Information System Security Officer, (ISSO)
Position Summary
The Information System Security Officer (ISSO) provides senior-level cybersecurity engineering and compliance support to the Defense Information Systems Agency (DISA) Internet Enterprise (IE) under the CTAS Task Order. This role ensures mission systems achieve and sustain Authorization to Operate (ATO) through implementation of the Risk Management Framework (RMF) and transition from legacy DIACAP requirements.
Key Responsibilities
Leading the development, maintenance, and validation of RMF and A&A artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), configuration management records, and testing documentation.
Implementing and validating compliance with DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to maintain technical baselines across supported systems.
Managing and analyzing results from vulnerability scanning and compliance tools such as ACAS, HBSS, and CMRS, and ensuring timely remediation of findings in accordance with IAVM directives.
Preparing and submitting comprehensive accreditation packages in eMASS, ensuring accuracy, completeness, and timeliness of submissions to meet contract and PWS requirements.
Conducting and documenting Security Test and Evaluation (ST&E) activities, ensuring objective assessment of control implementation and risk posture.
Serving as a senior-level resource, providing mentorship to mid-level and junior ISSOs, while interfacing with Government stakeholders, Information System Security Managers (ISSMs), and Authorizing Officials (AOs).
Required Qualifications
A bachelor’s degree in Cybersecurity, Information Technology, or related field.
Must hold and maintain an appropriate DoD 8140.03 / 8570.01-M certification baseline for this labor category (e.g., Security+, CISSP, CISM, or equivalent as required).
At least 7 years of experience in cybersecurity engineering, RMF/DIACAP accreditation, and compliance documentation in DoD environments.
Expertise in the application of DISA STIGs/SRGs, ACAS/HBSS vulnerability analysis, and eMASS package preparation.
Strong written and verbal communication skills, with demonstrated experience producing accreditation documentation and presenting risk findings to senior stakeholders.
Desired Qualifications
A master’s degree in Cybersecurity or related discipline.
Experience supporting DISA programs and preparing for CCRI inspections.
Advanced certifications such as CISSP-ISSAP or CISM.
Clearance Requirement
Active Top Secret
Benefits
Complete Insurance Coverage
Blue Cross Medical, Delta Dental, Vision
Life
Tuition Reimbursement
Generous Paid Time Off (including your birthday!)