Oak Ridge National Laboratory

Information Systems Security Officer (ISSO)

Oak Ridge National Laboratory • $100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • BS/BA in information technology or equivalent experience
  • 5+ years in cybersecurity and the C&A process
  • Active Q and/or TS/SCI clearance required
  • Knowledge of RMF process and NIST/CNSSI requirements
  • Strong communication skills for interfacing with security agencies and management
  • Experience developing RMF packages and authorized data transfers

Responsibilities

  • Lead continuous monitoring to ensure compliance with RMF
  • Direct IT personnel in applying security patches and configurations
  • Perform information assurance functions supporting the ISSM
  • Manage Splunk and SolarWinds for log monitoring and incident response
  • Develop and maintain system documentation for accreditation
  • Conduct annual reviews and compliance testing
  • Train users on security procedures and policies

Benefits

  • Work in a high-security environment with cutting-edge technology
  • Engage in meaningful work supporting national security missions
  • Collaborate with experts in cybersecurity and intelligence
  • Opportunity for professional development and certifications
  • Participate in a culture of ethics and values at ORNL
Full Job Description
Requisition Id 17187

Overview:

An active Q and/or TS/SCI clearance is required for consideration.

Oak Ridge National Laboratory (ORNL) is seeking an experienced Information Systems Security Officer (ISSO) to join the Information Assurance Group in the Field Intelligence Operations Division (FIOD). The position reports directly to the Group Leader and requires a Top Secret clearance with access to Q and SCI.

FIOD operates under Department of Energy (DOE) Office of Intelligence and Counterintelligence (IN) authorities and serves as ORNL's focal point for all intelligence community matters. The division sits within the National Security Sciences Directorate (NSSD). It provides operational security, information assurance, and IT support ORNL needs to maintain its Sensitive Compartmented Information Facilities, clearances, and classified systems. NSSD conducts research and development on the nation's most difficult security challenges and adversaries, with science and technology leadership in cybersecurity and cyber-physical resiliency, data analytics, geospatial science, nuclear nonproliferation, and high-performance computing for sensitive national security missions.

The ISSO will support FIOD's classified operations in three areas: classified intelligence IT and information assurance, classified R&D computing, and physical and personnel security. Working with the Information Systems Security Manager (ISSM), the ISSO will help certify and accredit systems and networks and implement cybersecurity requirements and procedures across NSSD.

Major Duties/Responsibilities:

The ISSO leads the continuous monitoring work that keeps FIOD systems compliant with the Risk Management Framework (RMF). The ISSO directs and assists programmatic IT and infrastructure support personnel in applying security patches and secure configurations in line with Security Technical Implementation Guides (STIGs).

Working under general supervision, the ISSO performs the full range of information assurance functions in support of the ORNL FIE ISSM and Group Leader. The ISSO consults routinely with the ISSM on the design, development, integration, and analysis of classified information systems.

The ideal candidate has designed, implemented, and managed security solutions in classified environments, with strong hands-on experience using Splunk for security information and event management (SIEM).

These responsibilities include:

System Security Oversight
  • Provide day-to-day cybersecurity support for classified/Sensitive Compartmented Information (SCI) systems.
  • Ensure compliance with DOE-IN, DoW, and NIST requirements across multiple facilities.
  • Develop, review, and maintain System Security Plans (SSPs) and related RMF artifacts (hardware/software lists, diagrams, PPSM, categorization forms, continuous monitoring plans, contingency plans).


Security Engineering & Compliance
  • Support design and implementation of security controls, ensuring alignment with DISA STIGs and NIST 800-53.
  • Assist with security architecture reviews, risk assessments, vulnerability analyses, and mitigation strategies.
  • Provide technical input for STIG feasibility and implementation, including possible automation of compliance checks.


