ISSO, Mid-Level

UIC Arctic Response Services, LLC

Lompoc (CA)

On-site

USD 140,000 - 160,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bowhead is seeking a Mid-Level ISSO for a 3‑month assignment at Vandenberg SFB. You will implement RMF controls, develop documentation, and support audits across collateral, SCI, and SAP environments.

The role requires DoD RMF expertise, familiarity with eMASS/Xacta/ACAS, and coordination with multiple stakeholders to ensure continuous authorization and readiness for inspections.

Qualifications

  • Minimum 2–5 years supporting RMF for DoD systems.
  • Bachelor’s degree in Cybersecurity, CS, IS, or equivalent.
  • Must meet DoD 8140 requirements for ISSM role within six months.
  • Familiar with RMF tools such as eMASS, Xacta, ACAS.
  • Strong knowledge of COMPUSEC and TEMPEST policies.

Responsibilities

  • Assist in RMF A&A package preparation and maintenance.
  • Develop and maintain SSPs, procedures, diagrams, and POA&Ms.
  • Track authorization timelines to maintain ATO/IATT.
  • Conduct vulnerability scans and test controls for continuous monitoring.
  • Maintain audit logs, access control lists, and incident reports.
  • Report POA&M items and document risk acceptance when applicable.
  • Support CCRIs, SAVs, and inspections; ensure readiness.
  • Coordinate with admins to maintain baselines and STIG compliance.
  • Perform security risk assessments for changes and deployments.
  • Deliver system-specific security briefings and user guides.
  • Support incident detection, triage, and response with CSSP/ISSM.

Skills

RMF
A&A
SSP documentation
POA&Ms
Vulnerability monitoring
COMPUSEC
TEMPEST
NIST SP 800-53
STIG
RMF tools knowledge

Education

Bachelor’s degree in Cybersecurity/Computer Science/Information Systems

Tools

eMASS
Xacta
ACAS

Job description

Overview

Delta Solutions and StrategiesBowhead is seeking a Mid-Level ISSO for our team at Vandenberg SFB.

This is a temporary role, expected to last around 3 months but could change based on the contract requirements.

The Information Systems Security Officer (ISSO) is responsible for implementing, maintaining, and continuously improving cybersecurity controls for assigned information systems in accordance with DoD, Air Force, and NIST Risk Management Framework (RMF) requirements. The ISSO ensures that all systems remain secure, compliant, and operational across all classification levels through proactive management of security artifacts, RMF authorization support, and ongoing vulnerability and compliance monitoring. In addition to RMF responsibilities, the ISSO performs Communications Security (COMPUSEC) and TEMPEST functions, including emission security evaluations, classified processing compliance, and controlled media handling. This position is critical to ensuring S4S maintains a secure cyber environment, sustained authorization, and readiness for audits and inspections.

The position provides day-to-day cybersecurity and information assurance support for Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) environments.

