Information System Security Officer (ISSO) – TS/SCI
Risk Management Framework
Develop, maintain, and update RMF documentation supporting IATT and ATO packages.
Author and maintain:
- System Security Plans (SSPs)
- Security Control Family Plans (AC, IA, SC, SI, etc.)
- POA&Ms
- Control implementation statements
- Continuous Monitoring documentation
Support the full RMF lifecycle in accordance with DoDI 8510.01 and NIST SP 800-53 Rev. 5.
Cloud Security
Maintain security posture across AWS environments supporting IL2, IL4, Secret, and TS workloads.
Assist engineering teams in implementing secure cloud architectures.
Review vulnerability findings and support remediation efforts.
Configure and monitor AWS security services including:
- GuardDuty
- Security Hub
- AWS Config
- IAM
- AWS Organizations / SCPs
Vulnerability & Compliance Management
Maintain POA&Ms and continuous monitoring activities.
Ensure compliance with customer cybersecurity policies and accreditation requirements.
Collaboration
Partner with cloud engineers, ISSOs, ISSEs, architects, and customer security teams.
Participate in security assessments and authorization reviews.
Provide guidance during audits and compliance activities.
Support ongoing improvements to cloud security posture and automation.
Qualifications
- Active TS/SCI Clearance
- 5+ years of Information Assurance, Cybersecurity, or Information System Security experience
- Minimum 2 years supporting RMF and NIST SP 800-53
- Minimum 1 year supporting AWS cloud security environments
- Experience creating and maintaining complete ATO packages
- Experience with SSPs, POA&Ms, Continuous Monitoring, and Control Implementation Statements
- Working knowledge of AWS security services
- Strong understanding of vulnerability management and security compliance
Preferred Qualifications
- Experience with eMASS, Xacta, Keyhole, or equivalent GRC platforms
- Experience supporting DoD IL2/IL4/Secret/TS cloud environments
- Familiarity with AWS Landing Zone Accelerator (LZA)
- Experience implementing Zero Trust security principles
- DoD 8570/8140 IAM Level II or IAT Level III certification
- One or more of the following: CISSP, CISP, CAP, CASP+
Desired Skills
- Excellent communication and documentation skills
- Strong analytical and troubleshooting abilities
- Ability to work independently in classified environments
- Experience supporting highly regulated Federal or Intelligence Community customers