Information System Security Officer (ISSO)

Aviation Systems Engineering Company

Lexington Park (MD)

Sur place

USD 125 000 - 140 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’il recherche.

Passez les filtres ATS

Résumé du poste

Aviation Systems Engineering Company is seeking an Information Systems Security Officer (ISSO) to support cybersecurity compliance, assessment and authorization, and continuous monitoring of information systems. The ISSO will coordinate with government cybersecurity personnel and engineering teams to implement security requirements and maintain authorization documentation.

This on-site position at our Lexington Park, MD corporate office may require occasional travel to supported locations.

Qualifications

  • Requires a Bachelor's degree in a related technical field.
  • Minimum 5 years IA/Cybersecurity experience preferred.
  • Experience supporting DoD information systems security activities is desired.
  • Familiarity with RMF, NIST SP 800-53 controls, and DoD requirements.
  • Experience using ACAS, STIGs, SCAP tools for assessments.

Responsabilités

  • Support RMF activities across system lifecycle including controls and authorization.
  • Develop and maintain SSPs, control evidence, and POA&Ms.
  • Maintain authorization docs in eMASS or repositories.
  • Coordinate hardware/software inventories and network diagrams.
  • Perform vulnerability assessments using ACAS and STIGs; verify remediation.
  • Review scans, coordinate with admins, and validate actions.
  • Prepare POA&Ms and mitigation statements for gov't review.
  • Monitor compliance with cybersecurity policies and configurations.
  • Review configuration changes for cybersecurity impact.
  • Coordinate cybersecurity requirements for installations and upgrades.
  • Review security logs and coordinate follow-ups with tech teams.
  • Report suspected incidents and assist with evidence collection.
  • Support inspections and authorization reviews; track follow-up actions.
  • Up to 10% travel may be required.

Connaissances

Relationship building
Excellent communication
Proactive
Analytical thinker
Highly organized

Formation

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field

Outils

ACAS
DISA STIGs
SCAP
eMASS

Description du poste

Description

What You'll Do:

As the Information Systems Security Officer (ISSO), you will support cybersecurity compliance, assessment and authorization, and continuous monitoring of information systems.

The ISSO will coordinate with Government cybersecurity personnel, Information System Security Managers (ISSMs), system administrators, network administrators, and engineering teams to implement security requirements, maintain authorization documentation, and address vulnerabilities.

This position requires on-site work at ASEC's corporate office in Lexington Park, MD. Some travel to supported locations may be required.

Key Responsibilities:
  • Support Risk Management Framework (RMF) activities throughout the system lifecycle, including security control implementation, assessment preparation, authorization, and continuous monitoring.
  • Develop, update, and maintain cybersecurity documentation, including System Security Plans (SSPs), security control implementation statements, supporting evidence, and authorization package artifacts.
  • Maintain system security records and authorization documentation in eMASS or other Government-designated repositories.
  • Coordinate with technical teams to maintain accurate hardware and software inventories, system boundary descriptions, network diagrams, and configuration baselines.
  • Perform and review vulnerability assessments using the Assured Compliance Assessment Solution (ACAS), applicable DISA Security Technical Implementation Guides (STIGs), and the Security Content Automation Protocol (SCAP) Compliance Checker.
  • Evaluate scan results and STIG findings, coordinate remediation with system and network administrators, and validate corrective actions.
  • Develop and maintain Plans of Action and Milestones (POA&Ms), track remediation progress, and prepare mitigation statements and supporting documentation for Government review.
  • Monitor compliance with applicable cybersecurity policies, approved system configurations, and authorization conditions.
  • Review proposed hardware, software, network, and system configuration changes for cybersecurity impacts and support established configuration management processes.
  • Coordinate cybersecurity requirements for system installations, upgrades, integration activities, and deployments.
  • Review security logs and monitoring information, identify potential concerns, and coordinate follow-up with appropriate technical and cybersecurity personnel.
  • Report suspected cybersecurity incidents through established channels and assist with evidence collection, documentation, and corrective actions.
  • Support inspections, security control assessments, and authorization reviews by organizing evidence, addressing findings, and tracking follow-up actions.
  • Up to 10% travel will be expected.

This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.

