Applied Research Associates Inc

Information System Security Officer (ISSO)

Applied Research Associates Inc$95K — $115K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 2-4 years in information technology, including 2 years in an ISSO role for classified systems.
  • Knowledgeable in 32 CFR Part 117, DCSA Guidelines, and NIST publications.
  • Experience managing RMF lifecycle for classified information systems.
  • Top Secret clearance required, with SCI eligibility preferable.
  • Strong understanding of security hardening for Windows/Linux systems.

Responsibilities

  • Support ISSM in managing and ensuring compliance of classified information systems.
  • Perform patch management, account management, and hardware troubleshooting.
  • Ensure all system changes follow approved change management processes.
  • Implement and validate security controls per compliance frameworks.
  • Analyze user activity monitoring data and audit records.
  • Report security incidents to the ISSM promptly.
  • Assist in executing all phases of the RMF lifecycle.

Benefits

  • Continuous opportunities for professional development.
  • Collaborative working environment with a focus on cybersecurity best practices.
  • Engagement with a team driven by integrity in handling sensitive information.
Full Job Description
Applied Research Associates, Inc. (ARA), Southwest Division (SWD) is looking for an experienced Information System Security Officer (ISSO) to join our security team located in Albuquerque, New Mexico. The Information System Security Officer (ISSO) supports the ISSM in the management, operation, and compliance of classified information systems (IS) operating under the National Industrial Security Program (NISP). This role is governed by the requirements of 32 CFR Part 117 (NISPOM Rule) and the DCSA Assessment and Authorization Guide (DAAG), which implements the Risk Management Framework (RMF) for cleared contractor facilities. The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture of assigned systems, ensuring continuous compliance with DCSA authorization requirements and maintaining a valid Authority to Operate (ATO).

Essential Functions as an ISSO

  • Possessing sufficient experience and technical competence commensurate with the complexity of the systems to include patch management, account management, STIGs/SCAPs, application updates and installs, hardware configuration and troubleshooting
  • Ensure all hardware and software additions, removals, and modifications follow approved change management processes
  • Maintain configuration management documentation for all hardware and software changes to classified systems
  • Implement and validate security controls on classified systems per NIST SP 800-53, CNSSI 1253, and applicable STIGs.
  • Ensuring user activity monitoring data and audit records are analyzed, stored, and protected in accordance with the ITPSO policies and procedures and System Security Plan (SSP)
  • Review system audit record findings related to inappropriate or unusual activity and escalate findings to the ISSM
  • Report all security-related incidents to the ISSM in accordance with 32 CFR Part 117 requirements
  • Assess changes to assigned systems that could affect authorization status and notify the ISSM
  • Assist and support the ISSM in all the following tasks:
  • Executing all phases of the RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor to include decommission
  • Development, maintenance, and continuous updating of Information Systems
  • Populate and maintain system records, artifacts, and security documentation in eMASS throughout the RMF lifecycle
  • Preparation and submission of authorization packages through the Package Approval Chain (PAC) workflow
  • Conducting periodic assessments and continuous monitoring of authorized systems and providing the corrective actions for all identified findings and vulnerabilities
  • Development and tracking of Plans of Action and Milestones (POA&Ms) for identified vulnerabilities


Experience and Skills Required

  • Minimum 2-4 years of experience in information technology, with at least 2 years in an ISSO or equivalent role supporting classified information systems
  • Demonstrated working knowledge of 32 CFR Part 117 A7117.18, the DCSA Assessment and Authorization Guide (DAAG), and NIST 800-series publications
  • Experience managing the RMF lifecycle for classified information systems under DCSA cognizance
  • Active (or ability to obtain) Top Secret clearance with SCI eligibility or clearance commensurate with the highest classification level processed on facility systems
  • Strong technical knowledge of Windows and/or Linux security hardening, STIG application, network security fundamentals, and audit log management
  • Experience with classified system configuration management, media control, and sanitization/destruction procedures


Core Competencies

  • Technical understanding of classified system security controls, network architecture, and risk management
  • Knowledge of NISPOM and related CFRs, DAAG, NIST SPs, CNSSI directive
  • Analytical thinking, technical writing, and the ability to produce clear security documentation (SSPs, POA&Ms, incident reports)
  • Effective collaboration with the ISSM, FSO, ITPSO, IT staff, and program managers
  • Discretion and integrity in handling classified information and sensitive cybersecurity data
  • Commitment to continuous professional development and staying current with evolving cybersecurity threats and DCSA guidance


Preferred

  • Security+
  • Prior industry ISSO or cybersecurity assessor experience (DCSA, NSA, or IC)
  • Knowledge of cross-domain solutions, classified cloud environments (IL4/IL5), and network interconnection security
  • Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and STIG Viewer / SCAP compliance tool


About Applied Research Associates Inc

Applied Research Associates, Inc. (ARA) is an employee-owned research and engineering company that provides technical solutions to complex problems in various fields, including defense, homeland security, intelligence, transportation, and energy. The company was founded in 1979 and is headquartered in Albuquerque, NM. ARA has over 1,600 employees and operates from more than 20 locations across the United States and Canada. The company's services include research and development, engineering, testing and evaluation, and consulting.
Learn more about Applied Research Associates Inc
Size
1,600 employees
Industry
Founded
1979

Similar Jobs

More Jobs at Applied Research Associates Inc

More Aerospace & Defense Jobs

Find similar Information System Security Officer (ISSO) jobs: