Information Systems Security Officer; ISSO
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security
Purpose and Impact:
Independently executes and coordinates day-to-day security operations for assigned systems limited supervision. Leads execution of continuous monitoring technical activities, including scan scheduling/executed support, log/alert triage, STIG compliance verification, and security tool health/coverage checks. Coordinates remediation actions with system administrators and engineers, validates corrective actions through re-scan/re-check activities, and maintains accurate operational security evidence repositories. Provides technical evidence and posture inputs to the ISSM to support RMF reporting and assessments.
The ISSO does not own RMF package governance, does not manage POA&Ms as the accountable authority, and does not make risk acceptance decisions.
Work Schedule: The coursesbeing supported are active from M-F. Contract core hours are .
Essential Responsibilities:
The Level 2 Information Systems Security Officer (ISSO) shall possess the following capabilities:
- Lead day-to-day security operations for assigned systems, including monitoring/triage of security alerts/logs, validation of security tool health/coverage, and escalation of incidents per SOP. response activities as directed, and driving timely resolution/escalation of anomalies in accordance with established procedures
- Plan and execute vulnerability and compliance scanning activities (credentialed/noncredentialled as approved), perform basic false-positive review, document results, and maintain remediation tickets with accurate technical detail.
- Execute and validate STIG/compliance posture checks (as assigned) and coordinate remediation with administrators; validate fixes via re-check and document completion evidence.
- Maintain security evidence repositories for assigned systems (scan outputs, STIG checklists, tool status evidence, access review artifacts as assiY1ed) ensuring labeling, access control, and retrievability.
- Support IAM control execution by coordinating account actions with administrators and supporting periodic access reviews; document results and discrepancies for disposition by Government/ISSM
- Provide technical security-impact inputs for proposed changes (affected components, required re-scan/re-test recommendations, control evidence impacts as observed) to support change control discussions (non-approval role).
- Produce recurring technical posture inputs (scan tends, top recurring findings, remediation aging) for ISSW/Government reporting and drive timely updates of tickets to reflect current status.
Security Clearance Required
:
- TS/SCI with Poly
Minimum Education:
- A Doctoral degree No experience; OR
- A Master’s degree plus 3 year of relevant experience; OR
- A Bachelor's degree plus 5 years of relevant experience; OR
- An Associate's degree or 18 semester hours of military coursework/training in a computer-related field plus 7 years of relevant experience may be considered;
- Degree in Information Assurance, Information Security, Information Systems, Information Technology, Computer Networking, Information Science, Cyber Security, or related is preferred
Minimum Years of
Experience:
- Relevant experience must be in information systems design, development, programming, information/computer/cyber/network security, vulnerability analysis, penetration testing, computer forensics, computer systems research, reverse engineering, and/or systems engineering (i.e., requirements analysis, design, implementation, testing, integration, deployment/installation, and maintenance). Experience in the Risk Management Framework (RNIF), Information Systems Security technologies, IT policies, and ability to interpret policies and directives is desired. Network and system administration may be used to meet some, but not all, of the relevant experience requirement.
Required
Certifications:
- Information Assurance Manager (IAM) Tier I certification requirements must be met within 6 months of assignment to the position. Maintaining certification status is required through continuous education training or sustainment training while serving in this work role
#javelin
As part of our commitment to maintaining a safe and compliant work environment, Amentum is a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).