Enterprise - Information System Security Officer - XACTA, SSP, POAM
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Enterprise - Information System Security Officer - XACTA, SSP, POAM
- Annapolis Junction, MD
Erias Ventures was founded to serve its customers with an entrepreneurial mindset. We value
creative problem-solving
,
open communication
, and
empowering our employees
to make decisions and put forth new ideas.
Our staff includes technical experts working across multiple disciplines, bringing diverse perspectives to every project. We are seeking engineers who wish to grow their careers and want to become part of a
technically strong
and
growth-oriented
company focused on bringing
innovative solutions
to the difficult mission problems facing our customers.
Provides support for a program, organization, system, or Provides support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. Maintains operational security posture for an information system or program to ensure information systems security policies, standards, and procedures are established and followed. Assists with the management of security aspects of the information system and performs day-to-day security operations of the system.
Evaluate security solutions to ensure they meet security requirements for processing classified information. Performs vulnerability/risk assessment analysis to support certification and accreditation. Provides configuration management (CM) for information system security software, hardware, and firmware. Manages changes to system and assesses the security impact of those changes. Prepares and reviews documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs).
Supports security authorization activities in compliance with NSA/CSS Information System Certification and Accreditation Process (NISCAP) and DoD Risk Management Framework (RMF).
A current Top-Secret/SCI with polygraph security clearance is required. Candidates cannot be sponsored or nominated for a government security clearance under this position.
ExperienceTen (10) years experience as an ISSO on programs and contracts of similar scope, type, and complexity is required. Experience is to include at least two (2) of the following areas: knowledge of current security tools, hardware/software security implementation; communication protocols; and encryption techniques/tools. Bachelor’s degree in Computer Science or related discipline from an accredited college or university is required. Four (4) years of additional experience as an ISSO may be substituted for a bachelor’s degree.
Requiredskills
- Experience supporting major federal information systems and applications
- Experience with security tools, hardware, software security implementation, communication protocols, or encryption techniques and tools
- Experience developing Risk Management products and working through system accreditations
- Experience interfacing with information assurance managers, including reviewing documentation, SSPs, Risk Assessment Reports, C&A packages, or Plans of Action and Milestones (POA&Ms)
- Experience working with XACTA IA Manager and Risk Management Frameworks
- Experience with national security information system security requirements, including JSIG, ICD 503, DAAPM, or NISPOM
- Experience in the oversight and execution of the Assessment and Authorization processes or C&A
- TS/SCI clearance with a polygraph
- Bachelor's degree and 10+ years of experience in Information Systems Security, or 14+ years of experience in Information Systems Security in lieu of a degree
- DoD 8570 IAM Level I Certification
Erias Ventures provides a complete package of wealth, health, and happiness benefits.
The expected…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).