Information Assurance III Information System Security Officer (ISSO)

DLS Engineering

$106K — $109K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience with DoD cybersecurity policies and implementation of Risk Management Framework (RMF)
  • Prior experience as an ISSO or ISSM supporting classified programs
  • Experienced in assessing and documenting compliance through test or analysis
  • 3+ years using RMF security tools like NESSUS and DISA STIGs
  • IAM-II Certification required
  • Certified in governance, risk, and compliance (CGRC)
  • Must be a US citizen
  • Must hold a current Top Secret clearance with SCI Access or an active Secret clearance

Responsibilities

  • Conduct security analysis of environments to assess compliance with standards
  • Implement Assessment and Authorization (A&A) processes under RMF
  • Facilitate development of security agreements and risk acceptance documentation
  • Develop and monitor Information System Continuous Monitoring (ISCM) strategy
  • Conduct assessments to document compliance and recommend risk mitigations
  • Supervise deployment of information security for program systems
  • Manage team efforts in executing RMF and coordinate security assessments

Benefits

  • Comprehensive health, vision, dental, life, and disability insurance
  • 401k program with company match
  • Generous paid time off package
Full Job Description
Position overview:

DLS Engineering is seeking an Information Assurance III Information System Security Officer (ISSO) professional for a full-time position in support of the Air Force Intranet Control (AFINC) program at Gunter Annex in Montgomery, Alabama. This is an on-site position.

As part of AFINC, the mission of the 26th Network Operations Squadron (26 NOS) is to provide mission assurance to the warfighter through the operation, management, and defense of the Department of Defense Information Network (DODIN). In the execution of its mission, the 26 NOS maintains network infrastructure, to include routers, switches, proxies, firewalls, servers, workstations, printers, Storage Area Networks (SAN) and test labs, to provide maneuverability and defense of both classified and unclassified networks.

A day in the life:

  • Performs security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards.
  • Implements the Assessment and Authorization (A&A) processes under the Risk Managed Framework (RMF) for new and existing information systems.
  • Facilitates development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA) and Risk Acceptance Letters.
  • Develop an Information System Continuous Monitoring (ISCM) strategy and monitor any proposed or actual changes to the system and its environment to maintain compliance. Audit systems to ensure security posture integrity.
  • Conduct assessments and test/analysis data to document state of compliance with security requirements. Conduct risk assessments and investigations, recommend implementation of risk mitigations, and coordinate incident response activities. Conduct periodic hardware/software inventory assessments.
  • Supervise the development and deployment of program information security for all program systems to meet the program and enterprise requirements, policies, standards, guidelines and procedures.
  • Manages assigned team to facilitate effective execution of Risk Management Framework (RMF). Coordinate and participate in security assessments and audits. Prepares, reviews, and presents technical reports and briefings.

When I read the below it sounds like me:

  • 5+ years of experience with DoD cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. NIST SP 800 series, CNSSI 1253.
  • Prior experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs.
  • Experience in assessing and documenting test or analysis data to show cybersecurity compliance.
  • 3+ years of experience in utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include: NESSUS, ACAS, DISA STIGs, Audit Tools, ESS, eMASS, PPS.
  • IAM-II Certification: CISM, CISSO, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GCSA, GICSP, or GSLC
  • Must be certified in governance, risk, and compliance (CGRC)
  • Must be a US citizen
  • Must hold a current Top Secret clearance with SCI Access (TS/SCI) or an active Secret clearance.

Other information:

  • We offer a competitive salary and a 401k program with company match.
  • We offer a comprehensive benefits package including health, vision, dental, life, and disability insurance.
  • We offer a generous paid time off package


The pay range for this role is:

106,000 - 109,000 USD per year (Montgomery, AL)

Similar Jobs

More Jobs at DLS Engineering

More Aerospace & Defense Jobs

Find similar Information Assurance III Information System Security Officer (ISSO) jobs: