Information System Security Officer (ISSO)

JFL Consulting LLC

Omaha (NE)

On-site

USD 120,000 - 140,000

Full time

22 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Full medical coverage (incl. depend.)
FSAs
Life and disability insurance
401(k) with immediate vesting
Generous PTO
Certification reimbursement

Job summary

JFL Consulting LLC is seeking an Information System Security Officer (ISSO) to support cybersecurity, RMF, and system authorization across secure government environments. The role focuses on maintaining security posture, supporting ATO and continuous monitoring, and ensuring DoD compliance throughout system lifecycles.

Ideal candidates have hands-on RMF experience, knowledge of NIST SP 800-53, vulnerability management, and security documentation.

Qualifications

  • 3-8+ years of information security, cybersecurity, or information technology experience.
  • Hands-on experience supporting RMF processes and system authorization activities.
  • Experience with vulnerability management, security scanning, STIG implementation, and remediation.
  • Familiarity with DoD cybersecurity requirements and security controls.

Responsibilities

  • RMF & Authorization Support: collaborate with ISSMs/ISSO, support RMF/ATO efforts.
  • Security Documentation & Compliance: develop SSPs, POA&Ms, SCTMs and monitor compliance.
  • Vulnerability Management & Security Operations: monitor vulnerabilities, coordinate remediation.
  • Technical Coordination & Communication: coordinate with owners, engineers, and leadership; produce status updates.

Skills

RMF experience
Vulnerability management
NIST SP 800-53
DoD compliance
ATO support

Education

Bachelor's degree in Cybersecurity, IT, or related field

Tools

eMASS
Xacta
Nessus Pro
ACAS

Job description

Information System Security Officer (ISSO)
About this position

Description:

Job Title: Information System Security Officer (ISSO)

Place of Performance: Bellevue, Nebraska (Omaha, Nebraska metropolitan area)

Mandatory Requirements: TS/SCI Clearance

Experience Level: Mid-Sr Level (3-8+ years)

On-Site, hybrid, remote: On-Site

Travel: Minimal / As Required

About JFL Consulting: With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients. Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit www.jflconsulting.com

What We Offer:

  • Salary: $120k - $140k
  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms

Job Overview: JFL Consulting is seeking a skilled Information System Security Officer (ISSO) to support cybersecurity, Risk Management Framework (RMF), and system authorization activities across secure government environments. This position is focused on maintaining the security posture of assigned information systems throughout their lifecycle, supporting Authorization to Operate (ATO) and continuous monitoring activities, and ensuring compliance with applicable DoD cybersecurity requirements. Candidates should have hands-on experience with RMF processes, security documentation, vulnerability management, security control implementation and validation, and remediation activities.

Key Responsibilities:

Responsibilities - RMF & Authorization Support:

  • Work directly with the Risk Management Framework (RMF) team (e.g., Information System Security Managers (ISSM), ISSOs, Cyber Security Engineers) supporting critical networks, and future RMF/Authorization to Operate (ATO) efforts.
  • Maintain the security posture of assigned information systems throughout their lifecycle.
  • Support RMF activities, including system authorization and reauthorization efforts.
  • Support development, maintenance, and execution of RMF packages within eMASS, Xacta, or other applicable compliance tools.
  • Ensure compliance with applicable cybersecurity policies, standards, and frameworks, including NIST guidance (Special Publication (SP) 800-53 Rev. 5) and Department of Defense cybersecurity requirements.
  • Support Security Control Assessments (SCAs), audits, inspections, and authorization activities.
  • Coordinate security control remediation efforts with ISSMs, Network / Systems Engineers, System Administrators and support maintenance of system authorization status.

Security Documentation & Compliance

  • Develop, maintain, and review system security documentation, including:
  • System Security Plans (SSPs)
  • Plans of Action and Milestones (POA&Ms)
  • Security Control Traceability Matrices (SCTMs)
  • Review security configurations, system changes, and software deployments for cybersecurity and compliance impacts.
  • Track and report cybersecurity metrics, vulnerabilities, incidents, remediation activities, and overall compliance status.
  • Support continuous monitoring (ConMon) activities and associated documentation.
  • Maintain accurate documentation necessary to support RMF, ATO, audit, and compliance requirements.

