Information Systems Security Officer (ISSO) (Cyber Test Engineer - Mid LCAT)
Location: College Park, MD; Washington, DC; Reston, VA; Colorado Springs, CO; Norfolk, VA
Required Clearance: Active TS/SCI with polygraph eligibility
Employment Type: Full-Time Regular
Shift: Day
Travel: No
Relocation Assistance: Yes
Job Description
Ennoble First is seeking an Information Systems Security Officer (ISSO) to support the assessment, implementation, and sustainment of security controls for developmental and operational cybersecurity tools in a mission-critical environment. The ISSO evaluates security configurations, identifies risks, and provides actionable recommendations to ensure systems comply with federal security requirements and achieve and maintain Authorization to Operate (ATO). This role works closely with engineers, vendors, and government stakeholders to translate cybersecurity policy and risk into secure, operational solutions.
Primary Responsibilities
• Assess and document security configurations for developmental and operational systems and tools
• Conduct tools assessments and configuration analysis against vendor guidance, best practices, and government security requirements
• Support implementation, oversight, and sustainment of security controls in accordance with RMF
• Apply and evaluate controls from NIST 800-53, FedRAMP, ICD 503, RMF, and DoD Information Levels
• Support system authorization activities including initial ATOs and ongoing continuous monitoring
• Perform risk analysis and document findings, recommendations, and mitigation strategies
• Coordinate with engineers, SMEs, subcontractors, and vendors to assess security impacts of system changes
• Develop and deliver security documentation, briefings, and artifacts to support stakeholder decision-making
Basic Qualifications
• 3+ years of experience as an Information System Security Officer (ISSO) or Information System Security Analyst (ISSA)
• Experience implementing and maintaining security controls for IT systems and cybersecurity tools
• Experience conducting configuration assessments and risk analysis
• Experience supporting RMF processes and security authorization activities
• Experience with eMASS or Xacta IA Manager
• Active TS/SCI clearance; willingness to take a polygraph exam
Education
• Associate's degree and 5+ years of experience supporting IT projects and activities, or
• Bachelor's degree and 3+ years of experience supporting IT projects and activities, or
• Master's degree and 1+ year of experience supporting IT projects and activities
Certifications
• Active DoD 8570 Information Assurance Technician (IAT) Level II certification (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, CND, or SSCP)
• Must obtain a DoD 8570 Cybersecurity Service Provider (CSSP) - Infrastructure Support certification (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND) prior to start date
Desired Qualifications
• Experience with DoD STIGs, SCAP, ACAS, and configuration assessment tools
• Experience assessing security impacts of new COTS tools, upgrades, or configuration changes
• Experience drafting or reviewing CONOPS, system topologies, and vulnerability scan results
• Familiarity with tools such as Ansible, Terraform, Splunk, or STIG Viewer
• Knowledge of cloud-native security tools and Zero Trust concepts
• Strong written, verbal, and presentation skills
• Ability to work effectively in a fast-paced, collaborative environment
• AWS, Azure, or GCP certification
Compensation
Salary range: $110,000 - $140,000
The Ennoble First pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered include responsibilities of the role, education, experience, knowledge, skills, internal equity, alignment with market data, applicable bargaining agreement (if any), or other law