Job ID: 9662
Date Posted: September 30, 2026
Location: Hill AFB, UtahSpace Dynamics Laboratory (SDL) is seeking a highly experienced Information Systems Security Officer (ISSO) to lead security efforts, ensuring compliance with federal regulations and industry best practices. The ideal candidate has 5+ years of experience in cybersecurity, risk management, and information system security.
Key Responsibilities:Security Compliance & Risk Management
- Ensures information systems comply with NIST 800-53, RMF, and other security frameworks
- Conducts risk assessments, vulnerability management, and mitigation planning
- Performs audit log reduction and analysis as well as SIEM tuning and configuration
- Maintains Authority to Operate (ATO) requirements for classified systems
Incident Response & Continuous Monitoring
- Oversees security operations, threat analysis, and intrusion detection
- Develops and executes incident response plans to protect sensitive data
- Implements continuous monitoring strategies to proactively identify threats
Policy Development & Documentation
- Develops security policies, procedures, and guidelines in alignment with DoD regulations
- Ensures thorough audit readiness and proper documentation of security controls
- Manages security training programs to promote best practices
Collaboration & Leadership
- Works closely with program teams, IT teams, and security personnel to strengthen SDL's cybersecurity posture
- Serves as a trusted advisor for leadership on emerging threats and risk management strategies
- Leads security assessments and interfaces with Government agencies (e.g., DoW entities)
Required Qualifications:- 5-10 years of experience in information systems security, cybersecurity, or related fields
- Bachelor's degree in cybersecurity, computer science, information assurance, or a related field
- Ability to obtain in 6 months after hire date one of the following certifications: CISSP, CISM, CISA, CGRC, or equivalent
- Knowledge of Security Frameworks: NIST 800-53 Risk Management Framework (RMF), FISMA, and DoD security controls
- Experience with examining and understanding security documentation for system hardware and software, to include System Security Plan (SSP), Plan of Action and Milestones (POA&M), equipment specifications, practices, and procedures including assessment of controls and artifacts to verify the system is ATO ready
- Assist in the execution of the Incident Response Plan, specifically in Data Spillage Cleanup
- Prepare the weekly, monthly, quarterly, bi-annual, and annual ConMon reports to push towards a perpetual ATO
- Recommend software packages for use in secure spaces
- Technical Skills: Expertise in SIEM tools, vulnerability scanning, encryption, and secure network architecture
- Ability to create professional reports for system owners and technical staff that accurately describe test events and results for highly complex requirements
- Must be a U.S. citizen with the ability to obtain and maintain a DoW security clearance
- Active DoW security Clearance
Preferred Qualifications:- Master's degree in cybersecurity, computer science, information assurance, or a related field
- Certifications: CISSP, CISM, CISA, CGRC, or equivalent
- Ability to understand, explain, and mitigate non-implemented controls
- Familiarity with various interconnection agreements and memorandums of understanding
- Familiarity with Joint Special Access Program (SAP) Implementation Guide (JSIG)
- Detailed understanding of customer-centric RMF workflows and the ability to articulate that knowledge to internal and external customers
- In-depth understanding of network topologies, protocols, hardware (switches, routers, etc.) and hardening techniques
- Knowledge of the complex network environments involving shared networks and multiple security enclaves
- Displays in-depth understanding of cybersecurity policies and procedures for government sector information systems
- Familiarity with eMASS ATO submission process
- Must possess the ability to bridge the technical implementation (i.e., developer talk) into commonly understood security words
- Technical knowledge and experience to implement cybersecurity policies and procedures
- Experience working with System Administrators, Developers, and Systems Engineers
- Familiarity with developing and maintaining system security documentation
- Work under limited supervision
*Salary Range- $95,000 - $159,000
- Salary commensurate based on education and relevant experience
This range serves as a general guideline and may vary based on factors such as role, level, location, market conditions, and individual qualifications, including job-related skills, experience, and relevant education or training. The range displayed in the job advertisement reflects the minimum and maximum target salaries across all US locations. Specific salary details for a candidate's preferred location can be provided by the recruiter or HR manager during the hiring process.