Junior Information System Security Officer (ISSO) - Audit-Focused

ASEC, Inc.

$120K — $135K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, IT, Engineering, or related field; or 5 years’ experience as an IT technician on DoD classified networks.
  • Minimum 3 years of experience as an ISSO or in cybersecurity, with a focus on system/network security auditing.
  • Familiarity with monitoring tools like SolarWinds SEM and auditing tools such as ACAS.
  • Hands-on experience with DISA STIGs, SCAP Compliance Checker, and DoD information security standards.
  • Knowledge of NIAP/Common Criteria and DoD cybersecurity directives.

Responsibilities

  • Assist with reviewing information system audit logs per established schedules.
  • Monitor security logs for unauthorized access and suspicious activity.
  • Document audit reviews using checklists and reporting templates.
  • Identify and report discrepancies and security concerns to senior cybersecurity personnel.
  • Escalate significant events following incident reporting procedures.
  • Support periodic reviews of user accounts and access permissions.
  • Maintain audit records for compliance and support assessment activities.

Benefits

  • Opportunity for professional growth in a specialized cybersecurity field.
  • Work within a structured environment focused on national security.
  • Gain experience with advanced audit and monitoring tools.
  • Collaborate with seasoned cybersecurity professionals in a critical role.
Full Job Description
Job Type

Full-time

Description

Location: NAS Patuxent River, MD

Security Clearance Requirement: Active Top Secret

Telework Eligible? No, position will be 100% on-site

The Junior Information Systems Security Officer (ISSO) will provide critical cybersecurity auditing support to the OASIS team in PMA-205 by reviewing system audit records, identifying and documenting security concerns, and reporting findings to the Information System Security Manager (ISSM) or cybersecurity lead.

Key Responsibilities:
  • Assisting with reviewing information system audit logs in accordance with established daily, weekly, and monthly schedules.
  • Monitoring security logs for unauthorized access attempts, unusual account activity, privilege changes, policy violations, and other suspicious events.
  • Documenting audit reviews using approved checklists, tracking systems, and reporting templates.
  • Identifying and report audit discrepancies, anomalies, and potential security concerns to the ISSM or senior cybersecurity personnel.
  • Escalating suspicious or significant events in accordance with established incident reporting procedures.
  • Assisting with tracking audit findings and maintaining supporting documentation through resolution.
  • Supporting periodic reviews of user accounts, privileged accounts, and access permissions.
  • Verifying that user access aligns with approved roles and authorization records.
  • Assisting with reviewing records related to account creation, modification, disabling, and removal.
  • Aiding in maintaining audit records to demonstrate compliance with organizational security requirements.
  • Supporting internal and external assessments by collecting and organizing requested audit evidence.
  • Assisting with preparing recurring audit reports, metrics, and compliance documentation.
  • Following established procedures for handling classified, controlled, or sensitive information.
  • Safeguarding audit information from unauthorized access, alteration, or disclosure.
  • Learning and applying applicable cybersecurity policies, procedures, and regulatory requirements.
  • Performing other audit and compliance-related duties as assigned within the scope of the position.
  • This position may require up to 5% annual travel.

The job description is not intended to be an all-inclusive list of duties and responsibilities. It is intended to describe the general nature of the position.

Requirements

Education and Experience:
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, Engineering, or a related technical field highly desired. In lieu of degree, 5 years' experience as an IT technician on DoD classified networks is acceptable.
  • Minimum 3 years of ISSO or cybersecurity experience, with a strong desire to increase experience that is focused on system/network security auditing.
  • Experience with SolarWinds Security Event Manager (SEM), ARM, and related monitoring/auditing tools is preferred.
  • Hands-on experience with ACAS, DISA STIGs, SCAP Compliance Checker, and DoD information security standards.
  • Familiarity with NIAP/Common Criteria, DoD APL, and DoD/IC cybersecurity directives.

Equally Important:
  • Ability to build positive, collaborative relationships across teams and with external partners.
  • Effective communicator with strong verbal and written skills.
  • Proactive, self-directed work style with the ability to operate independently.
  • Analytical thinker with proven problem-solving capabilities.
  • Highly organized, with the ability to balance competing priorities in a fast-paced environment.

Security Clearance Requirement:
  • This position requires U.S. citizenship and an active DoD Top Secret clearance. Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

Salary Range:
  • The estimated salary range for this position will be $120,000 - $135,000 annually, based on an individual's level of experience and skill set. It is our goal at ASEC to provide equitable compensation to all employees.

Similar Jobs

More Jobs at ASEC, Inc.

More Information Technology Jobs

Find similar Junior Information System Security Officer (ISSO) - Audit-Focused jobs: