Information System Security Officer (ISSO)

Noblis

Huntsville (AL)

On-site

USD 90,000 - 150,000

Full time

6 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Noblis is seeking an Information Systems Security Officer (ISSO) in Huntsville, AL to support the Threat Management Office (TSMO) and DoD RMF efforts. The ISSO will lead RMF packages, assess security controls, and ensure compliance across systems used in live, virtual, and constructive environments.

Responsibilities include developing artifacts (SSP, POA&M), performing vulnerability scans with ACAS/Nessus, SCC, and STIG tools, and maintaining eMASS records to support ATOs.

Qualifications

  • Bachelor's degree in a related field, or 7+ years direct experience.
  • 5+ years in cybersecurity/IA with RMF/ISSO experience.
  • Hands-on with eMASS and RMF package development.
  • DoD 8570/8140 IAT II certification and active DoD Secret clearance.

Responsibilities

  • Serves as an Information Systems Security Officer and will develop and advise on RMF packages, strategies, and technical components to ensure compliance with NIST 800-53 security controls. Assist in the implementation of the required government policy (i.e., NISPOM, NIST, DoD), and documenting process activities.
  • Develop security artifacts to support the Information Assurance program to include System Security Plans (SSP), Plan of Action and Milestones (POA&M), System Diagrams, System User Guides, Privileged User Guides, and other documentation as needed.
  • Perform self-assessments of systems and networks within the environment, using passive evaluation audit tools such as: STIG Viewer, SCAP Compliance Checker (SCC), and active evaluations through ACAS/NESSUS.
  • Track enterprise reporting and efficiencies through automatic generation of required security compliance reports, integration of security tools, system documentation, and other artifacts utilizing the Enterprise Mission Assurance Support Service.
  • Track security updates for Windows and Linux-based operating systems, VMWare based products, and associated software applications to ensure compliance.
  • Periodically conduct a review of system audits, monitor corrective actions until all actions are closed, and identify deficiencies during RMF assessment activities.

Skills

RMF/ISSO experience
NIST SP 800-53 knowledge
Threat assessment

Education

Bachelor's degree in a related field
DoD 8570/8140 IAT Level II certification

Tools

ACAS/Nessus
SCAP Compliance Checker (SCC)
STIG Viewer
Evaluate-STIG
eMASS

Job description

Responsibilities

Noblis is hiring an ISSO in Huntsville, AL to supporting the Threat Management Office (TSMO). The mission of the Threat Systems Management Office (TSMO) is to manage the Army Threat System Programs to include the total life cycle of threat systems for testing and training in the live, virtual, and constructive environments. TSMO designs, builds and tests representations of operational and emerging hostile systems with virtually identical performance capabilities that match the identified threat. TSMO ensures all threat systems are continually developed, upgraded, and/or modified and tested to reflect the current threat weapons systems platforms with state-of-the-art technology to support new and emerging DOD weapon systems. Additionally, TSMO conducts threat assessment and analysis in conjunction with the Army, Navy and other joint services operations.

Responsibilities

Noblis is hiring an ISSO in Huntsville, AL to supporting the Threat Management Office (TSMO). The mission of the Threat Systems Management Office (TSMO) is to manage the Army Threat System Programs to include the total life cycle of threat systems for testing and training in the live, virtual, and constructive environments. TSMO designs, builds and tests representations of operational and emerging hostile systems with virtually identical performance capabilities that match the identified threat. TSMO ensures all threat systems are continually developed, upgraded, and/or modified and tested to reflect the current threat weapons systems platforms with state-of-the-art technology to support new and emerging DOD weapon systems. Additionally, TSMO conducts threat assessment and analysis in conjunction with the Army, Navy and other joint services operations.

TSMO utilizes a combination of simulators and simulation models, foreign material acquisition, commercial-off-the-shelf (COTs), and new development efforts to achieve its goal of providing threat relevant Electronic Warfare (EW), Information Operations (IO), integrated air defense (IADs), and command and control (C2) capabilities to support Operational Test and Evaluation (OT&E) events. These OT&Es include Network Integration Evaluations (NIEs), Combatant Commander events, as well as other testing and training events. TSMO requires a range of activities associated with conceptualizing, developing, and supporting the execution of testing events. Support is required to allow for more realistic threat representation testing for both hardware and/or software, and to upgrade threat systems and sub‑systems with modern techniques that will offer superior threat representation testing against foreign threats. The TSMO requires the design of threat representations in order to reproduce live, virtual, and constructive threat simulations that satisfy the U.S. Army Test and Evaluation Command (ATEC) to support future test and training events.