Responsibilities
  • Assist in the preparation, submission, and maintenance of RMF Authorization packages (Assessment & Authorization – A&A) for S4S systems.
  • Develop and maintain all required cybersecurity documentation, to include System Security Plans (SSPs), procedures, diagrams, Plans of Action and Milestones (POA&Ms), and associated body-of-evidence artifacts.
  • Track and manage system authorization timelines and accreditation status to ensure uninterrupted Authority to Operate (ATO) or Interim Authorization to Test (IATT).
  • Conduct, document, and report results of cybersecurity self-inspections, vulnerability scans, and control tests to support continuous monitoring requirements.
  • Maintain and update audit logs, system access control lists, and incident reports in accordance with DoD and Air Force cybersecurity policy.
  • Track and report POA&M items, ensuring timely remediation of vulnerabilities and documentation of risk acceptance where applicable.
  • Maintain inspection readiness and provide direct support to cybersecurity inspections, Command Cyber Readiness Inspections (CCRIs), and Staff Assistance Visits (SAVs).
  • Ensure implementation and enforcement of administrative, procedural, and technical security controls in accordance with NIST SP 800-53 and related DoD guidance.
  • Coordinate with system administrators to maintain secure system baselines, verify proper patching, and validate STIG compliance.
  • Perform security risk assessments for system modifications, upgrades, integrations, and software deployments.
  • Assist in developing and delivering system-specific security briefings, user guides, and operational best practices to authorized users.
  • Support cybersecurity incident detection, triage, and response efforts in coordination with the Cybersecurity Service Provider (CSSP) and the Information System Security Manager (ISSM).
  • Prepare risk reports, status updates, and leadership briefings summarizing system cyber health, compliance metrics, and residual risk posture.
  • Liaise between system owners, administrators, cybersecurity teams, and external assessors to ensure consistent understanding and application of RMF controls.
  • Integrate cybersecurity considerations into system engineering, sustainment, and lifecycle management activities.
  • Represent cybersecurity equities during design reviews, planning boards, and operational or acquisition meetings.
  • Ensure systems and networks are operated, maintained, and disposed of in accordance with applicable cybersecurity and records management policies.
  • Ensure all system users complete required initial, recurring, and role-based cybersecurity training.
  • Conduct face-to-face or virtual security training and awareness sessions, documenting attendance and compliance.
  • Report, investigate, and document cybersecurity incidents in accordance with established incident response procedures.
  • Ensure compliance with COMPUSEC policies, including media marking, transfer, encryption, and destruction procedures.
  • Conduct TEMPEST risk assessments, ensuring compliance with DoD emission security policies and facility accreditations.
  • Coordinate or conduct TEMPEST inspections of facilities, equipment, and cabling to ensure compliance with CTTA-issued standards.
  • Maintain TEMPEST accreditation packages and verify that mitigation controls are implemented for identified vulnerabilities.
  • Liaise with Certified TEMPEST Technical Authorities (CTTAs) and ensure compliance with all emission security and classified processing requirements.
  • Support cybersecurity contingency planning, including exercises and real-world event response activities.
  • Support users and assist with the coordination and completion of paperwork required to resolve negligent discharge of classified information incidents and events.
  • Provide after-hours support as required to maintain system availability, mission continuity, and cyber defense posture.
  • Other duties as assigned.
Qualifications
  • Minimum of 2–5 years of related experience supporting RMF authorization packages, continuous monitoring, and cybersecurity compliance for DoD systems.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field; or equivalent combination of education and experience (4 years).
  • Must meet position and certification requirements outlined in DoD 8140 for the Information System Security Manager role (Intermediate Level) within six months of hire.
  • Must be familiar with RMF tools and workflows such as eMASS, Xacta, and ACAS.
  • Must possess a strong understanding of COMPUSEC and TEMPEST policies, DoDI 8500.01, CNSSI 1253, and related DoD guidance.
  • Ability to coordinate with multiple stakeholders to ensure cyber readiness across Collateral, SCI, and SAP environments.
  • Ability to provide surge and after-hours support during inspections, exercises, or real-world cyber events.
Physical Demands

Must be able to lift up to 50 poundsMust be able to stand and walk for prolonged amounts of timeMust be able to twist, bend and squat periodically

SECURITY CLEARANCE REQUIREMENTS

Must currently hold an active TS/SCI clearance.

Targeted salary range is $140,000 to $160,000 annually based on qualifications and experience.

Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.

#LI-MN1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering • Maryland

On-site
USD 110,000 - 145,000
11 paid holidays
3 weeks PTO
Group medical plan
1772 - Information System Security Officer
1772 - Information System Security Officer

Sigma Defense • March Air Reserve Base (CA)

On-site
USD 118,000 - 138,000
Dental Insurance
Vision Insurance
Medical Insurance with HSA/FSAs/DFSA
+6
ME00620-ISSO 1
ME00620-ISSO 1

Rippling, Inc. • Annapolis (MD)

Hybrid
USD 120,000 - 165,000
11 paid holidays
3 weeks PTO
Group medical plan
+2
1772 - Information System Security Officer
1772 - Information System Security Officer

Sigma Defense • California (MO), Northern (KY)

Hybrid
USD 118,000 - 138,000
Dental & Vision Insurance
Medical Insurance with HSA/FSA/DFSA
Life and AD&D
+5
1772 - Information System Security Officer
1772 - Information System Security Officer

Sigma-Defense • March Air Reserve Base (CA)

On-site
USD 118,000 - 138,000
Dental and Vision Insurance
Medical Insurance (HSA/FSA/DFSA)
Life and AD&D coverage
+5
1772 - Information System Security Officer
1772 - Information System Security Officer

Sigma Defense Systems • March Air Reserve Base (CA)

On-site
USD 118,000 - 138,000
Dental and Vision Insurance
Medical Insurance with HSA/FSA/DFSA
401(k) with company matching
ME00679-ISSO 1
ME00679-ISSO 1

Rippling, Inc. • Annapolis (MD)

On-site
USD 120,000 - 180,000
11 paid holidays
PTO (minimum 3 weeks)
Company sponsored group medical plan
+4
Information Systems Security Officer (ISSO) III (TS, with SCI Eligibility)
Information Systems Security Officer (ISSO) III (TS, with SCI Eligibility)

Redtracetech • Northern (KY)

On-site
USD 140,000 - 155,000
Competitive salary
401(k) plan
Annual performance bonus
+6
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Saalex • Camarillo (CA)

On-site
USD 145,000 - 180,000
Health care plan
Retirement plan
Life insurance
+5
Information Systems Security Officer (ISSO) III - SIGN-ON BONUS UP TO $10,000
Information Systems Security Officer (ISSO) III - SIGN-ON BONUS UP TO $10,000

General Dynamics - IT • Bedford (MA)

On-site
USD 120,000 - 160,000
Sign-on bonus up to $10,000