Information System Security Officer (ISSO)

ASEC, Inc.

$115K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems Management, Engineering, or related field preferred; 10 years of ISSO experience without a degree accepted.
  • At least 5 years of experience in Information Assurance/Cybersecurity (IA/CS).
  • Experience with Risk Management Framework (RMF) DODI 8510.01.
  • Knowledge of security controls and implementation standards (CNSSI 1253, NIST 800-53, JSIG).
  • Proficient in conducting vulnerability assessments using ACAS, DISA STIGs, and SCAP Compliance Checker.
  • Familiarity with identifying Common Criteria/NIAP technologies and DISA APL.
  • Understanding of IC Directive 705, DoD 5205.07 policies, and Special Access Program regulations.

Responsibilities

  • Propose, coordinate, and enforce information system security policies and standards.
  • Conduct vulnerability assessments using automated tools and benchmarks.
  • Utilize SolarWinds or Splunk for system monitoring and security event analysis.
  • Implement security configurations for operating systems and network devices in line with DISA STIGs.
  • Perform continuous monitoring and develop mitigation strategies for security controls.
  • Identify certified technologies and prepare certification letters with system owners.
  • Support cross-functional cybersecurity efforts and ensure alignment with program goals.

Benefits

  • Health, dental, and vision insurance.
  • 401(k) retirement plan with company matching.
  • Professional development and training opportunities.
  • Paid time off and holidays.
  • Flexible working hours may be required.
Full Job Description
Location:NAS Lemoore, CA

Security Clearance Requirement: Top Secret

Telework Eligible? No - 100% On-Site

What You'll Do:

As an Information System Security Officer (ISSO), you will play a key role in supporting a high-visibility DoD program. In this role, you'll help shape and enforce the information system security policies, standards, and methodologies that keep our mission-critical systems protected. Are you ready to make an impact?

As the ISSO, you will provide mission-critical support by:
  • Proposing, coordinating, implementing, and enforcing information system security policies, standards and methodologies.
  • Conducting vulnerability assessments using automated benchmarks and tools such as Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs), and Security Content Automation Protocol (SCAP) Compliance Checker.
  • Utilizing SolarWinds or Splunk to perform advanced system monitoring, security event analysis, and continuous compliance activities.
  • Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides (STIGs).
  • Performing security control continuous monitoring, reviewing system security plans and associated artifacts, security audits, risk analysis and developing mitigation strategies for DoD information systems.
  • Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL).
  • Preparing certification letters and Memoranda of Agreement (MoA) with system owners for interface and networking implementations.
  • Providing guidance of cross-functional cybersecurity efforts ensuring alignment with organizational and program goals and milestones.
  • Collaborating on documentation for Information System Authority to Operate (ATO) decisions, including SSPs, SOPs, POA&Ms, and Knowledge Articles.
  • Conducting comprehensive risk assessments and vulnerability analyses to identify and mitigate potential threats to satellite communication infrastructures.
  • Position may require flexibility in working hours.

This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.

Requirements

What You'll Bring:
  • Bachelor's in Computer Science, Information Systems Management, Engineering, or a related, technical area of study preferred. Without a bachelor's degree, 10 years of experience as an ISSO will be required.

At least 5 years of experience in the following areas is required:
  • Information Assurance/Cybersecurity (IA/CS).
  • Risk Management Framework (RMF) DODI 8510.01.
  • Security controls and implementation delineated in Committee of National Security Systems Instruction (CNSSI) 1253 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and the Joint Special Access Program Implementation Guide (JSIG).
  • Performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), the Security Content Automation Protocol (SCAP) Compliance Checker, incorporating automated Benchmarks.
  • Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides.
  • Performing security control continuous monitoring, security audits, risk analysis and developing mitigation strategies for DoD information systems.
  • Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL).
  • Knowledge of the Intelligence Community Directive (ICD) 705, DoD 5205.07, and DOD 5205.07-M Volumes 1-4, Special Access Program (SAP) Policy, and the Joint Special Access Program Implementation Guide (JSIG).

Equally Important:
  • Ability to build positive, collaborative relationships across teams and with external partners.
  • Effective communicator with strong verbal and written skills.
  • Proactive, self-directed work style with the ability to operate independently.
  • Analytical thinker with proven problem-solving capabilities.
  • Highly organized, with the ability to balance competing priorities in a fast-paced environment.

Certification Requirements:
  • CompTIA Security + is required. The following certifications are highly desired: CISSP, SecurityX (formerly CASP+), CAP, CISM, or GSLC. Please upload copies of any relevant IT certifications you hold.

Security Clearance Requirement:
  • This position requires U.S. citizenship and an active DoD Top Secret clearance with SCI eligibility. Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

Salary Range:
  • The anticipated annual salary range for this position is $115,000 - $150,000, commensurate with an individual's experience, qualifications, and skill set. ASEC is committed to providing fair and equitable compensation. The low end of this salary range is accounting for a candidate that meets or exceeds all of the listed requirements.


Not the right opportunity for you? Send this job posting to a friend!

Similar Jobs

More Jobs at ASEC, Inc.

More Information Technology Jobs

Find similar Information System Security Officer (ISSO) jobs: