JCTM · 4 days ago
Information Security Support Officer (ISSO)
JCTM is an organization focused on cybersecurity and information technology for military forces. They are seeking an Information Security Support Officer (ISSO) to ensure the security and compliance of information systems, manage cybersecurity activities, and support customers in navigating deployment processes.
ConsultingService IndustrySoftwareTraining
Responsibilities
Create, manage, and maintain Authorization and Accreditation (A&A) packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Plans of Action and Milestones (POA&Ms), and other necessary artifacts
Support the entry and maintenance of data in information system security systems of record such as eMASS or Xacta
Drive cybersecurity activities across all phases of the system lifecycle including planning, development, deployment, and operations. Enforce system hardening and perform security analysis to ensure protection of the CIA triad
Brief Information System Security Managers (ISSMs), Security Control Assessors (SCAs), and Authorizing Officials (AOs) on the cybersecurity posture of systems. Provide regular updates and insights
Manage and implement Continuous Monitoring activities including periodic control reviews, audits, vulnerability scans, and penetration test report evaluations
Develop and maintain POA&Ms to track system vulnerabilities, mitigation efforts, remediation actions, and closures. Provide fix actions and compensating controls, perform reviews, and deliver briefings to stakeholders
Qualification
Required
Active TS/SCI Security Clearance
5+ years of relevant cybersecurity experience
Experience assessing technical environments and translating implemented security controls into clear NIST SP 800-53 control narratives and supporting ATO documentation
Hands-on experience with eMASS or Xacta for full system lifecycle activities
Experience with NIST 800-53 Rev5 and CNSSI 1253
Experience as an RMF Engineer, ISSO, and/or information assurance engineer
Familiarity with at least one cloud platform: AWS, Azure, or Google GCP
Experience with Air Force risk management policies and procedures, including DODI 8510.01, AFI 17-101, Fast Track ATO Handbook, and AF Continuous ATO Playbook
Ability to clearly articulate ideas for executive-level consumption
Ability to use prior experience and knowledge to address new situations, especially during client interactions
Bachelor's degree in Information Security, Computer Science, or a related discipline; or in lieu of a degree, 3 additional years of equivalent industry experience
Preferred
Knowledge of the Air Force A&A process and requirements
Familiarity with SIEM tools such as Splunk or Elastic
Experience with DoD DevSecOps Fundamentals Playbook
Experience applying DoD Fast Track ATO and Air Force Continuous ATO Playbook methodologies
Company
JCTM
Joint Computer Technologies & Training Management (JCTM) is an 8(a) certified, Service Disabled Veteran Owned Small Business (SDVOSB) with VA certification, focused on bringing repair and healing to ordinary people as we continue to serve our great nation, its service members, and fellow veterans by supporting specialized programs across the Department of Defense (DoD) and National Intelligence Agencies.