Information System Security Officer (ISSO)
See all open roles at redhorse corporation →
Some ghost-posting signals
- open for 91 days (90+ without a fill is a strong ghost signal)
- 67 open roles at this company in 30 days (mass-hiring blitz)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
Key Responsibilities
Perform the duties of an Information System Security Officer (ISSO) as defined in AR 25-2, DA 25-2-14, and NIST SP 800-53 security controls.
Actively manage the organization’s eMASS records, including control validation and artifact association.
Assess security scan results and DISA STIGs to identify and mitigate system vulnerabilities.
Perform POA&M updates, tracking, and resolution to ensure timely remediation of security findings.
Lead continuous monitoring activities to maintain the ongoing security posture of the organization.
Manage the day-to-day activities and professional development of a team of Cybersecurity Analysts.
Collaborate with the O-ISSM on assessment and authorization (A&A) activities to ensure systems maintain an ATO on DoD/IC networks.
Maintain up-to-date status on all assigned systems and communicate risk posture to Government leadership.
Correspond with system administrators to communicate unacceptable risks and correct deficient POA&M items.
Coordinate with the Security Control Assessor (SCA) to analyze the overall risk level the system poses to enterprise networks and mission data.
Create and maintain cybersecurity policies, standards, and security testing plans aligned with Army G2 policy.
Produce actionable, risk-based reports on security assessment results and assist with vulnerability remediation.
Develop and improve risk models, metrics, and processes to stay compliant with evolving DoD and IC standards.
Provide guidance in the creation of Standard Operating Procedures (SOPs) and Tactics, Techniques, and Procedures (TTPs).
Required Experience/Clearance
Active TS security clearance with eligibility for SCI and NATO read-on prior to starting work.
Must meet DoD 8140 / 8570.01-m requirements for a privileged user (IAT II/III or IAM II/III) on a TS/SCI system.
Educational/Experience Background:
PhD in a STEM field with at least 15 years’ experience as a cybersecurity professional; OR
Master’s degree in a STEM field with at least 18 years’ experience as a cybersecurity professional; OR
Bachelor’s degree in a STEM field with at least 20 years’ experience as a cybersecurity professional.
15+ years’ experience with assessment and accreditation (A&A) of national security systems (NSSs).
10+ years’ experience validating system security controls.
10+ years’ experience with vulnerability management and DISA STIGs/SRGs.
8+ years’ experience specifically with RMF and eMASS.
5+ years’ experience with POA&M tracking and resolution.
3+ years’ experience performing continuous monitoring of system security controls.
Desired Experience
10+ years’ experience as an ISSO specifically supporting Army Intelligence programs.
2+ years’ experience with AC2SP tenant assessment and accreditation activities.
Experience leading large-scale cybersecurity teams within a Department of Defense environment.
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot