Information System Security Officer (ISSO)

Applied Research Associates, Inc

Albuquerque (NM)

On-site

USD 100,000 - 150,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Applied Research Associates, Inc. in Albuquerque, NM seeks an experienced Information System Security Officer (ISSO) to join the security team.

The ISSO will support the ISSM in managing classified information systems under NISPOM and RMF, ensuring continuous compliance and maintaining Authority to Operate (ATO). The role covers patch and configuration management, change control, system documentation, and regular RMF activities in a government contracting environment.

Qualifications

  • Minimum 2-4 years of information technology experience, with at least 2 years in an ISSO role supporting classified information systems.
  • Active Top Secret clearance with SCI eligibility or clearance commensurate with the highest classification level.
  • Strong knowledge of Windows and/or Linux security hardening, STIGs, and audit log management.
  • Experience managing the RMF lifecycle for classified information systems under DCSA cognizance.

Responsibilities

  • Implement and maintain RMF security controls on classified systems per NIST SP 800-53 and applicable STIGs.
  • Ensure change management processes are followed for all hardware and software changes.
  • Populate and maintain system records, artifacts, and security documentation in eMASS.
  • Conduct periodic assessments and support the authorization process through PAC workflow.

Skills

Patch management
STIGs/SCAPs
Configuration management
Audit log management
RMF lifecycle
Windows security
Linux security
NIST SP 800-53
Network security

Education

Bachelor's degree in Cybersecurity or related field

Tools

eMASS
STIG Viewer
SCAP
SIEM
Vulnerability scanners

Job description

Applied Research Associates, Inc. (ARA), Southwest Division (SWD) is looking for an experienced Information System Security Officer (ISSO) to join our security team located in Albuquerque, New Mexico. The Information System Security Officer (ISSO) supports the ISSM in the management, operation, and compliance of classified information systems (IS) operating under the National Industrial Security Program (NISP). This role is governed by the requirements of 32 CFR Part 117 (NISPOM Rule) and the DCSA Assessment and Authorization Guide (DAAG), which implements the Risk Management Framework (RMF) for cleared contractor facilities. The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture of assigned systems, ensuring continuous compliance with DCSA authorization requirements and maintaining a valid Authority to Operate (ATO).

Essential Functions as an ISSO
  • Possessing sufficient experience and technical competence commensurate with the complexity of the systems to include patch management, account management, STIGs/SCAPs, application updates and installs, hardware configuration and troubleshooting
  • Ensure all hardware and software additions, removals, and modifications follow approved change management processes
  • Maintain configuration management documentation for all hardware and software changes to classified systems
  • Implement and validate security controls on classified systems per NIST SP 800-53, CNSSI 1253, and applicable STIGs.
  • Ensuring user activity monitoring data and audit records are analyzed, stored, and protected in accordance with the ITPSO policies and procedures and System Security Plan (SSP)
  • Review system audit record findings related to inappropriate or unusual activity and elevate findings to the ISSM
  • Report all security-related incidents to the ISSM in accordance with 32 CFR Part 117 requirements
  • Assess changes to assigned systems that could affect authorization status and notify the ISSM
  • Assist and support the ISSM in all the following tasks:
  • Executing all phases of the RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor to include decommission
  • Development, maintenance, and continuous updating of Information Systems
  • Populate and maintain system records, artifacts, and security documentation in eMASS throughout the RMF lifecycle
  • Preparation and submission of authorization packages through the Package Approval Chain (PAC) workflow
  • Conducting periodic assessments and continuous monitoring of authorized systems and providing the corrective actions for all identified findings and vulnerabilities
  • Development and tracking of Plans of Action and Milestones (POA&Ms) for identified vulnerabilities
Experience and Skills Required
  • Minimum 2-4 years of experience in information technology, with at least 2 years in an ISSO or equivalent role supporting classified information systems
  • Demonstrated working knowledge of 32 CFR Part 117 §117.18, the DCSA Assessment and Authorization Guide (DAAG), and NIST 800-series publications
  • Experience managing the RMF lifecycle for classified information systems under DCSA cognizance
  • Active (or ability to obtain) Top Secret clearance with SCI eligibility or clearance commensurate with the highest classification level processed on facility systems
  • Strong technical knowledge of Windows and/or Linux security hardening, STIG application, network security fundamentals, and audit log management
  • Experience with classified system configuration management, media control, and sanitization/destruction procedures
Core Competencies
  • Technical understanding of classified system security controls, network architecture, and risk management
  • Knowledge of NISPOM and related CFRs, DAAG, NIST SPs, CNSSI directive
  • Analytical thinking, technical writing, and the ability to produce clear security documentation (SSPs, POA&Ms, incident reports)
  • Effective collaboration with the ISSM, FSO, ITPSO, IT staff, and program managers
  • Discretion and integrity in handling classified information and sensitive cybersecurity data
  • Commitment to continuous professional development and staying current with evolving cybersecurity threats and DCSA guidance
Preferred
  • Security+
  • Prior industry ISSO or cybersecurity assessor experience (DCSA, NSA, or IC)
  • Knowledge of cross-domain solutions, classified cloud environments (IL4/IL5), and network interconnection security
  • Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and STIG Viewer / SCAP compliance tool
Experience Required
  • 2 - 4 years: Relevant work experience
Education Required
  • Bachelors or better in Cybersecurity or related field
Behaviors Required
  • Team Player: Works well as a member of a group
  • Functional Expert: Considered a thought leader on a subject
  • Detail Oriented: Capable of carrying out a given task with all details necessary to get the task done well
  • Dedicated: Devoted to a task or purpose with loyalty or integrity
Motivations Required
  • Self-Starter: Inspired to perform without outside help
  • Goal Completion: Inspired to perform well by the completion of tasks
  • Ability to Make an Impact: Inspired to perform well by the ability to contribute to the success of a project or the organization

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

See job description

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Astrion • United States

On-site
USD 90,000 - 120,000
Information System Security Officer (ISSO) with Security Clearance
Information System Security Officer (ISSO) with Security Clearance

OSAAVA Services • Bellevue Second IV Precinct (NE)

On-site
USD 90,000 - 130,000
Medical, dental, vision insurance
401(k) with company match
Paid time off
+2
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Annapolis (MD)

On-site
USD 100,000 - 130,000
Ongoing training and mentorship
Competitive compensation
Generous benefits and work-life balance
Information System Security Officer
Information System Security Officer

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 90,000 - 130,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software • Maryland

On-site
USD 120,000 - 160,000
Competitive compensation
Generous benefits
Ongoing training and mentorship
+1
ISSO - Information Systems Security Officer
ISSO - Information Systems Security Officer

Anavationllc • Huntsville (AL)

On-site
USD 95,000 - 150,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Snsone • Fort Meade (MD)

On-site
USD 80,000 - 110,000
Competitive compensation
Strong benefits
Professional growth opportunities
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000