Information System Security Officer (ISSO)
FEDITC, LLC is a fast-growing business supporting DoD and other intelligence agencies worldwide. We develop mission-critical national security systems directly supporting the Warfighter, DoD Leadership, and the country.
About the role
The Information System Security Officer (ISSO) serves as the principal advisor to the Information System Owner (SO), Business Process Owner, and the Chief Information Security Officer (CISO) / Information System Security Manager (ISSM) on all matters involving the security of an information system. ISSOs are responsible for ensuring the implementation and maintenance of security controls in accordance with the Security Plan (SP) and Department of Defense (DoD) policies. ISSOs provide guidance, oversight, and expertise but may not develop security documents or implement controls directly. They coordinate, facilitate, or ensure activities are performed, requiring strong relationships with the SO, technical staff, and other stakeholders.
This position is located in Warren, MI. A United States Citizenship and an active Secret DoD Security Clearance are required.
Responsibilities
- Coordinates with the Information System Owner (ISO) to ensure the appropriate operations security posture is maintained for the information system.
- Serves as principal advisor on all matters involving the security of an information system.
- Manages day-to-day security operations of the system.
- Monitors information system and environment.
- Manages and controls changes to the system.
- Handles security incidents.
- Assists in the development of:
- Security policies and procedures.
- System Security Plan and its ongoing maintenance.
- Security Impact Analysis.
- Understanding of mission and business functions of the information system.
- Understands how the system supports the organization’s mission, including:
- System architecture and components (hardware, software, peripherals, etc.).
- Location of each system component.
- Data flow and interconnections (internal and external).
- Security categorization and requirements.
- Configuration management processes and procedures.
Requirements
- Two or more years of proven Governance, Risk, and Compliance (GRC) experience or related role.
- Strong knowledge of security principles, practices, and technologies.
- Experience with security assessment tools and techniques.
- Excellent problem-solving and analytical skills.
- DoD/Military Training: 531-25B30-C45, J-3B-0440, DAU ISSM Basic Playlist, RMF Implementers Course, or equivalent.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Data Science, Software Engineering, or Information Technology (from an ABET-accredited or NCAE-C-designated institution).
Qualifications
- Must have one of the following certifications: CompTIA Security+, CASP+, CISM, CISSP, CCISO, CCSP, CGRC/CAP, Cloud+, GSEC, SSCP, CISSO, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GCSA, GISCP, GSLC.
- Active Secret clearance is required.
- Must be a U.S. Citizen and pass a background check.
- Maintain applicable security clearance(s) and certification(s) as required by FEDITC and/or its clients.