Vulnerability Management & Security Operations

  • Monitor system vulnerabilities and ensure timely mitigation, remediation, and documentation.
  • Support vulnerability assessments, security scanning, Security Technical Implementation Guide (STIG) implementation, and remediation activities using tools such as Nessus Pro, Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), and EvaluateSTIG.
  • Assist with incident response activities, investigations, and corrective actions.
  • Validate security controls and system configurations to ensure continued compliance with established cybersecurity requirements.
  • Identify cybersecurity risks and coordinate appropriate remediation with technical and program stakeholders.

Technical Coordination & Communication

  • Coordinate with system owners, engineers, administrators, cybersecurity personnel, and other stakeholders to address security and compliance requirements.
  • Communicate cybersecurity risks, vulnerabilities, compliance issues, and remediation requirements to technical (ISSM) and program leadership.
  • Manage multiple systems, priorities, and authorization activities simultaneously.
  • Produce clear and accurate technical documentation, reports, and cybersecurity status updates.

Requirements:

Requirements - Certifications:

  • Required Baseline Certification: Active CompTIA Security+ CE certification is required as a minimum DoD 8140 baseline unless superseded by one or more of the advanced credentials below.
  • Preferred / Qualifying Advanced Certifications: Holding any of the following satisfies the baseline requirement and is preferred to align with intermediate DoD Cyber Workforce Framework Role 722 (ISSM) or Role 612 (Security Control Assessor) responsibilities:
    • CISSP, CISM, CISA, or CGRC
    • CCSP or Cloud+
    • SecurityX (CASP+), CySA+, or PenTest+

Experience:

  • 3-8+ years of information security, cybersecurity, or information technology experience.
  • Hands-on experience supporting Department of Defense Risk Management Framework (RMF) processes and system authorization activities.
  • Experience with vulnerability management, security scanning, STIG implementation, and remediation.
  • Working knowledge of cybersecurity principles, security controls, and DoD compliance requirements.
  • Experience supporting system authorization, reauthorization, and continuous monitoring activities.

Technical Skills:

  • Working knowledge of NIST SP 800-53, NIST Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), Continuous Monitoring (ConMon), eMASS or similar compliance tools, Security Control Assessments (SCAs), and Authorization to Operate (ATO) packages.
  • Understanding of cybersecurity risk management, security control validation, and compliance requirements.
  • Familiarity with vulnerability assessment and remediation processes.
  • Familiarity with incident response processes and corrective actions.

Communication:

  • Strong written and verbal communication skills.
  • Ability to develop and maintain clear technical and cybersecurity documentation.
  • Ability to communicate security risks and compliance requirements to both technical and non-technical stakeholders.
  • Ability to coordinate effectively across engineering, operations, cybersecurity, and program teams.

Preferred Education, Experience, & Skills:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent relevant experience.
  • Experience supporting federal government or Department of Defense information systems.
  • Experience supporting multiple RMF packages and ATO efforts.
  • Experience with eMASS, Xacta, and DoD authorization processes.
  • Familiarity with cloud security technologies and architectures.
  • Demonstrated experience with cybersecurity risk management, RMF implementation, ATO support, vulnerability remediation, STIG compliance, audit/SCA support, incident response, security documentation, security control validation, and continuous monitoring.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JAAW™ Group • Hill Air Force Base (UT)

On-site
USD 90,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

PD Inc • Washington

On-site
USD 120,000 - 170,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Mount Mary University • Washington

Hybrid
USD 110,000 - 140,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina-SCI Systems de México • Huntsville (AL)

On-site
USD 90,000 - 150,000
Entry Level- Information System Security Officer (ISSO) -
Entry Level- Information System Security Officer (ISSO) -

PD Inc • United States

On-site
USD 63,000 - 120,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Peraton • Laurel (MD)

On-site
USD 120,000 - 190,000
Sign-on bonus (may apply)
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering • Washington

On-site
USD 150,000 - 190,000
11 paid holidays
3 weeks PTO
Company-sponsored health plan
+2
Lead Senior Information Systems Security Officer (ISSO)
Lead Senior Information Systems Security Officer (ISSO)

Dynamic Solutions Technology LLC • Washington

On-site
USD 140,000 - 180,000
ME00673-Senior Information System Security Officer (ISSO)
ME00673-Senior Information System Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

On-site
USD 120,000 - 165,000
Paid holidays
3 weeks PTO
Group medical plan
+4
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina Corporation • Huntsville (AL)

On-site
USD 90,000 - 120,000