Information Systems Security Officer (ISSO)

MSI Defense Solutions

Mooresville (NC)

Hybrid

USD 110,000 - 160,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) with employer match
Dental Insurance
Health Insurance
Vision Insurance
Paid Time Off

Job summary

MSI Defense Solutions is seeking an Information Systems Security Officer (ISSO) to lead cybersecurity for classified and unclassified environments. The role focuses on RMF, NIST SP 800-53/171, CMMC, and maintaining ATO packages, with strong collaboration across IT, Security, Engineering, and government customers.

You will develop and maintain SSPs, assess readiness, and support continuous monitoring while ensuring secure configurations and incident response.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS or equivalent experience.
  • 5+ years in DoD/federal contractor cybersecurity.
  • Deep RMF, NIST SP 800-53/171, and CMMC knowledge.
  • Experience managing ATO packages and secured systems.
  • Strong documentation and writing skills.

Responsibilities

  • Lead ISSO duties for classified and unclassified systems.
  • Maintain RMF, NIST SP 800-53/171, and CMMC compliance.
  • Develop SSPs, POA&Ms, SARs, and RMF artifacts.
  • Manage GRC tools and evidence for audits.
  • Coordinate ATO/ATC and continuous monitoring.
  • Oversee vulnerability management and incident response.
  • Collaborate with IT, Engineering, Program teams and customers.
  • Prepare for audits and assessments (DCSA, CMMC).

Skills

RMF
NIST 800-53
NIST 800-171
CMMC Level 2
STIGs
ATO Packages
Microsoft 365 GCC High
Azure AD
Defender
Intune
SIEM
Documentation
Communication

Education

Bachelor's degree in Cybersecurity
Equivalent experience

Tools

Microsoft 365 GCC High
Azure Active Directory
Microsoft Defender
Intune
Endpoint security solutions
IntelliGRC

Job description

Position Overview

The Information Systems Security Officer (ISSO) is responsible for the security, compliance, and operational integrity of MSI Defense Solutions' information systems supporting both classified and unclassified environments. The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems comply with DoD Risk Management Framework (RMF), NIST SP 800-171, NIST SP 800-53, CMMC, and other applicable federal security requirements.

Position Overview

The Information Systems Security Officer (ISSO) is responsible for the security, compliance, and operational integrity of MSI Defense Solutions' information systems supporting both classified and unclassified environments. The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems comply with DoD Risk Management Framework (RMF), NIST SP 800-171, NIST SP 800-53, CMMC, and other applicable federal security requirements. This position is responsible for maintaining Authorization to Operate (ATO) packages, supporting security assessments, implementing continuous monitoring activities, and safeguarding Controlled Unclassified Information (CUI) and classified information. The ISSO partners closely with Information Technology, Security, Engineering, Program Management, and government customers to ensure cybersecurity requirements are integrated throughout the system lifecycle. The ISSO will report to the Digital Technology Manager. The position requires a full-time work week spent in the office or hybrid with 3 days onsite. Normal hours are Monday through Thursday 7:00am-4:30pm and Friday 7:00am - 12:00pm. (Must be flexible to work additional hours as needed based on project requirements and deadlines.)

Key Responsibilities
  • Serve as the Information Systems Security Officer (ISSO) for classified and unclassified information systems.
  • Maintain compliance with the DoD Risk Management Framework (RMF), NIST SP 800-53, NIST SP 800-171, CMMC, and applicable DoD cybersecurity policies.
  • Develop, maintain, and update System Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), and RMF documentation.
  • Administer and maintain the organization's Governance, Risk, and Compliance (GRC) platform (e.g., IntelliGRC), ensuring security documentation, evidence, POA&Ms, and assessment artifacts remain current and audit ready.
  • Support Authorization to Operate (ATO), Authority to Connect (ATC), and continuous monitoring activities.
  • Ensure implementation and maintenance of required security controls across enterprise systems.
  • Conduct vulnerability assessments, security audits, and remediation tracking.
  • Coordinate vulnerability scanning, patch management, and secure system configuration.
  • Investigate, document, and coordinate cybersecurity incident response activities.
  • Administer user access controls and privileged account management in accordance with least privilege principles.
  • Ensure compliance with security requirements for classified systems and secure facilities.
  • Lead the preparation for internal audits, DCSA assessments, customer inspections, and CMMC assessments including evidence collection, artifact management, and assessor coordination.
  • Collaborate with IT, Engineering, and Program teams to integrate cybersecurity throughout project execution.
  • Develop and maintain cybersecurity policies, procedures, and user awareness initiatives.
  • Support secure implementation of Microsoft 365 GCC High, Azure, Microsoft Defender, Intune, and related security technologies.
  • Serve as the primary cybersecurity liaison for government customers and external auditors.
  • Monitor compliance status, track remediation activities, and provide regular reporting on cybersecurity posture and outstanding compliance actions to leadership.
Skills And Qualifications Required
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
  • 5+ years of cybersecurity, information assurance, or information systems security experience within a DoD or federal contractor environment.
  • Strong knowledge of:
    • DoD Risk Management Framework (RMF)
    • NIST SP 800-53
    • NIST SP 800-171
    • CMMC Level 2
    • STIG implementation
  • Experience managing Authorization to Operate (ATO) packages.
  • Experience supporting classified information systems.
  • Experience administering Microsoft 365 GCC High, Azure Active Directory, Microsoft Defender, Intune, and endpoint security solutions.
  • Experience conducting vulnerability management and remediation.
  • Familiarity with SIEM solutions and continuous monitoring tools.
  • Excellent documentation and technical writing skills.
  • Strong communication and collaboration skills.
Preferred Qualifications
  • Experience supporting CMMC Level 2 environments or similar regulated environments
  • Familiarity with tools such as Microsoft Defender, SIEM platforms, and compliance tools (e.g., IntelliGRC)
  • Relevant certifications (Security+, CySA+, CISSP, or similar)
  • Experience with audit preparation and evidence collection
Security Requirements
  • U.S. Citizenship is required.
  • An active Secret security clearance is required.
  • Must be able to maintain eligibility for access to classified information.
Physical Requirements
  • Prolonged periods sitting at a desk and working on a computer
  • Must be able to lift up to 30 pounds at times.
  • Must be able to access and navigate each department at the organization's facilities.
The MSI Operating Code

