OverviewStellar Solutions is seeking an Information System Security Officer to support the cybersecurity compliance, authorization, and continuous monitoring of mission systems and assigned enclaves. This role applies technical and functional cybersecurity knowledge to develop solutions aligned with customer mission needs, serving as a bridge between technical security implementation and organizational risk management. The successful candidate will work independently with appropriate guidance, collaborate across technical teams, and may review or guide the activities of junior team members.
Role/Responsibilities/Qualifications
The Information System Security Officer will coordinate security compliance and risk-management activities throughout the system lifecycle. Working with the Information System Security Manager, Information System Security Engineer, system administrators, defensive cyber operations personnel, and product delivery teams, this individual will ensure security requirements are implemented, documented, assessed, and sustained. The role requires disciplined documentation, technical judgment, and the ability to communicate cybersecurity risks and requirements to technical and nontechnical stakeholders.
Key responsibilities include:
- Develop and maintain System Security Plans, Risk Assessment Reports, Plans of Action and Milestones, Security Control Traceability Matrices, Bodies of Evidence, security policies, and related Assessment and Authorization artifacts.
- Ensure authorization documentation is accurate, current, and aligned with applicable federal security regulations, organizational policies, and Risk Management Framework requirements.
- Document cybersecurity exceptions, deviations, and waivers, and maintain authorized-user access records in accordance with applicable records-management requirements.
- Verify that security controls for assigned enclaves are implemented, documented, and operating as intended, including maintaining current information in OpenRMF and eMASS.
- Conduct compliance audits, prepare systems for external inspections, and lead on-site cybersecurity assessments for assigned enclaves.
- Oversee continuous monitoring activities by reviewing security metrics, system logs, vulnerability scans, reports, and compliance trends.
- Identify risks and vulnerabilities, coordinate mitigation and remediation activities, and track corrective actions through Plans of Action and Milestones.
- Review Security Impact Analyses and provide security input during Configuration Control Board meetings and system change activities.
- Coordinate the identification, reporting, tracking, resolution, and post-incident review of cybersecurity incidents with defensive cyber operations personnel and other stakeholders.
- Provide cybersecurity training, procedures, and subject-matter expertise to system users, administrators, security teams, infrastructure teams, and product teams.
- Prepare quarterly security reviews and report compliance status, vulnerability remediation timelines, incident-response performance, risks, and recommended improvements.
- Identify opportunities to improve security controls, system hardening, tools, configurations, processes, and overall system defenses.
Required Qualifications
- Minimum of six years of experience as an Information System Security Officer supporting a federal agency or federally funded research and development center.
- Experience coordinating Assessment and Authorization activities and developing System Security Plans, Security Control Traceability Matrices, Plans of Action and Milestones, Bodies of Evidence, and related artifacts.
- Knowledge of FISMA, FIPS, FedRAMP, NIST SP 800-37, NIST SP 800-60, NIST SP 800-53, and the Risk Management Framework.
- Experience with continuous monitoring, vulnerability management, compliance audits, incident coordination, and remediation tracking.
- Experience using Governance, Risk, and Compliance tools and technologies, including Microsoft Office, Adobe Acrobat, and Visio.
- Ability to analyze logs, alerts, vulnerability reports, security metrics, and compliance data and translate findings into actionable recommendations.
- Experience coordinating with cybersecurity engineers, system administrators, defensive cyber operations teams, product owners, and other stakeholders.
- Ability to maintain complete, accurate, and audit-ready cybersecurity documentation.
- Bachelor’s degree in a science, technology, engineering, or mathematics field.
Desired Qualifications
- Experience with system hardening, configuration testing, continuous monitoring, and vulnerability scanning using Nessus, Splunk, McAfee, or related tools.
- Experience configuring or tuning security tools to support effective monitoring and vulnerability identification.
- Ability to identify process gaps, improve efficiency, resolve Plans of Action and Milestones, and develop mitigation reports from compliance and vulnerability-scanning results.
- Experience using OpenRMF and eMASS to document security controls and authorization information.
- Security+, CISSP, CISM, or CEH certification.
- Knowledge of emerging threats, vulnerabilities, attack techniques, and proactive defensive measures.
Clearance & Additional Requirements
- U.S. citizenship is required.
- Active Secret security clearance is required.
- Eligibility to obtain and maintain a Top Secret/Sensitive Compartmented Information clearance is required.
- Must obtain and maintain the cybersecurity certification required by AFMAN 17-1303.
- Ability to travel less than 10 percent of the time.
Location
Boulder, CO
Compensation:
The typical annual salary range for this position is approximately, USD $130,000 - $170,000. Individual pay is determined by many factors including work location, job-related skills, experience, and relevant education or training. In addition to salary, this position is also eligible for a discretionary annual performance bonus, profit sharing / retirement plan and other benefits (all in addition to annual base salary).
Deliverable(s)
You will be key member of a diverse team maintaining RMF compliant infrastructure that supports the national security mission. You will be responsible for generating risk matrices, POAMs, system scans and STIGs and creating compliant RMF packages in eMASS.