Information System Security Officer (ISSO) jobs in United States
cer-icon
Apply on Employer Site
company-logo

ASEC ยท 11 hours ago

Information System Security Officer (ISSO)

ASEC is a company that partners with government customers to deliver innovative solutions across engineering, information technology, training, and logistics. They are seeking an Information System Security Officer to support a high-visibility DoD program by shaping and enforcing security policies and conducting vulnerability assessments to protect mission-critical systems.

AerospaceConsultingLogisticsTraining
check
Growth Opportunities
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Proposing, coordinating, implementing, and enforcing information system security policies, standards and methodologies
Conducting vulnerability assessments using automated benchmarks and tools such as Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs), and Security Content Automation Protocol (SCAP) Compliance Checker
Utilizing SolarWinds or Splunk to perform advanced system monitoring, security event analysis, and continuous compliance activities
Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides (STIGs)
Performing security control continuous monitoring, reviewing system security plans and associated artifacts, security audits, risk analysis and developing mitigation strategies for DoD information systems
Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL)
Preparing certification letters and Memoranda of Agreement (MoA) with system owners for interface and networking implementations
Providing guidance of cross-functional cybersecurity efforts ensuring alignment with organizational and program goals and milestones
Collaborating on documentation for Information System Authority to Operate (ATO) decisions, including SSPs, SOPs, POA&Ms, and Knowledge Articles
Conducting comprehensive risk assessments and vulnerability analyses to identify and mitigate potential threats to satellite communication infrastructures

Qualification

IAM-II certificationInformation Assurance/CybersecurityRisk Management FrameworkVulnerability assessmentsSecurity controls implementationContinuous monitoringSecurity auditsMitigation strategiesAnalytical thinkerEffective communicatorProactive work styleHighly organized

Required

Bachelor's in Computer Science, Information Systems Management, Engineering, or a related, technical area of study preferred. Without a bachelor's degree, 10 years of experience as an ISSO will be required
Candidates must hold a current IAM-II certification (i.e CompTIA CASP+ CE, CISM, CISSP) as defined by DoD 8570.01-M
At least 5 years of experience in Information Assurance/Cybersecurity (IA/CS)
At least 5 years of experience in Risk Management Framework (RMF) DODI 8510.01
At least 5 years of experience in Security controls and implementation delineated in Committee of National Security Systems Instruction (CNSSI) 1253 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and the Joint Special Access Program Implementation Guide (JSIG)
At least 5 years of experience in Performing vulnerability assessments using Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), the Security Content Automation Protocol (SCAP) Compliance Checker, incorporating automated Benchmarks
At least 5 years of experience in Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides
At least 5 years of experience in Performing security control continuous monitoring, security audits, risk analysis and developing mitigation strategies for DoD information systems
At least 5 years of experience in Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL)
Knowledge of the Intelligence Community Directive (ICD) 705, DoD 5205.07, and DOD 5205.07-M Volumes 1-4, Special Access Program (SAP) Policy, and the Joint Special Access Program Implementation Guide (JSIG)
Ability to build positive, collaborative relationships across teams and with external partners
Effective communicator with strong verbal and written skills
Proactive, self-directed work style with the ability to operate independently
Analytical thinker with proven problem-solving capabilities
Highly organized, with the ability to balance competing priorities in a fast-paced environment
This position requires U.S. citizenship and an active DoD Top Secret clearance with SCI eligibility

Benefits

Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
401(k) with company match
Tuition assistance for undergraduate and graduate education
Veteran-friendly employer
Thriving employee culture

Company

ASEC

twittertwitter
company-logo
ASEC is an award-winning, 100% employee-owned business specializing in engineering, IT, training, and logistics, ensuring mission success through specialized expertise and cost-effective solutions.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Kristi Rote
Chief Financial Officer
linkedin
leader-logo
Jared Victory
CIO/Drone Operator
linkedin
Company data provided by crunchbase