Program Implementation Guide (JSIG).

Requirements

What You’ll Bring:

  • Bachelor’s in Computer Science, Information Systems Management, Engineering, or a related, technical area of study preferred. Without a bachelor’s degree, 10 years of experience as an ISSO will be required.

At least 5 years of experience in the following areas is required, * Ability to build positive, collaborative relationships across teams and with external partners.

  • Effective communicator with strong verbal and written skills.
  • Proactive, self-directed work style with the ability to operate independently.
  • Analytical thinker with proven problem-solving capabilities.
  • Highly organized, with the ability to balance competing priorities in a fast-paced environment.

ASEC is committed to providing access and reasonable accommodation in its services, activities, programs, and employment opportunities in accordance with the Americans with Disabilities Act and other applicable laws.

Certification Requirements:

  • Candidates must hold a current IAM-II certification (e.g., CompTIA CASP+ CE, CISM, CISSP) as defined by DoD 8570.01-M. Please upload copies of any relevant IT certifications as part of your application. These documents help us verify qualifications during the initial screening process.

Security Clearance Requirement:

  • This position requires U.S. citizenship and an active DoD Top Secret clearance with SCI eligibility. Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

Benefits & conditions

  • 100% employee-owned company. Learn more about our Employee Stock Ownership Plan (ESOP) here !
  • Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
  • 401(k) with company match
  • Tuition assistance for undergraduate and graduate education
  • Veteran-friendly employer
  • Thriving employee culture

About the company

ASEC offers meaningful, mission-driven work within a culture that supports your professional and personal growth. We partner with our government customers to deliver innovative solutions across engineering, information technology, training, and logistics. Above all, we are committed to doing what’s right for the Warfighter-plain and simple. Explore what makes ASEC different by visiting our website.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

2:37 min

Developing customized native applications for automotive user interfaces

Stephan Schuster · WWC 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · WWC 2025

57 sec

Identifying the ideal web applications for HTMX usage

Frederik Pietzko Frederik Pietzko · WWC 2025

Videos

See all

Related articles

See all