In this role, the Information Systems Security Officer (ISSO) leads the Risk Management Framework process for systems assigned, and will support the full lifecycle of the Department of Defense (DoD) RMF process, from system categorization and control implementation through assessment, authorization, and continuous monitoring. The ISSO must possess a strong knowledge of the process for developing Risk Management Framework (RMF) packages from beginning to award of Authority to Operate (ATO) and must also have a thorough understanding of the Enterprise Mission Assurance Support Service (eMASS) system to include inputting data, maintaining records, and navigating the system.

The ISSO will support the identification of system vulnerabilities and determine appropriate security controls to mitigate or eliminate risk from the uncovered vulnerabilities. The ISSO will be responsible for preparing artifacts and documents to support government Authorization to Operate (ATO) activities. Additionally, the ISSO will conduct and/or support vulnerability and security compliance assessments using applicable tools, including ACAS/Nessus, SCAP Compliance Checker (SCC), STIG Viewer, and Evaluate-STIG. The Contractor shall analyze assessment results, document security deficiencies, support remediation activities, and maintain evidence necessary to demonstrate compliance with applicable NIST, DoD, DISA, and Army cybersecurity requirements.

Specific Duties And Responsibilities Include
  • Serves as an Information Systems Security Officer and will develop and advise on RMF packages, strategies, and technical components to ensure compliance with NIST 800-53 security controls. Assist in the implementation of the required government policy (i.e., NISPOM, NIST, DoD), and documenting process activities.
  • Develop security artifacts to support the Information Assurance program to include System Security Plans (SSP), Plan of Action and Milestones (POA&M), System Diagrams, System User Guides, Privileged User Guides, and other documentation as needed.
  • Perform self-assessments of systems and networks within the environment, using passive evaluation audit tools such as: STIG Viewer, SCAP Compliance Checker (SCC), and active evaluations through ACAS/NESSUS.
  • Track enterprise reporting and efficiencies through automatic generation of required security compliance reports, integration of security tools, system documentation, and other artifacts utilizing the Enterprise Mission Assurance Support Service.
  • Track security updates for Windows and Linux-based operating systems, VMWare based products, and associated software applications to ensure compliance.
  • Periodically conduct a review of system audits, monitor corrective actions until all actions are closed, and identify deficiencies during RMF assessment activities.
Required Qualifications

Bachelor's degree in a related field or 7+ years direct experience.

  • Minimum 5 years of experience in cybersecurity/Information Assurance, with demonstrated RMF/ISSO experience.
  • Demonstrated experience with DoD RMF and obtaining and maintaining ATOs.
  • Demonstrated hands-on experience with eMASS.
  • Experience conducting vulnerability and STIG/compliance scans using ACAS/Nessus, SCC, STIG Viewer, Evaluate-STIG, or equivalent tools.
  • Working knowledge of NIST SP 800-53 and DoD cybersecurity policies.
  • DoD 8570/8140-compliant IAT Level II certification (Security+ CE or higher).
  • Active DoD Secret clearance with the ability to obtain a Top Secret clearance
  • Superior
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina-SCI Systems de México • Huntsville (AL)

On-site
USD 90,000 - 150,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina • Huntsville (AL)

On-site
USD 95,000 - 125,000
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Intermediate ISSO
Intermediate ISSO

Saliense • Virginia (MN)

On-site
USD 90,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000
Information Systems Security Officer (ISSO) (Journeyman)
Information Systems Security Officer (ISSO) (Journeyman)

Interactive Process Technology LLC • Huntsville (AL)

On-site
USD 100,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JAAW™ Group • Hill Air Force Base (UT)

On-site
USD 90,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Astrion • United States

On-site
USD 90,000 - 120,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina Corporation • Huntsville (AL)

On-site
USD 90,000 - 120,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Unity Compass • Alexandria (VA)

Hybrid
USD 90,000 - 175,000