CDS Information Systems Security Officer (ISSO
Verfasst am 2026-08-08
-
IT/Informationstechnik
Cyber-Sicherheit, Informationssicherheit & Datenschutz, Sicherheits-Manager
Location: Ramstein-Miesenbach
Type of
Requisition :
Regular Clearance Level Must Currently Possess:
Top Secret/SCI Clearance Level Must Be Able to Obtain:
Top Secret/SCI Public Trust/Other
Required:
None Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Cross Domain Solutions, Cybersecurity Controls, Risk Management Framework
Certifications:
None
Experience:
8 + years of related experience US Citizenship
Required:
Yes
CDS Information Systems Security Officer (ISSO) Advance your career while impacting our national security in cyber as a Cybersecurity Analyst Senior e, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. The Cybersecurity Auditor / Information Systems Security Officer (ISSO) is responsible for maintaining the operational security posture of assigned Cross Domain Solution (CDS) systems and ensuring continuous compliance with Department of Defense (DoW) and Intelligence Community (IC) security requirements, with a strong emphasis on Linux-based security auditing and continuous monitoring.
This role works closely with the Information System Security Manager (ISSM), system owners, enclave teams, and CDS engineering staff to execute day-to-day security operations focused on:
- Direct audit and review of CDS system logs and security-relevant events
- Continuous monitoring of guard behavior and data flows
- Validation of enforcement rules and configuration baselines
- Collection and organization of bodies of evidence for RMF and assessments
The Cybersecurity Auditor / ISSO provides technical expertise in:
- Linux system administration and command-line analysis
- Native log review and correlation (e.g., syslog, auditd, application logs)
- Transfer decision validation and sanitization evidence review
- Development of procedures and checklists for recurring security audits
This work ensures compliance with NIST SP 800-53, DoWI 8510.01 and CDS boundary protection requirements, and helps maintain CDS systems in an audit-ready, fail-secure posture.
RESPONSIBILITIES- Assist the ISSM in meeting assigned duties and responsibilities in accordance with DoDI 8510.01 and NIST RMF guidance.
- Conduct continuous monitoring activities for assigned authorization boundaries, with specific focus on CDS guard behavior and data flows.
- Perform detailed security audits directly on Linux-based CDS systems, including review of operating system, application, and custom guard logs.
- Monitor guard behavior and validate data flow enforcement rules to ensure only authorized transfers occur across domains.
- Develop and maintain procedures for Linux log collection, rotation, retention, and secure storage to support audit requirements.
- Prepare, review, and update authorization documentation related to audit and monitoring controls (e.g., SSP sections, monitoring procedures, control implementation summaries).
- Conduct periodic reviews of information systems to ensure compliance with the security authorization package and applicable policies.
- Assess the security impact of system changes (e.g., configuration updates, patching, rule changes) and provide recommendations to the ISSM prior to implementation.
- Validate time synchronization, log integrity, and audit completeness across CDS components.
- Identify and troubleshoot logging gaps, misconfigurations, or failures directly on Linux systems (e.g., auditd, rsyslog, custom logging services).
- Provide log extracts, audit trails, and evidence packages to support internal and external audits and assessments.
- Ensure audit records are reviewed and documented, including identification, investigation, and resolution of anomalies.
- Ensure appropriate logging and monitoring of all internal components that make up the HSG/TSG [consider expanding or clarifying this acronym in the final posting].
- Coordinate with system and network administrators to ensure logging and monitoring requirements are embedded in system deployments and configuration baselines.
- Support RMF lifecycle activities within XACTA, including maintenance of control implementations and bodies of evidence.
- Maintain SSP sections related to monitoring and audit architecture, and keep documentation…
Um nach Stellen zu suchen, sie anzusehen und sich zu bewerben, die Bewerbungen aus Ihrem Standort oder Land akzeptieren, klicken Sie hier, um eine Suche zu starten: