About the RoleApex is looking for an Information Systems Security Officer (ISSO) to keep assigned systems secure, documented, and ready for customer or third-party review. You will work with system owners, IT, engineering, the SOC, and the Cybersecurity Lead to make sure security requirements are implemented in the environment and supported by evidence that holds up under review.
The primary focus is NIST SP 800-171 and CMMC Level 2. This role will also support ATO activities, SOC 2 Type II, ISO-aligned compliance work, and other customer security requirements as Apex grows.
Responsibilities
- Serve as the security point of contact for operations and keep teams informed on the current cyber posture.
- Work with the Cybersecurity team to assess requirements, risk findings, and due dates for contracts.
- Maintain the SSP, system inventory, policies, procedures, and supporting evidence for our CUI environment.
- Track NIST SP 800-171 and CMMC Level 2 implementation at the specific artifact level.
- Support ATO and RMF activities including creating and updating security documentation and writing POA&Ms with target completion dates.
- Validate evidence from our cybersecurity suite including CrowdStrike, Palo Alto, Tenable, and Jira.
- Lead vulnerability and configuration remediation with system owners; make sure ownership, expectations, and target dates are clear.
- Lead security reviews on privileged accounts, terminated users, vulnerability results, and other security requests from the program.
Requirements
- Active TS/SCI clearance required
- US Citizenship required
- 3 or more years of experience as an ISSO, security compliance analyst, security engineer, system administrator with security responsibilities, or a similar role
- Strong working knowledge of NIST SP 800-171, CMMC Level 2, POA&M management, control evidence, and assessment preparation
- Experience maintaining an SSP or equivalent system security documentation and supporting formal security reviews
- Ability to understand and validate evidence from identity, cloud, endpoint, network, vulnerability, and logging platforms
- Strong follow-through across multiple teams and the ability to write security documentation that clearly reflects what is actually implemented
Preferred Qualifications
- Experience with ATO, RMF, NIST SP 800-53, SOC 2 Type II, ISO 27001, DFARS [redacted], SPRS, STIGs, or classified system security
- Experience with Microsoft GCC High, CrowdStrike, Palo Alto, Tenable, AWS GovCloud, Entra ID, or similar enterprise security platforms
- Security+, CGRC, CISSP, or a comparable security certification
-Experience supporting aerospace, defense, national security, ATO, RMF, or other regulated technical environments
What We Offer For Full-time Employees:- Shared upside: Receive equity in Apex, letting you benefit from the work you create
- Best-in-class healthcare: 100% company-paid medical, dental, and vision for you and your dependents, plus $100k life insurance at no cost
- Comprehensive PTO package to reset and recharge - starting at 15 days vacation, growing to 20+ days annually, plus 10 paid holidays
- Competitive 401(k) plan with generous matching - 100% match on first 3%, 50% on next 2%
- 8 weeks paid parental leave plus childcare reimbursement up to $350/day for work-related travel
- Daily catered lunch and unlimited snacks to keep you fueled throughout the day
- Vibrant community: Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family
- Your dream desk setup and all the tools you need to be your most productive self
- World-class Playa Vista office with the benefit of in-person collaboration with amazing coworkers and flexibility to integrate work and life
- Real impact opportunity: Work alongside experts from aerospace, new space, and other cutting-edge industries to make a lasting difference
Ready to join a team where your contributions matter and your future is bright? Let's build something extraordinary together.