AM Pierce & Associates
Information System Security Officer
Who We Are:
AM Pierce & Associates and Applied Technologies Group (ATG), a wholly owned subsidiary of AM Pierce & Associates, is a woman-owned small business providing Engineering & Research, Cyber, C5ISR, Program & Acquisition Management services and solutions to a diverse government and industry client base. We are a stable and growing company who offers our employees a rich benefits package, supportive and flexible work environment, and the opportunity to work with experts in their field.
The Position:
Torch Technologies is seeking an Information System Security Officer to join a team supporting cyber security operations for our DoW customer in Lexington Park MD.
Salary:
The estimated salary range for this position is $80,000 - $130,000 annually, based upon an individual's level of experience, skillset, and education. The range that is given is an estimate and may vary based on contractual constraints. At AM Pierce & Associates, it is our goal to provide equitable compensation for all employees.
The Location:
Lexington Park, MD
The Work Environment:
On-Site
The Description:
- Assists in providing detection, identification, and reporting of possible cyber-attacks/intrusions, anomalous activities, and misuse activities. Uses Computer Network Defense (CND) tools for continual monitoring and vulnerability testing and analysis of system activity to identify malicious activity.
- Assists with performing security events and incident correlation using information gathered from a variety of sources.
- Collect, prepare, and submit artifacts supporting eMASS ATO packages, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), and supporting evidence for control implementation.
- Verify system and network configurations against NIST 800-53 control requirements, identifying and documenting gaps or non-conformance.
- Manage the Plan of Action and Milestones (POA&M) for assigned systems, including tracking open findings, coordinating remediation with system owners and engineers, and closing items with appropriate evidence.
- Coordinate with ISSEs, system administrators, and engineering teams to gather technical evidence and validate control implementation.
- Support continuous monitoring activities, including periodic control reviews, vulnerability scan result analysis, and reassessment of control effectiveness.
- Support continuous monitoring activities, including periodic control reviews, vulnerability scan result analysis, and reassessment of control effectiveness.
- Track authorization expiration dates and lead re-authorization/renewal efforts to maintain continuous ATO status.
- Maintain accurate, audit-ready documentation in eMASS for assigned systems and support external audits or assessor requests.
- Review vulnerability and compliance scan results (e.g., ACAS/Nessus, SCAP) and correlate findings to relevant 800-53 controls and POA&M items.
- Support incident reporting and documentation requirements in accordance with applicable DoD and program policies.
- Communicate risk posture and compliance status to program management and Authorizing Officials (AOs) as required.
Education & Experience:
- Bachelor's degree in computer science, or a related field or equivalent experience. Advanced degree preferred.
- A minimum of 2 years of experience in systems security.
- Able to communicate effectively and clearly present technical approaches and findings.
- Work is performed under some direction. Exercises a limited degree of latitude in determining technical objectives of assignment.
Required Qualifications:
- Active DoW Secret security clearance required
- US. citizenship required.
- Bachelor's degree in information technology, Cybersecurity, or a related field, or equivalent professional experience.
- 2+ years of experience in an ISSO, ISSM, or compliance-focused cybersecurity role within DoD or federal environments.
- Working knowledge of the Risk Management Framework (RMF) and NIST 800-53 security controls.
- Hands‑on experience preparing and submitting artifacts in eMASS.
- Demonstrated experience managing POA&Ms, including tracking, coordinating remediation, and documenting closure of findings.
- Familiarity with vulnerability and compliance scanning tools (e.g., ACAS/Nessus, SCAP) and interpreting results against control requirements.
- DoD 8570/8140-compliant certification at IAM/IAT Level II or higher (e.g., Security+, CAP, CySA+).
Preferred Qualifications:
- CAP, CASP, CISSP, or CISM certification.
- Experience supporting both classified and unclassified system authorizations.
- Experience with continuous monitoring/ConMon programs and periodic reassessment cycles.
- Familiarity with STIG‑based hardening and correlating hardening