Every employee at MSI is expected to operate in accordance with the MSI Operating Code. These seven principles define how we think, decide, and execute. They are not aspirational. They are the working standard by which all employees are evaluated.

The Seven Principles
  • Own It. If a problem touches your function, it is yours until it is solved or explicitly transferred. Do not wait. Do not delegate upward. Do not hide behind process. Ownership means driving to resolution, not monitoring status.
  • Kill the Wrong Fight. Before optimizing a solution, question whether the problem is yours to solve. If an opportunity requires MSI to become something we are not, kill it fast. The discipline to say no is what protects our ability to say yes to the right things.
  • Move Before You're Told. Speed is MSI's compounding advantage. We move when directionally correct and adjust in motion. Leaders who wait for permission are not leading. We would rather correct a fast decision than wait for a perfect one.
  • Solve Before You Contract. Prove the integration works before formalizing the relationship. Capability first, paperwork follows. Working capability is the strongest negotiating position and the most honest form of business development.
  • Integrate First. MSI's moat is not any single technology. It is the ability to integrate modular systems faster and more effectively than anyone else. Every decision should reinforce our position as the integration hub.
  • Say It Now. Silence is not alignment. If you disagree, say so, with data, with reasoning, and with an alternative path. Passive execution is institutional risk.
  • Build Beyond Yourself. If your function depends on your presence to operate, you have not built anything. Develop your people. Document your processes. Create depth that survives your absence.
Benefits
  • 401(k) with employer match
  • Dental Insurance
  • Disability Insurance
  • Health Insurance
  • Vision Insurance
  • Paid Parental and Maternity Leave
  • Life Insurance
  • Paid Time Off - 120 hours per year to start (prorated in first year of employment)
  • Continuing Education
  • Annual Year End Paid Holiday Closure
Classification
  • Position is full-time, Exempt

MSI Defense Solutions is an Equal Opportunity/Affirmative Action Employer. We recruit, hire, train, promote, and compensate employees based on merit, qualifications, and business needs. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable federal, state, or local law, including race, color, religion, sex (including pregnancy, sexual orientation, and gender identity), national origin, age, disability, genetic information, protected veteran status, or any other legally protected status. MSI Defense Solutions is committed to fostering a workplace free from discrimination, harassment, and retaliation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Msidefensesolutions • Mooresville (NC)

Hybrid
USD 110,000 - 170,000
401(k) with employer match
Dental Insurance
Health Insurance
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Msidefensesolutions • Mooresville (NC)

Hybrid
USD 110,000 - 150,000
401(k) with employer match
Health Insurance
Dental Insurance
+3
Information Systems Security Administrator (ISSA)
Information Systems Security Administrator (ISSA)

MSI Defense Solutions • Mooresville (NC)

Hybrid
USD 70,000 - 90,000
401(k) with employer match
Health Insurance
Paid Time Off - 120 hours per year
Information Systems Security Manager ISSM
Information Systems Security Manager ISSM

Kms-Solutions,-LL • Alexandria (VA)

On-site
USD 130,000 - 160,000
Medical insurance
401k / retirement savings plan
Paid time off (PTO)
+3
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

IPSECURE, INC. • Satellite Beach (FL)

On-site
USD 110,000 - 160,000
Medical insurance
Dental & Vision coverage
401(k) retirement plan
+2
Information System Security Officer
Information System Security Officer

Cymertek Corporation • Reston (VA)

On-site
USD 120,000 - 150,000
Excellent Salaries
Flexible Work Schedule
Medical/Dental/Vision - 100% employee
+1
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Kratos Defense and Security Solutions • Glen Burnie (MD)

On-site
USD 140,000 - 190,000
Medical, Dental & Vision Insurance
401(k) Savings Plan
Employee Stock Purchase Plan (ESPP)
+3
Information System Security Officer
Information System Security Officer

Cymertek Corporation • San Antonio (TX)

On-site
USD 110,000 - 150,000
Excellent Salaries
Flexible Work Schedule
401k Matching
+2
Information Systems Security Officer
Information Systems Security Officer

CSCI Consulting • Illinois

On-site
USD 110,000 - 160,000
Competitive salary
PTO
Federal holidays aligned to calendar
+4
Information System Security Officer
Information System Security Officer

Cymertek Corporation • Honolulu (HI)

On-site
USD 110,000 - 165,000
Excellent Salaries
Flexible Work Schedule
Cafeteria Style Benefits
+1