SonicJobs Logo
Left arrow iconBack to search

Information System Security Officer (ISSO)

Omniscius Consulting
Posted 2 days ago, valid for a month
Location

Oakton, VA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Information System Security Officer (ISSO) position is based on-site in Oakton, VA, within the Cyber Security Services department.
  • Candidates are required to have a Bachelor’s degree in Cybersecurity or a related field, along with 5–7+ years of experience in an ISSO role or a senior DoD RMF compliance position.
  • The role involves ensuring the secure operation of complex IT systems, managing RMF authorization packages, and conducting vulnerability assessments using tools like ACAS.
  • A Top Secret clearance with the ability to obtain SCI with CI Poly is necessary for this position, which also demands compliance with DoD Directive 8570.01-M / 8140.03 for IAM Level II or III.
  • Salary details are not explicitly mentioned, but the position is classified as full-time and non-exempt.
  • Job Title: Information System Security Officer (ISSO)
  • Location: On-Site in Oakton, VA  
  • Department: Cyber Security Services  
  • Reports To: Management 
  • FLSA Status: Full Time/Non-exempt  
  • Clearance: Top Secret with the ability to obtain SCI with CI Poly

Job Purpose:

The Information Systems Security Officer (ISSO) ensures the secure operation of complex, multi-enclave IT and Research & Development (R&D) systems. The ISSO serves as the principal advisor to Information System Owners regarding security posture. This role requires a "hands-on" governance approach, heavily utilizing the Assured Compliance Assessment Solution (ACAS) and standard DoD tooling to drive Continuous Monitoring (ConMon), validate compliance, and maintain active Authority to Operate (ATO) statuses without disrupting critical experimental research.

Duties & Responsibilities:

ISSO responsibilities include, but are not limited to:

RMF Lifecycle Management: Develop, maintain, and oversee RMF authorization packages (SSP, SAR, RAR, SAP, and POA&M) within systems of record (e.g., eMASS, Xacta) for standard enterprise and non-standard research environments.

ACAS Operations & Vulnerability Management: Execute credentialed and non-credentialed ACAS (Tenable.sc / Nessus) scans across connected and air-gapped networks. Analyze scan results to identify vulnerabilities, assess risk, and validate compliance against DoD baselines.

POA&M & Remediation Advisory: Translate complex ACAS scan results and DISA STIG findings into actionable mitigation strategies. Work directly with systems administrators and researchers to remediate vulnerabilities, track progress, and close POA&M items.

Continuous Monitoring (ConMon): Implement and oversee ConMon strategies. Review ACAS dashboards, audit logs (e.g., Splunk, Elastic), and system configurations to ensure ongoing compliance with NIST SP 800-53 controls.

Air-Gapped & Multi-Enclave Support: Facilitate secure data transfers, manual ACAS plugin/feed updates, and compliance validation for isolated, disconnected, and highly classified enclaves.

Security Assessments: Conduct routine compliance checks using SCC, STIG Viewer, and Evaluate-STIG. Support independent third-party assessments (e.g., CCRI) and ATO control validations.

Incident Handling: Coordinate with the Information Systems Security Manager (ISSM) and incident response teams to investigate security anomalies, audit anomalies, or classified data spillages.

Requirements

Qualifications:

  • Education/Experience: Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience) with 5–7+ years of experience acting as an ISSO or in a senior DoD RMF compliance role.
  • DoD Directive: DoD 8570.01-M / 8140.03 compliant for IAM Level II or III (e.g., CAP, CISM, CASP+ CE, CISSP).
  • Framework Knowledge: Expert-level understanding of DoD RMF (DoDI 8510.01), NIST SP 800-53/800-37/800-171, and DISA STIG implementation.
  • Tooling: Proven experience managing ATO artifacts in eMASS or Xacta. Proficient with SCC, STIG Viewer, and interpreting IAVA/IAVM notices.
  • Communication: Exceptional written and verbal communication skills. Ability to act as a security liaison, balancing strict DoD compliance requirements with our flexible, fast-paced R&D mission needs.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.