Information System Security Officer (ISSO) – Senior

ASRC Federal

Aberdeen, Northern (MD, KY)

Hybrid

USD 110,000 - 165,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health care
401(k)
Paid time off
Education assistance

Job summary

ASRC Federal is seeking a Senior Information System Security Officer (ISSO) to support DEVCOM-CBC G-6 at Aberdeen Proving Ground, MD. The role focuses on RMF activities, eMASS artifacts, and incident response across unclassified and classified systems.

Requires an active Secret clearance or higher and deep DoD cybersecurity knowledge. The ISSO will maintain ATO status, manage POA&M and CONMON, perform vulnerability assessments, and coordinate remediation actions.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Engineering, or related field or 5 years of experience in lieu of degree.
  • 5+ years of hands-on RMF/EMASS authorization duties.
  • Experience with DoD/Army cybersecurity regulations including RMF policy.
  • Familiarity with Active Directory and STIG/SRG audit processes.

Responsibilities

  • Maintain current Authority to Operate (ATO) status for DEVCOM systems and provide RMF guidance and support to other locations.
  • Develop and update system-level artifacts (policies, plans, diagrams) and map them to controls in eMASS.
  • Coordinate vulnerability scanning and compliance checks (STIGs, Nessus/ACAS).
  • Manage POA&M, milestones, and authorization documentation.
  • Conduct vulnerability management, incident response coordination, and risk assessment tracking.

Skills

RMF EMASS
eMASS
STIG/ACAS
Vulnerability Scans
DoD Regulations
Communication

Education

Bachelor's degree in IT/CS or 5 years equivalent

Tools

eMASS
Nessus/ACAS
POA&M
CONMON

Job description

Information System Security Officer (ISSO) - Senior
Job Description

Posted Tuesday, September 8, 2026 at 5:00 AM

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are atop veteran employer and Certified Great Place to Work™

Program:

DEVCOM-CBC G-6

Location:

On-site at Aberdeen Proving Ground , MD

US Gov. Security Clearance:

A DoD Secret or higher

Position Type:

Full-Time, Exempt

ASRC Federal Technology Solutions LLC is looking for an experienced Information System Security Officer with an active Secret clearance or higher to support their work with DEVCOM-CBC G-6. This position supports the development, implementation, and maintenance of cybersecurity policies, standards, and procedures, ensuring compliance with applicable Department of Defense (DoD), Army, and DEVCOM CBC regulations.

In this role, you will provide cybersecurity support to the DEVCOM-CBC G-6 Cybersecurity Branch, focusing on all aspects of Risk Management Framework (RMF) activities, cybersecurity assessments, and incident response. This role requires a deep understanding of cybersecurity principles, a strong analytical ability, and excellent communication skills to effectively convey complex information to both technical and non-technical audiences, while maintaining a broad portfolio of compliance and accounts management responsibilities across unclassified, classified, and standalone systems.

KEY RESPONSIBILITIES

  • Maintain current Authority to Operate (ATO) status for DEVCOM systems and provide RMF guidance and support to other ACC locations with similar systems.
  • Develop, update, and/or modify the system-level artifacts (e.g., TTPs, plans, policies, procedures, hardware/software lists, data flow, system architecture diagrams, PIAs, Ports/Protocols/Services, MOA/MOU, etc...) and ensure they are associated with corresponding controls in eMASS.
  • Obtain, run, analyze, and import all applicable vulnerability scanners and compliance checkers as required, including STIGs, Nessus/ACAS Scans, etc...
  • Track and report IAVAs related to DEVCOM systems.
  • Create, modify, and/or maintain all aspects of the implementation plan and test results, as defined by DOD, Army, NETCOM, and DEVCOM requirements.
  • Manage Plans of Action and Milestones (POA&M), including development, status updates, milestone tracking, and closure.
  • Manage assigned network packages within eMASS and maintain accurate, current authorization documentation.
  • Create, modify, and/or maintain all aspects of CONMON.
  • Utilize existing or develop custom solutions to facilitate RMF requirements, reduce timelines and provide up-to-date status reporting of compliance
  • Update and track cybersecurity test results, implementation plans, and risk assessments.
  • Evaluate STIG checklists and document compliance status, deficiencies, and required remediation actions.
  • Perform first-response coordination for Negligent Disclosure of Classified Information incidents in accordance with organization SOPs for incident response
  • Conduct vulnerability management activities, including identifying, tracking, and coordinating corrective actions.

