PeopleTec

Information Systems Security Officer (ISSO)

PeopleTec$108K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 9+ years of progressive experience in cybersecurity or related IT fields.
  • 7+ years as an ISSO or ISSM in a cleared DoD or Intelligence Community environment.
  • 3+ years managing cloud-based systems in high-security environments (IL5/IL6).
  • Expertise in implementing and managing RMF for defense systems.
  • Mastery of RMF, NIST SP 800-series documentation, and DoD 8500-series instructions.
  • Exceptional communication skills for translating technical issues into business risks for military leadership.
  • Active IAM Level III certification (e.g., CISSP, GISP) and a cloud security certification from recognized providers.

Responsibilities

  • Lead RMF Steps 1–6 for Guam Defense System to ensure A&A cycles and maintain ATOs.
  • Author and maintain cybersecurity documentation such as SSPs and POA&Ms.
  • Design and implement continuous monitoring for compliance and threats in GDS cloud environments.
  • Conduct vulnerability scans and collaborate on remediation plans with cloud engineers.
  • Utilize security tools to detect and mitigate vulnerabilities and APTs.
  • Support incident response, leading post-incident investigations and remediations.
  • Provide security architecture advice to engineering and DevOps teams on automated deployments and Zero Trust architectures.

Benefits

  • Flexible working hours and potential for remote work.
  • Professional development opportunities including certifications and training.
  • Collaborative and supportive work environment.
  • Health and wellness benefits including medical, dental, and vision coverage.
  • Opportunities to work on cutting-edge cybersecurity projects for national defense.
Full Job Description
Opportunity

PeopleTec is currently seeking an Information Systems Security Officer (ISSO) to support our Huntsville, AL location.

 

This is a Senior Information Systems Security Officer (ISSO) position responsible for overseeing risk management, security compliance, and cybersecurity operations for the cloud-based information systems supporting the Guam Defense System (GDS). This role serves as a key technical and compliance advisor, ensuring systems conform to the Risk Management Framework (RMF), National Institute of Standards and Technology (NIST) guidelines, and DoD Cloud Computing Security Requirements Guide (SRG) for Impact Level 6 (IL6) data.

 

Duties:

  • Lead and coordinate Risk Management Framework (RMF) Steps 1–6 for GDS, ensuring successful Assessment & Authorization (A&A) cycles and securing/maintaining Authorities to Operate (ATOs).
  • Author and maintain comprehensive cybersecurity documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and boundary diagrams.
  • Design and execute continuous monitoring strategies for GDS cloud environments to capture, analyze, and report real-time compliance and threat vectors.
  • Perform regular vulnerability scans and configurations checks of cloud infrastructure, containerized environments, and serverless applications. Analyze results and collaborate with GDS cloud engineers to prioritize and execute remediation plans.
  • Deploy and utilize enterprise security tools to detect, investigate, and mitigate vulnerabilities and advanced persistent threats (APTs).
  • Support incident response teams during active security events. Lead post-incident forensic investigations, root-cause analyses, and the implementation of permanent remediation measures.
  • Provide expert security architecture recommendations to engineering and DevOps teams implementing DevSecOps pipelines, automated infrastructure-as-code (IaC) deployments, and Zero Trust architectures.
  • Track and report cybersecurity risks, system compliance drift, and mitigation progress directly to GDS program leadership and government Authorizing Officials (AOs).
Qualifications

Required Skills/Experience:

  • Minimum of nine (9) years of progressive experience in cybersecurity, information assurance, systems engineering, or related IT fields.
  • At least seven (7) years of direct experience serving as an ISSO or ISSM within a cleared DoD or Intelligence Community (IC) environment.
  • Minimum of three (3) years of hands-on experience securing and managing cloud-based systems (AWS, Azure, or GCP), specifically within federal, defense, or high-security hybrid/multicloud environments (IL5/IL6).
  • Proven experience implementing RMF (NIST SP 800-37, 800-53, 800-137) for tactical, strategic, or defense systems.
  • Mastery of RMF, NIST SP 800-series, CNSSI 1253, and DoD 8500-series instructions.
  • Strong understanding of cloud service models (IaaS, PaaS, SaaS), shared responsibility models, identity and access management (IAM), secure virtual networking, encryption standards (at rest and in transit), and container security (Kubernetes, Docker).
  • Proficiency with enterprise vulnerability management, log aggregation, and system assessment tools.
  • Familiarity with the operational environment of Integrated Air and Missile Defense (IAMD) systems, Joint All-Domain Command and Control (JADC2) initiatives, and cross-domain solution (CDS) implementation is highly preferred.
  • Exceptional written and verbal communication skills, with the ability to translate complex technical vulnerabilities into business/mission risk for senior military leaders.
  • Strong analytical, troubleshooting, and problem-solving skills in high-stakes, fast-paced environments.
  • Candidate must hold an active certification meeting the DoDM 8140.03 IAM Level III requirement:

    • CISSP (Certified Information Systems Security Professional)
    • GISP (Global Information Security Professional)
    • CASP+ (CompTIA Advanced Security Practitioner)
    • Or equivalent IAM Level III-approved certification.
  • Candidate must also hold at least one (1) active cloud security or cloud architecture certification from a major provider or recognized organization:
    • CCSP ((ISC)² Certified Cloud Security Professional)
    • AWS Certified Security – Specialty
    • AWS Certified Solutions Architect – Associate
    • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
    • Google Professional Cloud Security Engineer
  • Ability to travel
  • Must be a U.S. Citizen
  • Active Secret security clearance is required at the time of hire, with the ability to obtain Top-Secret/SCI.

Education Requirements:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related technical discipline is preferred. Master’s degree in a related technical or business field is highly desirable.

About PeopleTec

PeopleTec, Inc. is a defense contractor that provides engineering and technical services to the United States Department of Defense and other government agencies. The company was founded in 2005 and is headquartered in Huntsville, Alabama. PeopleTec specializes in systems engineering, cybersecurity, and software development. The company has received numerous awards for its work, including the 2019 North Alabama Better Business Bureau Torch Award for Ethics and the 2018 Huntsville/Madison County Chamber of Commerce Small Business of the Year Award. PeopleTec has a strong commitment to giving back to the community and supports a variety of charitable organizations.
Learn more about PeopleTec
Size
500 employees
Industry
Net Income
$10 million
Founded
2005
5 Year Trend
+20%
Revenue
$100 million

Similar Jobs

More Jobs at PeopleTec

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO) jobs: