Information System Security Officer (ISSO) II
The Amatriot Group · Warren AFB, WY · 1 wk ago
On-site$106k–$107k/yrFull-time
Position Overview
The Information System Security Officer (ISSO) is responsible for maintaining the appropriate operational security posture of an information system and works closely with the ISSM and ISO. The ISSO manages the security aspects of an information system and, in many organizations, is responsible for the system's day-to-day security operations. The position supports Special Access Programs (SAPs) for Department of Defense (DoD) agencies, including HQ Air Force, Office of the Secretary of Defense (OSD), and Military Compartments efforts. The position provides day-to-day support for Collateral, Sensitive Compartmented Information (SCI), and SAP activities.
Responsibilities
- Assist the ISSM in meeting duties and responsibilities.
- Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
- Monitor information systems and their environments of operation in coordination with the ISSM and ISO.
- Ensure all information system security-related documentation is current and accessible to properly authorized individuals.
- Prepare reports on the status of security safeguards applied to computer systems.
- Perform ISSO duties in support of in-house and external customers.
- Prepare, review, and update authorization packages.
- Develop and update authorization documentation.
- Notify the ISSM of changes that may affect the authorization determination of information systems.
- Conduct security impact analysis activities for configuration management changes to authorization boundaries and provide the results to the ISSM.
- Coordinate changes or modifications to system hardware, software, or firmware with the ISSM and AO/DAO before implementation.
- Assess the security impact of configuration changes and make recommendations to the ISSM.
- Execute the cybersecurity portion of the self-inspection, including providing security coordination and reviewing all system assessment plans.
- Implement configuration management across authorization boundaries.
- Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
- Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media.
- Ensure audit records are collected, reviewed, and documented, including anomalies.
- Identify cybersecurity vulnerabilities and assist with implementing countermeasures.
- Support physical and environmental protection, personnel security, incident handling, and security training and awareness.
- Attend required technical and security training, including operating system, networking, and security management training, relative to assigned duties.
Qualifications
- Bachelor's degree or 4 years of additional experience in lieu of degree. [Required]
- 2–5 years of related experience, especially in developing Risk Management Framework (RMF) packages or bodies of evidence. [Required]
- Prior performance in roles such as System/Network Administrator or ISSO. [Required]
- SAP experience. [Required]
- IAT Level II or IAM Level II certification. [Required]
- Active TS/SCI clearance. [Required]
- Must be willing to obtain a CI Poly. [Required]