Information Systems Security Officer; ISSO
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Information Security
position overview
information systems security officer (isso) with rmf experience will support usspacecom systems and efforts to achieve authorization to operate (ato). The role is located at the bayfield building in colorado springs, co, and includes full life‑cycle assessment and authorization management through all 6 steps of the rmf process for command‑issm.
source:
Following responsibilities will be performed in accordance with nist 800.53 r5.
- reviewing systems to identify potential security weaknesses and recommending improvements to amend vulnerabilities, implement changes, and document upgrades.
- maintaining responsibility for managing cybersecurity risk from an organizational perspective.
- identifying organizational risks, prioritizing those risks, and maintaining a risk registry for escalating and presenting those risks to senior leadership.
- providing security guidance and is validation using nist rmf and local security policies.
- providing configuration management recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the issm, security control assessor, and authorizing official.
- maintaining vulnerability scanning tool compliance (e.g., trellix hbss or acas nessus) and patch management to ensure it staff pushes patches to all systems, maintaining compliance with all applicable directives, managing system changes, and assessing the security impact of those changes.
- providing subject‑matter expertise for cybersecurity and trusted system technology.
- applying advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
- researching, writing, reviewing, disposition of feedback, and finalizing recommendations regarding cybersecurity policy, assessment and authorization assessments, security test and evaluation reports, and security engineering practices and processes.
- conducting research and writing risk assessment reports to include risk thresholds, evaluation, and scoring.
- supporting analysis of findings and providing expert technical guidance for mitigation strategies, including implementation advice on the cybersecurity risk findings and other complex problems.
filling this position is contingent upon funding
#li-lh1
requirements- bachelor's degree.
- a minimum of five (5) years experience as an information assurance (ia) analyst, isse, isso, or similar role in ato package development, including generating security documentation for requirements, security control assessment, stig and iava compliance, standard operating procedures, test results, etc.
- emass experience.
- professional security certification such as: ccna, cysa+, gicsp, gsec, comptia security+ ce, sscp, or higher.
- strong desktop publishing skills using microsoft word, excel, visio, and adobe.
- experience with industry writing styles such as grammar, sentence form, and structure.
- ability to multi‑task in a deadline‑oriented environment.
- cissp, casp, or a similar certificate is preferred.
- master's degree in cybersecurity or related field.
- strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
- demonstrated ability to work well independently and as a part of a team.
- excellent work ethic and a high commitment to quality.
src is a contractor for the u.s. Government. This position will require u.s. Citizenship as well as a u.s. Government security clearance at the top secret / sci level
travel requirements- some travel may be required for this position, up to 10%.
scientific research corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
src offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).