Information System Security Officer (ISSO) – Contingent Upon Contract Award

Jmares

Philadelphia (Philadelphia County)

Hybrid

USD 110,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

JMA Resources in Philadelphia, PA, seeks an Information System Security Officer (ISSO) to support RMF activities, cybersecurity compliance, and ongoing security operations for client systems. You will coordinate security requirements, maintain documentation and system records, support vulnerability and incident response, and collaborate with ISSMs, system owners, validators, and program stakeholders.

The role requires a DoD clearance eligibility candidate and a STEM bachelor’s degree with

Qualifications

  • 6+ years of professional cybersecurity experience with RMF/A&A and policy compliance.
  • Experience coordinating security changes across multiple organizational levels.
  • Experience with vulnerability analysis and incident response support.

Responsibilities

  • Support RMF and cybersecurity compliance for assigned systems.
  • Coordinate security controls testing and vulnerability remediation.
  • Maintain and update A&A status, eMASS records, and security documentation.
  • Support incident response and cross-team coordination.

Skills

RMF
A&A
cybersecurity controls
continuous monitoring
documentation
communication
coordination with ISSMs/owners

Education

Bachelor's degree in computer science / IT / STEM
CAP
CASP+ CE
CISM
CISSP or Associate of ISC2
GSLC
CCISO
HCISPP

Tools

eMASS
POA&Ms
VRAM

Job description

Position Overview

The Information System Security Officer (ISSO) supports cybersecurity compliance, Risk Management Framework (RMF) activities, and ongoing security operations for assigned client systems. This role coordinates security requirements, maintains cybersecurity documentation and system records, supports vulnerability and incident response activities, and works closely with ISSMs, system owners, and other program stakeholders.

Responsibilities
  • RMF & Cybersecurity Compliance
    • Support Information System Security Managers (ISSMs) in carrying out cybersecurity responsibilities for assigned systems.
    • Coordinate cybersecurity processes and activities in accordance with NAVSEA, Department of the Navy, and Department of Defense policies.
    • Maintain current cybersecurity policies, procedures, Security Plans, and other required system documentation.
    • Track and report Assessment and Authorization (A&A) and Assess Only (AO) status to program and system stakeholders.
    • Support identification of security control baselines and applicable overlays.
    • Conduct RMF Standard Operating Procedure reviews and support resolution of assessment findings.
    • Register and maintain assigned systems in Enterprise Mission Assurance Support Service (eMASS).
  • Security Controls & Continuous Monitoring
    • Coordinate security control testing with Navy Qualified Validators in support of Risk Assessments and Annual Security Reviews.
    • Manage Plans of Action and Milestones (POA&Ms), including tracking vulnerabilities through mitigation and remediation.
    • Monitor changes to security system posture and report relevant updates to the ISSM.
    • Execute continuous monitoring requirements in accordance with the System Level Continuous Monitoring strategy.
    • Review continuous monitoring data, update eMASS records as needed, and elevate issues requiring leadership action.
    • Correlate findings from vulnerability assessments, penetration testing, operational testing, and other security activities to applicable RMF controls.
    • Participate in change control and configuration management activities.
  • Vulnerability & Incident Support
    • Conduct cybersecurity vulnerability and threat analysis for assigned systems.
    • Maintain vulnerability information in Vulnerability Remediation Asset Manager (VRAM).
    • Support cybersecurity incident response, including isolating potentially affected assets, performing initial investigation and data collection, and providing status updates and reporting.
    • Coordinate required security changes across organizational levels to maintain compliance with applicable policies and requirements.
    • Carry out other related duties as assigned to support evolving client, project, and company needs.
Clearance Level
  • Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required. Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines.
Required Qualifications
  • Experience:
    • At least 6 years of professional cybersecurity experience, including experience with:
      • Coordinating and implementing required security changes across multiple levels of an organization.
      • Ensuring compliance with established cybersecurity policies and requirements.
      • Conducting cybersecurity vulnerability and threat analysis.
      • Supporting cyber incident response, including asset isolation, initial investigation, data collection, and status reporting.
  • Education/Certification:
    • Bachelor’s degree in computer science, information technology, communications systems management, or an equivalent STEM field.
    • One of the following certifications:
      • Certified Authorization Professional (CAP)
      • CompTIA Advanced Security Practitioner Continuing Education (CASP+ CE)
      • Certified Information Security Manager (CISM)
      • Certified Information Systems Security Professional (CISSP) or Associate of ISC2
      • GIAC Security Leadership Certification (GSLC)
      • Certified Chief Information Security Officer (CCISO)
      • HealthCare Information Security and Privacy Practitioner (HCISPP)
  • Skills:
    • Strong knowledge of RMF, A&A, cybersecurity controls, and continuous monitoring activities.
    • Experience working with eMASS, POA&Ms, vulnerability tracking, and cybersecurity documentation.
    • Ability to analyze security risks, vulnerabilities, and changes in system security posture.
    • Strong documentation, organization, and technical communication skills.
    • Ability to coordinate effectively with ISSMs, system owners, validators, program managers, and technical teams.
Preferred Qualifications
  • Experience supporting Navy or Department of Defense RMF and cybersecurity programs.
  • Experience with VRAM, Navy cybersecurity processes, or security control validation activities.
Location & Commitments
  • Position: Full Time
  • Work Arrangement:Hybrid – On-site at our client site in Philadelphia, Pennsylvania. The number of days on-site will be determined by client needs after hire.
  • Travel Requirements: May be required
  • Location Preference: Must reside within a 50-mile radius of Philadelphia, Pennsylvania, due to the on-site/hybrid nature of the position.
  • Work Hours: A typical workday consists of eighthours, totaling a forty-hour workweek. We understand that there may be times when employees will need to adjust their work hours due to client needs or personal reasons. To help balance these demands, we offer some flexibility in work schedules.
What We Offer
  • Competitive salary and discretionary bonuses.
  • Comprehensive health benefits, including medical, dental, and vision insurance.
  • Flexible Paid Time Off (PTO) and holidays to help you maintain a healthy work-life balance.
  • Opportunities for professional development and continued learning.
  • Hybrid/remote work arrangement with flexible hours.
  • 401(k) retirement plan with company match.
  • Employee recognition programs and company events.

