ISSO Security Analyst
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The Opportunity:
As a ISSOon our team, you’ll use your experience to work with United States Marine Corps (USMC) Information System Owners (ISO), Information System Security Officers (ISSO), site managers, and other system stakeholders to coordinate and drive the completion of Risk Management Framework (RMF) steps 0-6 ATO activities and requirements, identify and mitigate risks, elevate project risks to leadership, understand and apply USMC authorization policies and processes, and provide information system security expertise.
You’llensure the appropriate operationalsecurity posture ismaintainedfor information systems throughout the system’s lifecycle from product acquisition and installation through decommission. You will complete andmaintainvery detailedsecurity documentation and coordinate to execute ATO support duties that documents security details related to a variety of IT systems, networks, hardware, and software in a variety of complex and simple installation sites.
You’llwork with your client to translate security concepts into actionable implementable solution recommendations to help the client make informed security decisions from all aspects of IT deployments ensuring full commissioning is completed through deployment, into production and decommissioning.
6+ years of experience with both Information Technology (IT) and Information Assurance (IA)
Experience with National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, system authorizations, and security compliance standards and processes, including IATTs, ATOs, ATCs, and reciprocity agreements
Experience supporting all RMF steps, security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M) for the IT system or application being accredited
Experience creating plans and approaches for executing product installation securely in accordance with agency authorization policy requirements for system major changes and development life cycles whileidentifyingpotential risks and working with system stakeholders to create mitigation strategies to reduce oreliminaterisks
Experience analyzing authorization documents and associated artifacts against authorization requirements toidentifygaps,establisha schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gapsin accordance with required deadlines
Experience with Enterprise Mission Assurance Support Service (eMASS) and tools such as the Assured Compliance Assessment Solution (ACAS), Security Technical Implementation Guides (STIG), and Evaluate-STIG
Ability to organize, manage, andmaintainlarge amountsof discrete data with variousexpirationdates across multiple systems simultaneously
Secret clearance
Batchelor’s degree in Cyber Security
DoD 8570.01 IAM Level II Certification, including CAP, CISSP, CASP, CISM, or GSLC Certification
Experience working with MOUs, MOAs and ISAs
Experience with RMF DoW and USMC Cybersecurity and Acquisition policies
Ability to work as part of a team
Possession of excellent verbal and written communication skills
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information;
Secret clearance is required.
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs.
Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).