Information System Security Officer; ISSO III
Listed on 2026-06-24
-
IT/Tech
Cybersecurity, Information Security, Systems Administrator, Network Security
Location: Lincoln
Job Details
- Security Clearance:
Active TS/SCI (Must be able to obtain a CI Poly) - Location:
Hanscom AFB, MA - Job Type: Full-Time
- Target Salary Range: $132,000 - $141,000
- This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary.
The Information System Security Officer (ISSO) is responsible for maintaining the appropriate operational security posture for assigned information systems. The ISSO works closely with the Information System Security Manager (ISSM), Information System Owner (ISO), Authorizing Official/Designated Authorizing Official (AO/DAO), system administrators, and other stakeholders to support secure system operations and compliance with applicable cybersecurity requirements.
The ISSO provides day-to-day security support for information systems operating within Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) environments. This role requires detailed knowledge of security operations, Risk Management Framework (RMF), authorization documentation, continuous monitoring, incident handling, configuration management, physical and environmental security, personnel security, and security training and awareness.
The primary function of this position is to support Special Access Programs for Department of Defense agencies, including Headquarters Air Force, the Office of the Secretary of Defense, and other military compartmented efforts.
Key Responsibilities- Assist the ISSM in meeting assigned cybersecurity, compliance, and system security responsibilities.
- Prepare, review, maintain, and update system authorization packages, RMF documentation, and supporting bodies of evidence.
- Support Assessment and Authorization efforts for DoD, national agency, and contractor information systems.
- Conduct periodic reviews of information systems to ensure compliance with approved security authorization packages.
- Conduct continuous monitoring activities for assigned authorization boundaries.
- Ensure security documentation is current, complete, accurate, and accessible to properly authorized personnel.
- Coordinate proposed hardware, software, firmware, and configuration changes with the ISSM and AO/DAO prior to implementation.
- Assess the security impact of system changes and provide recommendations to the ISSM.
- Notify the ISSM of changes that may affect the authorization status or security posture of assigned systems.
- Support configuration management activities across system authorization boundaries.
- Ensure approved procedures are in place for clearing, sanitizing, and destroying hardware and media.
- Monitor system recovery processes to ensure security features and procedures are properly restored and functioning.
- Ensure audit records are collected, reviewed, analyzed, and documented, including identification and reporting of anomalies.
- Identify cybersecurity vulnerabilities and assist with the implementation of appropriate countermeasures.
- Prepare reports on the status of security safeguards applied to information systems.
- Execute the cybersecurity portion of self-inspections, including security coordination and review of system assessment plans.
- Support incident handling activities, including identification, reporting, documentation, and coordination with appropriate security personnel.
- Support physical, environmental, and personnel security requirements related to assigned systems.
- Attend required technical and security training, including training related to operating systems, networking, cybersecurity, RMF, and security management.
- Perform ISSO duties in support of internal and external customers.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related technical discipline is preferred.
- Additional relevant experience may be considered in lieu of a degree.
- 5-7 years of related cybersecurity, information assurance, systems administration, network administration, or ISSO experience.
- Experience developing, maintaining, and supporting RMF…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).