JMA Resources is an equal opportunity employer committed to achieving a workforce with an environment free of discrimination and harassment. All aspects of employment, including recruitment, hiring, promotions, transfers, discipline, terminations, wage and salary administration, benefits, and training, are based on business needs, job requirements, and individual qualifications, without regard to race, age, color, physical or mental disability, religion, gender, sexual orientation, gender identity/expression, marital status, national origin, political affiliation or protected veteran status.

At JMA Resources, we are dedicated to fostering an inclusive environment for all qualified individuals. We provide reasonable accommodations to persons with disabilities to ensure equal access throughout the application and hiring process. If you needassistanceor require an accommodation, please reach out to Amy Foy, VP of Employee Experience, at afoy@jmares.com.

JMA Resources participates in E-Verify to confirm the identity and employment eligibility of all newly hired employees.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM) - Contingent Upon Contract Award
Information System Security Manager (ISSM) - Contingent Upon Contract Award

Jmares • Philadelphia

On-site
USD 120,000 - 180,000
Information System Security Officer (ISSO) (Engineer Info Assurance 3) - 28730
Information System Security Officer (ISSO) (Engineer Info Assurance 3) - 28730

Huntington Ingalls Industries • Nellis Air Force Base Census-Designated Place (NV)

On-site
USD 95,626 - 135,012
Medical, dental, and vision coverage
401(k) savings plan
Tuition reimbursement
+1
Operations Support Specialist – Contingent Upon Contract Award
Operations Support Specialist – Contingent Upon Contract Award

Jmares • Philadelphia

On-site
USD 65,000 - 95,000
Competitive salary
Health benefits
Flexible PTO
+3
Information Systems Security Manager ISSM
Information Systems Security Manager ISSM

Kms-Solutions,-LL • Alexandria (VA)

On-site
USD 130,000 - 160,000
Medical insurance
401k / retirement savings plan
Paid time off (PTO)
+3
Information System Security Officer (ISSO) (Engineer Info Assurance 3) - 28730
Information System Security Officer (ISSO) (Engineer Info Assurance 3) - 28730

Mission Technologies, a division of HII • Nellis Air Force Base Census-Designated Place (NV)

On-site
USD 95,000 - 130,000
Information Systems Security Manager
Information Systems Security Manager

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information Systems Security Engineer
Information Systems Security Engineer

Data Intelligence LLC • Philadelphia

On-site
USD 100,000 - 130,000
Medical, dental and vision insurance
401k
PTO
+1
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Saalex Corporation in • Camarillo (CA)

On-site
USD 145,000 - 180,000
Health Care Plan (Medical, Dental &amp
Retirement Plan
Life Insurance (Basic, Voluntary & AD&
+5
Program Manager – Contingent Upon Contract Award
Program Manager – Contingent Upon Contract Award

Jmares • Philadelphia

On-site
USD 110,000 - 150,000
Health benefits
Hybrid/remote work arrangement
401(k) retirement plan
+3
Journeyman Information Systems Security Officer (ISSO)
Journeyman Information Systems Security Officer (ISSO)

Saalex Corporation in • Camarillo (CA)

On-site
USD 120,000 - 145,000
Health Care Plan (Medical, Dental &amp
Retirement Plan (401k, IRA)
Life Insurance (Basic, Voluntary &
+5