Information Systems Security Officer (ISSO)

Trace Systems Inc.

Riyadh

On-site

SAR 250,000 - 450,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Trace Systems is seeking an experienced Information Systems Security Officer (ISSO) to support the USMTM CITS contract in Riyadh, Kingdom of Saudi Arabia. The ISSO supports cybersecurity posture, authorization, continuous monitoring, vulnerability management, incident response, and compliance for mission-critical systems.

Key duties include RMF planning and authorization support, creating and maintaining System Security Plans and POA&Ms, reviewing scans and logs, and coordinating with Government

Qualifications

  • Eight (8) or more years of progressively responsible cybersecurity experience.
  • DoD RMF, authorization packages, ATO sustainment, POA&Ms, continuous monitoring, and control assessments.

Responsibilities

  • Support RMF implementation for assigned systems and network enclaves.
  • Develop and maintain System Security Plans and control artifacts.
  • Support authorization activities to obtain and maintain ATO status.
  • Maintain POA&Ms and track remediation; coordinate with teams for closure.
  • Prepare risk assessments and continuous-monitoring documentation.
  • Coordinate with Government IAM, ISSM, and authorizing officials.

Skills

Analytical thinking
Technical writing
Stakeholder coordination

Education

Bachelor’s degree in Cybersecurity or related field

Tools

eMASS
ACAS
SCAP Compliance Checker
Log-management tools

Job description

Job Overview

Job Title: Information Systems Security Officer (ISSO)

Job Location: Al Nakhla, Saudi Arabia

Job Responsibilities

Trace Systems is seeking an experienced Information Systems Security Officer (ISSO) to support the USMTM CITS contract in Riyadh, Kingdom of Saudi Arabia. The ISSO supports cybersecurity posture, authorization, continuous monitoring, vulnerability management, incident response, security-control implementation, audit readiness, and compliance for mission-critical classified and unclassified systems.

  • Support implementation and sustainment of the Department of Defense Risk Management Framework for assigned systems and network enclaves.
  • Develop, review, and maintain System Security Plans, control implementation statements, system descriptions, contingency and incident response plans, and authorization artifacts.
  • Support initial and recurring authorization activities required to obtain and maintain Authority to Operate status.
  • Maintain Plans of Action and Milestones, track remediation, validate closure evidence, and coordinate disposition of cybersecurity findings.
  • Prepare Security Assessment Reports, risk assessments, control-assessment evidence, and continuous-monitoring documentation.
  • Coordinate with Government IAM, ISSM, authorizing officials, assessors, cybersecurity service providers, and higher-level organizations.
  • Perform security-impact analyses and provide cybersecurity recommendations through Configuration Control Board processes.
  • Monitor security posture using approved vulnerability, compliance, endpoint-security, logging, and scanning tools.
  • Review scan results, security bulletins, IAVAs, directives, and notifications; prioritize and coordinate remediation with technical teams.
  • Verify implementation of STIGs, security baselines, patches, mitigations, logging, access controls, and corrective actions.
  • Support incident triage, reporting, investigation, containment, eradication, recovery, notifications, and after-action activities.
  • Review system, application, audit, and security logs for anomalies, unauthorized activity, or indicators of compromise.
  • Support account management, privileged access, PKI, token, password, identity lifecycle, certificates, and SIPR credential processes when authorized.
  • Support security testing, inspections, audits, assessments, metrics, briefings, awareness, role-based training, and continuity documentation.
  • Provide cybersecurity guidance that balances compliance, mission availability, operational risk, and technical requirements.
  • Participate in maintenance, emergency response, after-hours support, and on-call activities when cybersecurity events require.
Minimum Qualifications
  • Active, in-scope US Government issued Secret clearance.
  • Due to the nature of the work and contract requirements: US Citizenship is required.
  • Candidates must meet the applicable DoD 8140 qualification requirements for the assigned work role. DoD 8140 Work Role(s): 541 - Vulnerability Assessment Analyst, Proficiency Level: Intermediate; and may qualify through education, military training, certifications, or a combination thereof. DoD identifies Work Role 541 as the Vulnerability Assessment Analyst role.
  • Qualifying education or training may include a bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Data Science, Software Engineering or completion of relevant military cyber, information assurance, communications, or network security training.
  • Qualifying certifications may include Security+, CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or other DoD 8140-approved certifications applicable to the Vulnerability Assessment Analyst work role. Higher proficiency-level or equivalent DoD 8140-approved certifications applicable to the assigned work role may also be accepted.
  • Eight (8) or more years of progressively responsible cybersecurity, information assurance, assessment and authorization, or related security experience.
  • Demonstrated experience supporting DoD RMF, authorization packages, ATO sustainment, POA&Ms, continuous monitoring, and control assessments.
  • Experience with vulnerability scanning, risk assessment, security-impact analysis, incident response, remediation tracking, DISA STIGs, and security baselines.
  • Experience supporting classified information systems or secure Government environments.
  • Working knowledge of NIST security controls, DoD cybersecurity policy, and federal information-security requirements.
  • Strong analytical, technical writing, documentation, briefing, and stakeholder-coordination skills.
  • Ability to relocate to Riyadh, Kingdom of Saudi Arabia.
Desired Qualification
  • Previous experience as an ISSO, ISSM, security control assessor, cybersecurity analyst, or information assurance lead on a DoD program.
  • Experience supporting Army, CENTCOM, USARCENT, NETCOM, DISA, RCC-SWA, or other enterprise cybersecurity organizations.
  • Experience with eMASS, ACAS, SCAP Compliance Checker, endpoint-security platforms, log-management tools, and Government vulnerability-management technologies.
  • Experience supporting Windows Server, Active Directory, VMware, networks, SharePoint, voice, and endpoint environments.
  • Experience with NIST SP 800-53, cybersecurity inspections, authorization reviews, and overseas or military mission support.
Trace Systems

Trace Systems, headquartered in Vienna, Virginia, was founded to support and defend our nation's security interests at home and abroad-- whenever and wherever. We provide cybersecurity, intelligence, communications, networking and information technology services, systems, and solutions to the United States Department of Defense, Intelligence Community and Department of Homeland Security.

Trace Systems is an Equal Opportunity and ... All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Riyadh ISSO: DoD RMF & Cyber Defense Lead
Riyadh ISSO: DoD RMF & Cyber Defense Lead

Trace Systems Inc. • Riyadh

On-site
SAR 250,000 - 450,000
Service Management Analyst
Service Management Analyst

Trace Systems Inc. • Riyadh

On-site
SAR 180,000 - 300,000
Network Administrator
Network Administrator

Trace Systems Inc. • Riyadh

On-site
SAR 240,000 - 360,000
Help Desk Technician
Help Desk Technician

Trace Systems Inc. • Riyadh

On-site
SAR 150,000 - 210,000
Network Support Technician
Network Support Technician

Trace Systems Inc. • Riyadh

On-site
SAR 90,000 - 140,000
SharePoint Developer
SharePoint Developer

Trace Systems Inc. • Riyadh

On-site
SAR 200,000 - 320,000
Voice Technician
Voice Technician

Trace Systems Inc. • Riyadh

On-site
SAR 120,000 - 180,000
Senior Network Administrator – Secure Gov Network (Riyadh)
Senior Network Administrator – Secure Gov Network (Riyadh)

Trace Systems Inc. • Riyadh

On-site
SAR 240,000 - 360,000
Information Security Analyst
Information Security Analyst

Work in USA • Ar Rass

On-site
Information Security & Incident Response Specialist
Information Security & Incident Response Specialist

Al Tamimi • Al Khobar

On-site
SAR 120,000 - 180,000