Requirements
What You'll Bring:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related technical field.
  • At least 5 years of related IA/Cybersecurity experience is preferred.
  • Demonstrated experience supporting cybersecurity compliance, vulnerability management, or assessment and authorization activities for DoD information systems.
  • Working knowledge of RMF, NIST SP 800-53 security controls, and DoD cybersecurity requirements.
  • Experience developing and maintaining authorization documentation, security control evidence, and POA&Ms.
  • Experience using ACAS, DISA STIGs, and SCAP tools to assess system security and support vulnerability remediation.
  • Familiarity with eMASS or comparable cybersecurity assessment and authorization repositories.
  • Working knowledge of Windows and Linux operating systems, networking fundamentals, access controls, and system hardening.
Certification Requirements:
  • At a minimum, this position requires CompTIA Security+.
  • Candidates with a bachelor's degree specifically in Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering do not require an additional certification beyond the baseline (Security +) requirement.
  • Candidates without one of these degrees must hold one of the following additional certifications: SecurityX, GMON, CCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GSEC, SSCP. Note: your CISSP or CISM will satisfy the additional certification requirement.
Equally Important:
  • Ability to build positive, collaborative relationships across teams and with external partners.
  • Effective communicator with strong verbal and written skills.
  • Proactive, self-directed work style with the ability to operate independently.
  • Analytical thinker with proven problem-solving capabilities.
  • Highly organized, with the ability to balance competing priorities in a fast-paced environment.

ASEC is committed to providing access and reasonable accommodation in its services, activities, programs, and employment opportunities in accordance with the Americans with Disabilities Act and other applicable laws.

Security Clearance Requirement:
  • This position requires U.S. citizenship and an active DoD Top Secret clearance. Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
Salary Range:
  • The anticipated annual salary range for this position is $125,000 - $140,000, commensurate with an individual's experience, qualifications, and skill set. ASEC is committed to providing fair and equitable compensation.
Who We Are:

ASEC offers meaningful, mission-driven work within a culture that supports your professional and personal growth. We partner with our government customers to deliver innovative solutions across engineering, information technology, training, and logistics. Above all, we are committed to doing what's right for the Warfighter-plain and simple. Explore what makes ASEC different by visiting our website.

Why work at ASEC?
  • 100% employee-owned company. Learn more about our Employee Stock Ownership Plan (ESOP) here!
  • Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
  • 401(k) with company match
  • Tuition assistance for undergraduate and graduate education
  • Veteran-friendly employer
  • Thriving employee culture

ASEC is an Equal Opportunity Employer. We recruit, hire, train, compensate, and promote employees based on qualifications, merit, and business needs, without regard to race, color, religion, sex, national origin, ancestry, age, marital status, sexual orientation, gender identity or expression, disability, veteran status, genetic information, pregnancy or related conditions (including breastfeeding), or any other status protected by law.

ASEC also complies with all applicable pay transparency laws and will not discriminate against employees or applicants for inquiring about, discussing, or disclosing compensation.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Lexington Park (MD)

Sur place
USD 125 000 - 140 000
ESOP
Comprehensive benefits package
401(k)
+3
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • California (MO)

Sur place
USD 145 000 - 165 000
100% employee-owned company
Comprehensive benefits package
401(k) with company match
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Lemoore (CA)

Sur place
USD 115 000 - 150 000
ESOP
11 paid holidays
Medical/dental/vision coverage
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASEC, Inc • Lemoore (CA)

Sur place
USD 115 000 - 150 000
ESOP
401(k) match
Tuition assistance
+2
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Fallon (NV)

Sur place
USD 120 000 - 180 000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

ASEC, Inc • China Lake (CA)

Sur place
USD 135 000 - 165 000
100% employee-owned company
Comprehensive benefits including 401(k) match
Tuition assistance
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Ridgecrest (CA)

Sur place
USD 115 000 - 135 000
ESOP
Benefits package
401(k) with match
+3
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASEC, Inc • Nevada (IA)

Sur place
USD 80 000 - 120 000
Comprehensive benefits package
Employee Stock Ownership Plan
401(k) with company match
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Aviation Systems Engineering Company • Ridgecrest (CA)

Sur place
USD 115 000 - 135 000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Aviation Systems Engineering Company • California (MO)

Sur place
USD 145 000 - 165 000
Comprehensive benefits package
Tuition assistance
401(k) with company match
+2