Information Systems Security Officer (ISSO)
KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on protecting our national security.
About the role
Innovative Projects: Work on prototype projects supporting the U.S. Air Force Research Laboratory’s most mission-critical objectives. AFRL is the primary scientific research and development center for the Department of the Air Force, leading the discovery, development, and integration of affordable warfighting technologies for air, space, and cyberspace forces.
Collaborative Environment: Join a dynamic and collaborative atmosphere where cross-functional teams of product owners, engineers, developers, and defense experts work in unison using Agile and DevOps principles. The team is passionate, forward-thinking, and united by a mission-first mindset.
Impactful Work: Your contributions will directly support the Air Force in expanding national capabilities, collaborating with experts across the Intelligence Community, Department of Defense, National Laboratories, industry, academia, and partner nations.
Responsibilities
- Architect, develop, and implement out-of-the-box cyber solutions to meet warfighter needs and ensure end-to-end security
- Serve as a cybersecurity advisor to the Government
- Analyze customer requirements and identify the need for cybersecurity solutions
- Develop and maintain a deep understanding of the organization’s overall technology landscape
- Create and maintain documentation for systems, enclaves, and applications, including design documents, implementation guides, standard operating procedures, and approval paperwork
- Oversee implementation of RMF, NIST SP 800-53, and STIG requirements, ensuring alignment with DoD security mandates
- Perform vulnerability assessments, support remediation of scan findings and IAVAs, and manage incident response workflows and recovery operations to maintain hardened security posture
- Support security documentation, security control assessments, and continuous monitoring in alignment with FISMA
- Load and manage cryptographic keys for High Assurance Internet Protocol Encryptors (HAIPE)
- Provide expert guidance in support of cyber audits, ATO packages, and continuous compliance processes
- Engage with customers to define the problem space and vision, determining capabilities and priorities for prototypes
- Work across multiple technology stacks, gaining hands-on experience with various languages, frameworks, and tools to support a broad range of applications
Requirements
- Active TS/SCI security clearance, eligible for SAP
- BS degree in Computer Science or Information Systems (other degrees considered with relevant work experience)
- One or more current certifications: CISM, CISSO, FITSP-M, GCIA, GCSA, GCIH, GSLC, GICSP, CISSP, CISSP-Associate, CISSP-ISSMP
- At least four (4) years of experience applying the DoD Risk Management Framework (RMF), including NIST SP 800-53, DISA STIGs, SCAP, IAVAs, and FISMA
- Experience managing cybersecurity projects in cloud environments (AWS, Azure, or VMware)
- Experience supporting ATO processes, POA&Ms, and cyber strategy development in federal or military environments
- Knowledge of Linux and Windows Operating Systems
- Knowledge of networking architecture and devices, including IDSs, firewalls, and CDSs
- Experience with Kubernetes and containerization
- Strong passion for conducting independent research, tackling complex problems, and continuously learning new technologies
- Excellent communication and collaboration skills
- Strong problem-solving and analytical skills
- Ability to work in a fast-paced environment and meet deadlines
Qualifications (Desired)
- At least eight (8) years of experience analyzing, assessing, and implementing corrective actions based on vulnerability scanning and penetration testing results
- At least eight (8) years of experience supporting defensive cyber operations for DoD, including incident handling, reporting, system defense, and information recovery
- Knowledge of Cybersecurity Process and Approval for Special Access Programs (SAPs)
- DevSecOps experience integrating security measures throughout the entire SDLC
- Familiar with air-gapped Kubernetes deployments using Helm charts and Zarf
- Proficient in using GitLab for version control, CI/CD pipelines, and collaboration
- Experienced in leveraging Agile Software Development methodologies for efficient and iterative project management
- High level of curiosity, investigative mindset, attention to detail, adaptability, and resilience
Schedule
- Location: Colorado Springs, CO (On-site)
- Travel Requirements: Minimal
- Working Hours: Standard, 40 hours per week (Full-time)
Pay
For Colorado only, the salary range for this position is approximately $104,000 - $120,000. The offered rate will be based on the selected candidate’s knowledge, skills, abilities, and experience, and in consideration of internal parity.
Benefits
- 401K plan with company match
- Medical, dental, and vision insurance
- Life insurance and AD&D
- Flexible spending account
- Disability coverage
- Paid time off or flexible work schedule
- Professional training and development for career advancement
- Bonuses, commissions, or other forms of compensation per internal policy or contractual designation
- Additional compensation may include sign-on bonus, relocation benefits, short-term incentives, long-term incentives, or discretionary payments for exceptional performance