REQUIRED QUALIFICATIONS

  • Bachelor's degree (BA/BS) in Computer Science, Information Technology, Engineering, or a related field or 4 additional years of experience (for a total of 5 years) in lieu of the degree
  • 5 or more years of hands-on RMF EMASS Authorization duties
  • Working knowledge of DoD and Army cybersecurity regulations including Army Regulation 25-2, DoD 8140, and DoD RMF policy
  • Experience with Active Directory account management and STIG/SRG audit processes
  • Familiarity with the Army Account Validation System (AVS) or equivalent DoD workforce compliance tracking platforms

PREFERRED QUALIFICATIONS

  • Direct experience with eMASS, POA&M and RMF processes and responsibilities
  • Experience serving as an Enhanced Trusted Agent for PKI hardware token issuance
  • Experience performing Software Assurance or Hardware Assurance reviews for DoD networks
  • Familiarity with NSA and Army data sanitization and destruction policy
  • Experience coordinating Negligent Disclosure of Classified Information or classified spill incident response
  • CISSP, CASP+, or CISM certification
  • Experience supporting DEVCOM or Army G-6 cybersecurity programs

CLEARANCE LEVEL

  • This position requires an active Secret clearance. An interim Secret clearance is acceptable until the full clearance is granted.

EDUCATION REQUIREMENTS

  • Bachelor's degree in Information Technology, Computer Science, or a related field or 4 additional years of experience in lieu of the degree

CERTIFICATION

  • DoDI 8140.03 qualification for DCWF Work Role Information Systems Security Manager (722 Intermediate). Accepted foundational qualifications include certifications mapped to Work Role 722 Intermediate in the current DoD 8140 Qualification Matrix, such as SecurityX, CASP+, CCISO, CCSP, CISSO, Cloud+, Security+, and SSCP.

Preferred

  • CISSP
  • SecurityX
  • SSCP

WORK ENVIRONMENT AND PHYSICAL DEMANDS:

  • This position primarily operates in a professional office environment at Aberdeen Proving Ground, MD, working within or alongside the DEVCOM-CBC G-6 Cybersecurity Branch. The role involves extended use of computer equipment and may require the candidate to move between buildings on the installation to support users and coordinate with government staff. Some work may involve access to classified facilities and systems. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO) – Senior
Information System Security Officer (ISSO) – Senior

ASRC Federal • Maryland

On-site
USD 110,000 - 170,000
Information System Security Officer
Information System Security Officer

ASRC Federal • Alaska

On-site
USD 95,000 - 125,000
Senior Information Security Engineer
Senior Information Security Engineer

ASRC Federal • Reston (VA), Northern (KY)

Hybrid
USD 110,000 - 160,000
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Virginia (IL), Northern (KY)

Hybrid
USD 90,000 - 120,000
Health care
Dental
Vision
+4
Information Security Engineer
Information Security Engineer

ASRC Federal Holding Company • Huntsville (AL)

On-site
USD 90,000 - 130,000
Principal Cyber Security Engineer
Principal Cyber Security Engineer

ASRC Federal • Colorado Springs (CO), Northern (KY)

Hybrid
USD 120,000 - 160,000
Health care
Dental
Vision
+6
Sr. Computer Engineer ISSO
Sr. Computer Engineer ISSO

Amentum • Indiana (PA)

On-site
USD 110,000 - 150,000
Health, dental, and vision insurance
Paid time off
401(k) matching
+6
Sr. Computer Engineer ISSO
Sr. Computer Engineer ISSO

Amentum • Crane (IN)

On-site
USD 110,000 - 150,000
Health insurance
401(k) matching
Educational reimbursement
+6
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASEC, Inc • Nevada (IA)

On-site
USD 80,000 - 120,000
Comprehensive benefits package
Employee Stock Ownership Plan
401(k) with company match
+1
Information Security Engineer
Information Security Engineer

ASRC Federal • Huntsville (AL)

On-site
USD 90,000 - 140,000