Information Systems Security Officer (ISSO) - Senior

Astrion

Boulder (CO)

On-site

USD 102,000 - 138,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Astrion is seeking a Senior Information Systems Security Officer (ISSO) to support Space Systems Command activities in Boulder, CO. This role emphasizes creating A&A documentation, SSPs, and security controls to support Authorization to Operate decisions in a TS/SCI environment.

You will work with the ISSM across domains, applying RMF, STIGs, and cloud security practices to safeguard critical intelligence systems and data, enabling mission success.

Qualifications

  • Bachelor's degree in engineering or related technical field is required.
  • 10+ years of ISSO experience with A&A documentation and SSPs.
  • Valid Security+ CE certification and DoD 8570.01-M Level II requirements.
  • Cloud design and security experience is highly desirable.
  • IAM Level II certification is highly desirable.

Responsibilities

  • Ensure cybersecurity architecture is functional and secure across domains.
  • Develop and sustain RMF accreditation packages from concept to ATO.
  • Develop and sustain cloud environments and related security controls.
  • Provide IS security operations support and technical assessments.
  • Apply STIG best practices to classified and unclassified systems.
  • Interface with government customers and approving authorities.
  • Perform vulnerability/risk analysis to support ATO decisions.
  • Prepare SSPs, Risk Assessments, ATO packages, and SCTMs.
  • Conduct periodic IS policy reviews and IS security inspections.

Skills

ISSO experience
A&A documentation
RMF accreditation

Education

Bachelor's degree in engineering or related technical field

Job description

Senior Information Systems Security Officer (ISSO)

LOCATION: Boulder ColoradoSTATUS:Full-TimeCLEARANCE: TS/SCI clearance

SALARY: 120,000 +annually*

*depending on experience, certifications, and qualifications

Astrion is currently seeking a Senior Information Systems Security Officer (ISSO) to supportSpace Systems Command(SSC), Space Sensing Tools Application & Processing (TAP) Lab in Boulder, CO and integration support to the Overhead Persistent Infrared (OPIR) Battlespace Awareness Center (OBAC) at Buckley SFB, Aurora, Colorado.

Work with Information Systems Security Manager (ISSM) to create and maintain Assessment and Authorization (A&A) documentation, including the system security plan, security control assessment, plan of action and milestones to support Authorization to Operate decisions. Capture and refine information security requirement for new systems or for enhanced functionality on existing systems. Provide support for proposing, coordinating, implementing and enforcing information systems security policies, standards and methodologies. Your talents, perspectives, and efforts will contribute directly to the safeguarding of valuable intelligence systems and data, ensuring positive mission outcomes. This position is located in Boulder, Colorado and requires level of effort across multiple domains and security levels.

REQUIRED QUALIFICATIONS / SKILLS

  • Education: Bachelor's degree in engineering or related technical field (Required).
  • Experience: 10+ years of experience working Information Systems Security Officer (ISSO) and creating and maintain Assessment and Authorization (A&A) documentation, including the system security plan, security control assessment, plan of action and milestones to support Authorization to Operate decisions. (Required)
  • Valid Security+ CE Certification. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technical Level 2. (Required)
  • Cloud design and security experience. Highly Desired.
  • Cyber Workforce Management Program (DoDD 8140.01 & DoD 8570.01-m) Information Assurance Management (IAM) Level II certified. Highly Desired
  • Demonstrated understanding of Cybersecurity Service Provider (CSSP) and DCO operations and tools. Desired
  • Familiarity with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and system configuration validation and verification against documented security requirements. Desired
  • Familiarity with cloud-based systems, operating systems, databases, networking, firewalls, Network Intrusion Detection and Prevention Systems (IDS/IPS) and host-based IDS and IPS. Desired
  • Familiarity with Program Security responsibilities to include but not limited to: OPSEC, Program. Protection, Personnel Security clearances, Security Training and Education, Classification management. Desired

RESPONSIBILITIES

  • Ensuring the cybersecurity architecture and design of the customer’s systems are functional and secure with the ability to identify, protect, detect, respond and recover from cyber-attack
  • Developing and sustaining enterprise RMF accreditation packages, from concept development and contract pre-acquisition through contractor design and accreditation
  • Experience in Developing and Sustaining Cloud environments from concept development and contract pre-acquisition through contractor design and accreditation
  • Providing Information System Security Operations support, integration services, technical assessments, and solutions to enable cybersecurity and DCO
  • Applies a combination of expert engineering knowledge of security solutions to design, develop and/or implement solutions to ensure they are consistent with enterprise architecture security policies and support full spectrum military cyberspace operations
  • Overseeing system and network designs that encompass multiple computer and network devices to include those with differing data protections/classification requirements
  • Developing Defensive Cyberspace Operations and incident Response Tactics, Techniques and Procedures to monitor and protect the system from cyber-attacks
  • Apply Secure Technical Implementation Guide (STIG) best practices to classified and unclassified information systems, networking equipment, and applicable software/applications
  • Information Security interface to government customer and approving authorities across the DoD and Intelligence Communities
  • Perform vulnerability/risk assessment analysis to support authorization and accreditation
  • Prepare and review documentation to include System Security Plans (SSPs), Risk Assessment Reports, Authorization To Operate (ATO) packages, policies and Security Controls Traceability Matrices (SCTMs)
  • Conduct periodic reviews and evaluations of required IS policies and procedures
  • Support IS Security Inspections, tests, and reviews

#CJ

CJ#

Get your free, confidential resume review.
or drag and drop your file here.