ISSO- MID-LEVEL

Quantum Research International Inc

Huntsville (AL)

On-site

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Quantum Research International, Inc. seeks an experienced cyber-cloud Information System Security Officer (ISSO) to support an Army ECMA program. The mid-level ISSO will maintain the system's security posture, participate in CCB meetings, and ensure compliance with RMF and DoD standards.

On-site in Huntsville, AL. The role requires DoD RMF expertise, 4+ years ISSO/ISSE experience, and active or eligible SCI considerations. U.S.

Qualifications

  • Bachelor's degree in CS/IS or 5+ years of related work experience.
  • 4+ years of verifiable ISSO/ISSE experience.
  • Knowledge of DoD 8510 and NIST 800-53 RMF implementation.
  • DoD 8140 compliance with DCWF Code 722; Security+ CE or equivalent.
  • Clearance: US Citizenship and eligibility for SCI designation.
  • Knowledge of DISA eMASS.

Responsibilities

  • Develop and maintain ATO documentation including CMP, AMP, ISCP, IRP, BIA, PIA, SSP, and CONOPS.
  • Identify applicable STIGs and SRGs for technologies in the IS.
  • Coordinate with government SO/ISSM to ensure ATO conditions.
  • Advise the program on IS security requirements per RMF and NIST/DISA.
  • Provide security design guidance across RMF phases to meet controls.
  • Oversee daily security operations: logs, vulnerabilities, remediation.
  • Act as CM facilitator and voting CCB member for security changes.
  • Prepare SIAs for SCRs to support CCB review and decisions.
  • Annual account reviews and approvals for general/privileged users.
  • Review security assessments and plan mitigations with ACAS/Nessus/SCAP data.
  • Serve as IS primary POC with Security Control Assessor (SCA).
  • Create and maintain POA&M items in eMASS.

Skills

BS/ISSO experience
ISSO/ISSE
RMF/NIST 800-53
DoD 8140/DCWF
Security+ / equivalent
AWS/Azure

Education

Bachelor of Science in CS/IS

Tools

eMASS
ACAS
Nessus
SCAP

Job description

Overview:

Quantum Research International, Inc (Quantum) provides our national defense and federal civilian and industry customers with services and products in the following main areas: 1) Cybersecurity and Information Operations; 2) Space Operations and Control; 3) Aviation Systems; 4) Ground, Air and Missile Defense, and Fires Support Systems; 5) Intelligence Programs Support; 6) Experimentation and Test; 7) Program Management; and (8) Audio/Visual Technology Applications. Quantum's Corporate Office is located in Huntsville, AL, but Quantum actively hires for positions nationwide and internationally. We pride ourselves on providing high quality support to the U.S. Government and our Nation's Warfighters. In addition to our corporate office, we have physical locations in Aberdeen, MD; Colorado Springs, CO; Crestview, FL; Orlando , FL and Tupelo, MS.

Mission:

Quantum Research is seeking an experienced cyber-cloud Information System Security Officer (ISSO) to support an Army Program maintained within the Army's Enterprise Cloud Management Agency (ECMA). The mid-level ISSO will be responsible for maintaining the system's overall security posture IAW DoD RMF requirements. This role includes facilitating and participating in Configuration Control Board (CCB) meetings, evaluate proposed system and architecture changes to confirm security baselines are maintained through approved change management processes, and executing continuous monitoring activities such as reviewing system audits logs, general/privileged user account reviews, RMF documentation creation/maintenance, vulnerability response (CTOs/IAVAs), Information System Contingency Plan (ISCP) Table-Top exercises, and security control artifact development. The ISSO will maintain oversight of configuration management, security scanning and remediation activities, manage the Plan of Action and Milestones (POA&M), and provide cybersecurity guidance to infrastructure team members and on-site personnel to ensure compliance and risk reduction..

