Information Systems Security Officer; ISSO
Job in
Huntsville, Madison County, Alabama, 35824, USA
Listed on 2026-08-30
Listing for:
PeopleTec, Inc.
Full Time
position Listed on 2026-08-30
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Opportunity
People Tec is currently seeking an Information Systems Security Officer (ISSO) to support our Huntsville, AL location.
This is a Senior Information Systems Security Officer (ISSO) position responsible for overseeing risk management, security compliance, and cybersecurity operations for the cloud-based information systems supporting the Guam Defense System (GDS). This role serves as a key technical and compliance advisor, ensuring systems conform to the Risk Management Framework (RMF), National Institute of Standards and Technology (NIST) guidelines, and DoD Cloud Computing Security Requirements Guide (SRG) for Impact Level 6 (IL6) data.
Duties:
- Lead and coordinate Risk Management Framework (RMF) Steps 1–6 for GDS, ensuring successful Assessment & Authorization (A&A) cycles and securing/maintaining Authorities to Operate (ATOs).
- Author and maintain comprehensive cybersecurity documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and boundary diagrams.
- Design and execute continuous monitoring strategies for GDS cloud environments to capture, analyze, and report real-time compliance and threat vectors.
- Perform regular vulnerability scans and configurations checks of cloud infrastructure, containerized environments, and serverless applications. Analyze results and collaborate with GDS cloud engineers to prioritize and execute remediation plans.
- Deploy and utilize enterprise security tools to detect, investigate, and mitigate vulnerabilities and advanced persistent threats (APTs).
- Support incident response teams during active security events. Lead post-incident forensic investigations, root-cause analyses, and the implementation of permanent remediation measures.
- Provide expert security architecture recommendations to engineering and Dev Ops teams implementing Dev Sec Ops pipelines, automated infrastructure-as-code (IaC) deployments, and Zero Trust architectures.
- Track and report cybersecurity risks, system compliance drift, and mitigation progress directly to GDS program leadership and government Authorizing Officials (AOs).
Required Skills/
Experience:
- Minimum of nine (9) years of progressive experience in cybersecurity, information assurance, systems engineering, or related IT fields.
- At least seven (7) years of direct experience serving as an ISSO or ISSM within a cleared DoD or Intelligence Community (IC) environment.
- Minimum of three (3) years of hands-on experience securing and managing cloud-based systems (AWS, Azure, or GCP), specifically within federal, defense, or high-security hybrid/multicloud environments (IL5/IL6).
- Proven experience implementing RMF (NIST SP 800-37, 800-53, 800-137) for tactical, strategic, or defense systems.
- Mastery of RMF, NIST SP 800-series, CNSSI 1253, and DoD 8500-series instructions.
- Strong understanding of cloud service models (IaaS, PaaS, SaaS), shared responsibility models, identity and access management (IAM), secure virtual networking, encryption standards (at rest and in transit), and container security (Kubernetes, Docker).
- Proficiency with enterprise vulnerability management, log aggregation, and system assessment tools.
- Familiarity with the operational environment of Integrated Air and Missile Defense (IAMD) systems, Joint All-Domain Command and Control (JADC2) initiatives, and cross-domain solution (CDS) implementation is highly preferred.
- Exceptional written and verbal communication skills, with the ability to translate complex technical vulnerabilities into business/mission risk for senior military leaders.
- Strong analytical, troubleshooting, and problem-solving skills in high-stakes, fast-paced environments.
- Candidate must hold an active certification meeting the DoDM 8140.03 IAM Level III requirement:
- CISSP (Certified Information Systems Security Professional)
- GISP (Global Information Security Professional)
- CASP+ (CompTIA Advanced Security Practitioner)
- Or equivalent IAM Level III-approved certification.
- Candidate must also hold at least one (1) active cloud security or cloud architecture certification from a major provider or recognized organization:
- CCSP ((ISC)² Certified Cloud Security Professional)
- AW…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×