Information System Security Specialist II

Star3

Indiana (PA)

On-site

USD 85,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Star3 is seeking a skilled Information System Security Specialist II to support security authorization and compliance for critical information systems. This position involves maintaining IA artifacts, applying the Risk Management Framework (RMF), and collaborating with various technical teams to ensure system security.

The ideal candidate will have at least 5 years of experience with DoD cybersecurity standards, strong technical writing skills, and a related degree. This role requires a U.S. citizenship and the ability to obtain a security clearance.

Qualifications

  • 5 years of experience supporting RMF-based ATO processes.
  • Hands-on experience with eMASS, STIGs, SCAP, and ACAS.
  • Knowledge of DoD cybersecurity policies, standards, and best practices.
  • Experience with patch management and vulnerability scanning.
  • Strong technical writing and communication skills.

Responsibilities

  • Create and maintain IA artifacts for ATO decisions.
  • Apply RMF for system accreditation and monitoring.
  • Document security and remediation activities.
  • Support Annual Security Reviews and V&V activities.
  • Monitor systems to assess risk and recommend policy improvements.

Skills

Risk Management Framework (RMF)
Compliance monitoring
Patch management
Technical writing
Security documentation
Communication skills

Education

Bachelor's degree in Cybersecurity, IT, or related field

Tools

eMASS
STIGs
SCAP
ACAS

Job description

Description

We are seeking an experienced Information System Security Specialist II to support the security authorization, compliance, and continuous monitoring activities of mission-critical information systems. The successful candidate will create and maintain IA artifacts, support Authority to Operate (ATO) efforts using the Risk Management Framework (RMF), perform compliance scanning and patch management activities, and collaborate with system owners, ISSMs, and technical teams to ensure systems remain secure and compliant.

Key Responsibilities
  • Create, update, and maintain IA artifacts required to obtain and sustain favorable Authority to Operate (ATO) decisions.
  • Apply the Risk Management Framework (RMF) to support system accreditation and continuous monitoring activities.
  • Upload and maintain IA documentation and artifacts within eMASS.
  • Track, apply, test, and report STIG compliance using STIG checklists and Security Content Automation Protocol (SCAP) tools.
  • Document system management procedures, operating procedures, security concerns, and proposed solutions.
  • Support security readiness reviews and preparation of security checklists.
  • Provide software support for patching and compliance scanning activities.
  • Maintain software baselines to ensure IA compliance and perform monthly regressive compliance scanning, including ACAS scans and SCAP reporting.
  • Maintain records of applied patches and update associated documentation with software version information.
  • Anticipate and mitigate potential security risks affecting the software baseline.
  • Monitor and analyze systems and networks to assess risk and recommend policy improvements.
  • Coordinate hardware, software, and firmware changes with the ISSM and verify appropriate installation of security patches.
  • Document security concerns and remediation activities through whitepapers and Plans of Action & Milestones (POA&M).
  • Assist with Annual Security Reviews (ASRs) and Verification & Validation (V&V) activities.
  • Develop detailed test procedures and security configuration documentation in support of security test events.
  • Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary.
Requirements
  • 5 yrs experience supporting RMF-based ATO processes.
  • Hands‑on experience with eMASS, STIGs, SCAP, and ACAS.
  • Knowledge of DoD cybersecurity policies, standards, and best practices.
  • Experience with patch management, vulnerability scanning, and compliance reporting.
  • Strong technical writing skills, including experience developing security documentation and POA&Ms.
  • Ability to analyze security controls and recommend effective mitigation strategies.
  • Strong communication and collaboration skills.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
  • Must have or be able to obtain a CompTIA Security Plus certification prior to start date.
  • Ability to obtain and maintain a security clearance.
  • Must be a U.S. Citizen.
About TRISTAR

TRISTAR is an SBA certified Service‑Disabled Veteran‑Owned professional services company supporting the U.S. Department of War programs.

TRISTAR is proud to serve the Department of War and other Federal Agencies.

TRISTAR provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer II
Information Systems Security Engineer II

ARMADA, Ltd. • Philadelphia

On-site
USD 80,000 - 100,000
Information Systems Security Engineer II
Information Systems Security Engineer II

Armada LTD • Philadelphia

On-site
USD 90,000 - 120,000
Information System Security Specialist II
Information System Security Specialist II

DirectViz Solutions, LLC • Virginia Beach (VA)

On-site
USD 80,000 - 100,000
Competitive compensation
Comprehensive medical benefits
401(k) match
+2
Information Systems Security Specialist III
Information Systems Security Specialist III

TRISTAR • Crane (IN)

On-site
USD 80,000 - 100,000
Information Systems Security Engineer
Information Systems Security Engineer

Arenatechnologies • Alabama

On-site
USD 85,000 - 100,000
Competitive compensation
401k contribution
Collaborative work environment
Information Systems Security Engineer III
Information Systems Security Engineer III

ARMADA, Ltd. • Philadelphia

On-site
USD 90,000 - 110,000
Information System Security Manager I (ISSM I) (TS, w/ SCI Eligibility) -
Information System Security Manager I (ISSM I) (TS, w/ SCI Eligibility) -

Redtracetech • Lincoln (MA)

On-site
USD 90,000 - 120,000
401(k) plan
Annual performance bonus
Health Care Insurance (medical, dental, vision)
+1
Information System Security Manager (ISSM) (Engineer Info Assurance 3) - 28719
Information System Security Manager (ISSM) (Engineer Info Assurance 3) - 28719

Mission Technologies, a division of HII • Alexandria (VA)

On-site
USD 104,000 - 160,000
Best-in-class medical plans
401(k) savings plan
Tuition reimbursement
+2
Information Systems Security Manager (ISSM) II
Information Systems Security Manager (ISSM) II

TAC Integrated Solutions • Lincoln (MA)

On-site
USD 110,000 - 160,000
Information System Security Manager I (ISSM I) (TS, w/ SCI Eligibility)
Information System Security Manager I (ISSM I) (TS, w/ SCI Eligibility)

Redtracetech • Bedford (MA)

On-site
USD 100,000 - 130,000
Competitive salary
401(k) plan
Health Care Insurance
+2