Monitoring & Incident Response
  • Manage Splunk and SolarWinds environments for log collection, correlation, and monitoring.
  • Create and maintain dashboards, alerts, and reports to support real-time detection and response.
  • Investigate security incidents, document findings, and implement corrective measures.
  • Perform regular audit log reviews, authorized data transfers, and media control in accordance with policy.


Risk Management Framework (RMF) & Documentation
  • Develop and maintain system documentation to support system authorization and accreditation.
  • Track system changes, security impact assessments, and coordinate with ISSM on approvals.
  • Conduct and support continuous monitoring activities, including vulnerability management and reporting.


Governance & Training
  • Conduct annual account reviews, self-inspections, and compliance testing.
  • Train users and system administrators on security procedures and policy.
  • Support ISSM in implementing local policies, reporting metrics, and preparing for inspections.
  • Continuously update and enhance documentation best practices and local security procedures, train users on these procedures, and consistently apply appropriate ES&H standards.
  • Maintain a strong commitment and implementation of ORNL values and ethics.


Basic Qualifications:
  • BS/BA in information technology or technical equivalent and a minimum of five years of experience in cyber security and the C&A process. An overall combination of equivalent education and experience may be considered.
  • An active Q and/or TS/SCI clearance is required for consideration.
  • Working knowledge of:
      • Risk Management Framework (RMF) process & requirements.
      • NIST and CNSSI requirements
  • Excellent written and verbal communication skills with an ability to interface with numerous cognizant security agencies, customers, and senior managers.
  • Previous experience in developing, testing, and collecting artifacts for RMF packages and BoEs of multiple systems.
  • Experience in authorized data transfers across multiple systems and different classifications.


Preferred Qualifications:
  • Relevant ISSO / ISSE experience within the DoW or Intelligence Community.
  • Must be organized, self-motivated, and be able to work with minimal guidance.
  • CISSP, SEC+, or other relevant certifications.
  • Previous experience supporting SCI environments.
  • Deep understanding of incident response procedures and enterprise security tool implementation.
  • Knowledge of the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and configuration standards.
  • Working knowledge of Industry Standard tools for purposes of audit reduction, vulnerability scanning, and malware analysis is preferred. Relevant tools include but are not limited to: Splunk, Tenable Nessus, Host Based Security System (HBSS) components, Security Content Automation Protocol (SCAP) Checker, and STIG viewer.
  • Experience with Security Directives, Policies, Publications, and Regulations.


Special Requirements:
  • Visa sponsorship is not available for this position.
  • This position requires the ability to obtain and maintain a Secret Compartmented Information (SCI) clearance from the Department of Energy. As such, this position is a Workplace Substance Abuse (WSAP) testing designated position. WSAP positions require passing a pre-placement drug test and participation in an ongoing random drug testing program. In addition, due to the SCI, you may also be subject to random polygraph testing.


This position will remain open for a minimum of 5 days after which it will close when a qualified candidate is identified and/or hired.

We accept Word (.doc, .docx), Adobe (unsecured .pdf), Rich Text Format (.rtf), and HTML (.htm, .html) up to 5MB in size. Resumes from third party vendors will not be accepted; these resumes will be deleted and the candidates submitted will not be considered for employment.



About Oak Ridge National Laboratory

Oak Ridge National Laboratory (ORNL) is a science and technology national laboratory managed for the United States Department of Energy (DOE) by UT-Battelle. ORNL is the largest science and energy national laboratory in the Department of Energy system by size and by annual budget. ORNL conducts research and development activities in a variety of scientific and technical disciplines. ORNL's scientific programs focus on materials, neutron science, energy, high-performance computing, systems biology and national security. ORNL partners with other national laboratories, universities and industry to solve complex problems and transfer knowledge and technology. ORNL is home to several of the world's most powerful supercomputers, including Summit, the world's most powerful supercomputer as of November 2018.
Learn more about Oak Ridge National Laboratory
Size
5,000 employees
Industry
Founded
1943

Similar Jobs

More Jobs at Oak Ridge National Laboratory

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO) jobs: