Information System Security Officer (ISSO)
Location: Eglin AFB, FL
Job Status: Full-time
Clearance: Secret, with ability to obtain Top Secret
Certification: CompTIA Security+
Travel: 0-10%
Required Qualifications / Skills
- Active SECRET clearance. Must be eligible for a TOP SECRET clearance. Must be a U.S. citizen.
- Requires 3 to 10 years of relevant experience.
- Bachelor’s or Master’s degree in the applicable discipline.
- 6 years work experience may be substituted for a Bachelor's Degree; OR Associate’s degree plus 4 years work experience may be substituted for a Bachelor's Degree; OR Bachelor's Degree plus 8 years work experience may be substituted for a Master's Degree; OR 12 years work experience may be substituted for a Master's Degree.
- This skill level typically works on high‑visibility or mission‑critical aspects of a given program and performs all functional duties independently.
- CompTIA Security+ certification is required. Other certification may be required based on constantly changing requirements.
Preferred Qualifications / Skills
- Technical audits and enforcement of information systems security procedures.
- Experience working with government regulations, such as NISPOM, JAFAN, JSIG, DIACAP and Risk Management Framework.
- Experience supporting various system configurations (Stand Alone, Local Area Networks, and Wide Area Networks).
- Self‑motivated and possess good written, verbal, listening and presentation skills.
- Previous experience working in a classified information systems environment.
- Familiarity with test equipment and sanitization procedures.
Responsibilities
- The primary purpose of this position is to serve as an ISSO overseeing the cyber‑security posture and compliance of critical mission systems. Responsible for executing the RMF lifecycle, adhering to the DoD Joint SAP Implementation Guide (JSIG), and securing Authorities to Operate (ATOs) for Information Systems.
- Develop, update, and maintain System Security Plans (SSPs), manage Plans of Action and Milestones (POA&Ms), and conduct continuous monitoring of classified and unclassified networks.
- Ensure systems comply with information security policies, FISMA, NIST controls, and applicable DoW/DoD regulations.
- Integrate security by design, advising software developers, system administrators, and project leaders on secure architecture, hardware/software compatibility, and vulnerability mitigation. Design and review security audit routines; analyze complex security incidents; perform risk assessments on new technologies and system modifications. Work to achieve quality improvement in security processes and take a proactive approach to customer assistance. Maintain an up‑to‑date awareness of emerging cyber threats and technologies to predict future security requirements.
- Apply principles of IA and cyber‑security to evaluate new and emerging IT security technologies and ensure successful integration into the organization’s infrastructure.
- Guide systems through the assessment and authorization (A&A) process and maintain continuous ATO status, using knowledge of RMF, JSIG, NIST SP 800‑53 controls and FISMA requirements.
- Isolate vulnerabilities, interpret vulnerability scanner results (e.g., ACAS/Nessus, STIGs), and recommend technical mitigations that support business processes without compromising security.
- Ensure security controls are integrated early in the design phase and evaluate the impact of proposed modifications or new applications via SDLC and DevSecOps.
- Gather facts and use analytical methods to assess complex cyber‑security requirements, develop and manage SSPs and POA&Ms, and solve intricate security and compliance problems.
- Maintain awareness of technological advances and cyber threat intelligence to predict how management can securely meet future operational requirements.
- Communicate orally and in writing to brief senior leadership on cyber risks, draft comprehensive security documentation, and provide training to functional users.
- Modify and adapt precedent security solutions to unique, specialized, or Special Access Program (SAP) requirements.
- Apply agency cyber‑security policies, incident response procedures, and audit management standards.