Information System Security Officer II
Req: 26-J-0305
About the role
The ISSO is responsible for ensuring the appropriate operational security posture is maintained for an information system and, as such, works in close collaboration with the ISSM and ISO. The position requires detailed knowledge and expertise to manage the security aspects of an information system and is often responsible for the day-to-day security operations of a system. This includes physical and environmental protection, personnel security, incident handling, and security training and awareness. The role involves close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation, developing and updating authorization documentation, and implementing configuration management across authorization boundaries. The ISSO assesses the security impact of changes and makes recommendations to the ISSM.
The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD), and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities.
Responsibilities
- Develop physical or logical topologies for a system.
- Assist the ISSM in meeting their duties and responsibilities.
- Prepare, review, and update authorization packages.
- Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media.
- Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
- Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
- Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
- Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
- Ensure audit records are collected, reviewed, and documented (to include any anomalies).
- Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
- Execute the cyber security portion of the self-inspection, including providing security coordination and review of all system assessment plans.
- Identify cyber security vulnerabilities and assist with the implementation of countermeasures.
- Prepare reports on the status of security safeguards applied to computer systems.
- Perform ISSO duties in support of in-house and external customers.
- Conduct security impact analysis activities and provide findings to the ISSM on all configuration management changes to the authorization boundaries.
Requirements
- Bachelor’s degree or associate degree in a related area + 2 years’ experience OR equivalent experience (4 years).
- Current TS/SCI clearance as defined in ATTACHMENT VI.
- Eligibility for access to Special Access Program Information.
- Willingness to submit to a Counterintelligence polygraph.
- 2-5 years of related experience, especially in developing RMF packages or bodies of evidence.
- Prior performance in roles such as System/Network Administrator or ISSO.
- SAP experience.
- DoD 8570.01-M IAM Level II (in lieu of IAT Level II) certification.
- Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level II or Information Assurance Manager II within 6 months of hire.
- Must be able to regularly lift up to 50 lb.
Benefits
- Competitive compensation package.
- Generous PTO and flexible holiday package.
- Tax-free healthcare cost reimbursement.
- Immediate vesting 401K with 4% matching.