American Systems logo
American SystemsPosted 2 weeks ago

Information Systems Security Officer (ISSO), Master

$180,000–$180,000 year

On-siteDallas, Texas, United States

Full TimeSenior LevelBachelors DegreeLarge

Job Summary

Develop and integrate cybersecurity architectures for systems processing multiple classification levels while performing senior-level ISSO and ISSE duties throughout the system development, authorization, and continuous monitoring life cycles. Apply JSIG, RMF, and NIST SP 800-series requirements to system design, control implementation, assessment, and authorization. Manually develop and maintain authorization artifacts and bodies of evidence, including SSPs, control narratives, POA&Ms, inventories, diagrams, and assessment evidence. Evaluate security architectures and system changes for impacts to security controls, authorization boundaries, and risk posture. Perform hands-on security assessments using command-line audits, compliance scans, configuration analysis, log reviews, and control validation. Identify security gaps and develop actionable risk management, remediation, and POA&M plans. Determine protection needs and coordinate the allocation of system-specific, hybrid, and common controls. Implement secure configuration processes and assess compliance with STIGs and Security Requirements Guides. Use Tenable, Trellix, SolarWinds, SIEM, SCAP, OpenSCAP, and Evaluate-STIG to assess vulnerabilities, configurations, and controls. Review system diagrams, data flows, inventories, interconnections, and configurations for accuracy and security compliance. Coordinate with program security, authorization officials, assessors, system owners, engineers, and administrators. Provide technical leadership for complex SAP cybersecurity, incident response, remediation, and authorization activities.

Required Qualifications

  • Active Top Secret/SCI clearance with SAP eligibility
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, Information Technology, or a related field
  • 11–12 years of relevant experience in cybersecurity, information assurance, systems security engineering, or ISSO support
  • DoD 8140 IAM-III level certification (e.g. CISM, CISSP, GSLC, or CCISO)
  • Experience performing combined ISSO and ISSE duties for classified systems in a SAP environment
  • Advanced knowledge of the JSIG, RMF, and applicable NIST SP 800-series publications
  • Proven experience manually developing authorization artifacts and bodies of evidence without reliance on automated RMF tools
  • Experience authoring SSPs, control narratives, POA&Ms, inventories, architecture diagrams, and assessment evidence
  • Hands-on experience assessing Linux and Windows systems through command-line validation, compliance scanning, configuration reviews, and log analysis
  • Experience implementing and assessing STIGs, Security Requirements Guides, and secure configuration baselines
  • Knowledge of enterprise architecture, firewalls, remote access, network infrastructure, and systems integration
  • Experience preparing systems for authorization, reassessment, continuous monitoring, and security inspections
  • Ability to identify deficiencies, assess risk, and provide actionable remediation recommendations
  • Ability to coordinate with customers, security officials, system owners, engineers, and administrators

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce