Senior Information Systems Security Officer (ISSO)
RAZOR · Colorado Springs, CO · 5 days ago
On-siteOTHRFull-time
Education & Certification Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field (or equivalent experience)
- One or more of the following certifications is required: CISSP, CASP+, CISM, or GSLC
- Must meet DoD 8140/8570 IAM Level II or III requirements, depending on the program
Clearance Requirements
- Active Secret clearance required
- Top Secret/SCI preferred
- CI Polygraph may be required depending on customer requirements
- U.S. Citizenship required
Responsibilities
- Lead Risk Management Framework (RMF) activities for assigned information systems
- Develop, maintain, and manage Authorization to Operate (ATO) packages within eMASS
- Implement, assess, and validate NIST SP 800-53 security controls
- Perform security impact analyses for system changes and architecture updates
- Review STIG compliance and vulnerability scan results to identify security risks
- Coordinate remediation activities for POA&M findings and security deficiencies
- Conduct continuous monitoring (ConMon) activities and maintain cybersecurity documentation
- Review system architectures to ensure compliance with DoD cybersecurity requirements
- Support security assessments, audits, inspections, and authorization activities
- Collaborate with ISSMs, Information System Owners (ISOs), engineers, and system administrators to implement and maintain security controls
- Investigate cybersecurity incidents and support incident response efforts
- Maintain system security documentation, including SSPs, SARs, POA&Ms, Configuration Management documentation, and Security Control Traceability Matrices (SCTMs)
- Brief government stakeholders on system security posture, residual risk, and compliance status
- Mentor junior ISSOs and cybersecurity personnel
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field (or equivalent experience)
- 8-12+ years of cybersecurity or information assurance experience
- 5+ years supporting RMF for Department of Defense or Intelligence Community systems
- Experience developing and maintaining ATO packages
- Experience using eMASS, ACAS, SCAP, STIG Viewer, and Nessus
- Strong knowledge of RMF, NIST SP 800-53, CNSSI 1253, DoDI 8510.01, and Security Technical Implementation Guides (STIGs)
- Experience interpreting vulnerability scan results and developing remediation plans
- Experience supporting Continuous Monitoring (ConMon) activities
- Strong analytical, documentation, and communication skills
- Ability to manage multiple systems and priorities within a fast-paced environment
Desired Skills
- Experience supporting classified Department of Defense or Intelligence Community environments
- Experience with AWS GovCloud, Azure Government, or OCI Government Cloud
- Knowledge of DevSecOps and CI/CD security practices
- Experience with Splunk, Microsoft Defender, SIEM platforms, or enterprise security monitoring tools
- Experience securing containerized environments such as Kubernetes or OpenShift
- Cloud security experience
- Strong customer-facing communication and presentation skills
- Experience mentoring junior cybersecurity professionals
Benefits
- Medical, dental, and vision insurance
- Paid time off and holidays
- 401(k) with company match
- Professional development opportunities
- Other competitive benefits designed to support the health and well-being of our employees