Job Responsibilities
  • Develop and maintain ATO related documentation to include Configuration Management Plan (CMP), Account Management Plan (AMP), Information System Contingency Plan (ISCP), Incident Response Plan (IRP), Business Impact Analysis (BIA), Privacy Impact Analysis (PIA), System Security Plan (SSP), and Concept of Operations (CONOPS).
  • Identify the correct applicable Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) for technologies used within the Information System (IS).
  • Communicate and coordinate with the government System Owner (SO) and/or government ISSM to ensure the system operates within the conditions of the established ATO.
  • Advise the program on IS security requirements, ensuring alignment with RMF, applicable NIST Guidelines/Standards, and DISA STIG/SRG compliance.
  • Provide security design guidance and analysis to project stakeholders across all RMF phases to ensure alignment with security control requirements.
  • Oversee daily system security operations by monitoring control effectiveness, validating access controls, reviewing security audit logs, tracking vulnerabilities, responding to CTOs/IAVAs within government customer's SharePoint site, and coordinating remediation efforts to maintain an acceptable security posture.
  • Act as the Configuration Management (CM) facilitator and voting CCB member, overseeing change control processes and participating in formal decision-making for system modifications affecting security posture and compliance.
  • Prepare Security Impact Assessments (SIAs) for all System Change Requests (SCRs) to support Configuration Control Board (CCB) review and decision-making.
  • Perform annual account reviews and approve all general and privileged user account requests prior to creation, ensuring proper authorization, access justification, and compliance IAW approved policies and procedures.
  • Review technical security assessments, analyze vulnerabilities, and risk data using ACAS, Nessus, and SCAP scan results to identify system vulnerabilities, non-compliance, and appropriate mitigation strategies.
  • Serve as the IS primary POC when communicating with the Security Control Assessor (SCA).
  • Create and maintain Plan of Action and Milestone (POA&M) items within eMASS
Required Skills and Qualifications
  • Minimum of a Bachelor of Science (BS) degree in Computer Science, Information Systems or five (5) years of comparable work experience
  • 4 years of verifiable ISSO/ISSE experience
  • Knowledge and practical experience of DoD 8510 and NIST 800-53 Risk Management Framework implementation
  • Candidate must be compliant with DoD 8140; DoD Cyber Workforce Framework (DCWF) Code 722, Information System Security Manager, at the intermediate level. Requires CompTIA Security+ CE or other training and education requirements as identified in DoDM 8140.03
  • Fundamental knowledge of DISA Enterprise Mission Assurance Support Service (eMASS)
  • US Citizen is required for Active Top Secret Clearance. Must be capable/eligible of obtaining a SCI designation.
  • Applicable Certifications include but are not limited to any of the following: Security+, CISSP, AWS/Azure
Desired Skills and Qualifications
  • Broad experience with a variety of enterprise computing infrastructure and public and private computing technologies.
  • Experience with modern application architecture, design, development, and deployment processes.
  • Self-starter with the ability to independently identify, prioritize, and execute required tasks
  • SC2 CISSP Certification
  • AWS/Azure experience

Note: This position is part of Quantum Research Intl 's CAOC (Computing Architecture Operations Center) and is an onsite position in Huntsville, AL

#LI-JL1, #LI-Onsite

Equal Opportunity Employer/Affirmative Action Employer M/F/D/V:

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity, or any other characteristic protected by law. *Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ISSO (MID-LEVEL)
ISSO (MID-LEVEL)

Quantum Research International • Huntsville (AL)

On-site
USD 90,000 - 120,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 110,000 - 140,000
Senior Information System Security Officer
Senior Information System Security Officer

Quantum Sky • Washington

Hybrid
USD 120,000 - 130,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Fort Cavazos Motorcycle and POV Campus (TX)

On-site
USD 155,000 - 180,000
PTO
11 Paid Holidays
401(k) Matching
+3
Information Systems Security Officer (ISSO), Mid
Information Systems Security Officer (ISSO), Mid

Quantum Sky • Washington

On-site
USD 105,000 - 125,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Que Technology Group • Fort Meade (MD)

On-site
USD 140,000 - 190,000
Competitive salary
Company Medical/Dental/Vision plans –
Vacation / Personal days 25 days/year
+2
ME00620-ISSO 1
ME00620-ISSO 1

Rippling, Inc. • Maryland

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Group medical plan
+4
ME00620-ISSO 1
ME00620-ISSO 1

Rippling, Inc. • Annapolis (MD)

Hybrid
USD 120,000 - 165,000
11 paid holidays
3 weeks PTO
Group medical plan
+2
ISSO - Information Systems Security Officer
ISSO - Information Systems Security Officer

TECHFORGE Solutions • Dayton (OH)

On-site
USD 85,000 - 115,000
ME00679-ISSO 1
ME00679-ISSO 1

Rippling, Inc. • Annapolis (MD)

On-site
USD 120,000 - 180,000
11 paid holidays
PTO (minimum 3 weeks)
Company sponsored group medical plan
+4