Information System Security Officer III with Security Clearance
Why This Role Stands Out
This hybrid role offers a fantastic opportunity to grow your cybersecurity expertise within a reputable company, directly contributing to critical national security efforts. If you're a mid-senior cybersecurity professional with a knack for RMF lifecycle management and a security clearance, you'll thrive by implementing and monitoring essential security controls. Apply today to leverage your skills in a dynamic and impactful environment.
Quick Overview
Job Description
Job Description: Position Overview ORBIS requires an Information System Security Officer III (ISSO III) to serve as a tactical cybersecurity expert supporting the NSWC Corona CCAM contract. Working under the direction of the ISSM, the ISSO III is responsible for the day-to-day implementation, monitoring, and maintenance of security controls across assigned information systems. This key personnel role is heavily involved in the technical aspects of the RMF lifecycle and continuous monitoring programs.
Operational Cybersecurity & RMF Responsibilities
- Execute daily, weekly, and monthly cybersecurity operations for assigned networks, enclaves, and Platform IT systems.
- Coordinate directly with system engineers, developers, and administrators to ensure security configurations are applied during the system development lifecycle.
- Conduct comprehensive vulnerability assessments utilizing the Assured Compliance Assessment Solution (ACAS/Nessus) and analyze the results to identify critical flaws.
- Apply and verify Security Technical Implementation Guides (STIGs) using the SCAP Compliance Checker (SCC) and manual STIG Viewer reviews.
- Develop, compile, and upload high-quality artifacts into eMASS to demonstrate the successful implementation of NIST 800-53 security controls.
- Draft and update essential RMF documentation, including Information System Contingency Plans (ISCP), Incident Response Plans (IRP), and hardware/software inventories.
- Assist the ISSM in creating, updating, and managing Plan of Action and Milestones (POA&M) entries, documenting steps taken to remediate identified vulnerabilities.
- Perform daily reviews of system audit logs, Security Information and Event Management (SIEM) alerts, and firewall traffic to identify anomalous or malicious activity.
- Enforce account management policies, ensuring that user access, privileged access, and administrative roles are granted according to the principle of least privilege.
- Support cyber incident response activities, executing containment procedures, preserving evidence, and assisting in root-cause analysis.
- Monitor systems for compliance with Information Assurance Vulnerability Alerts (IAVAs), ensuring patches and updates are tested and deployed within mandated timeframes.
- Participate in Configuration Control Board (CCB) meetings to evaluate the security impact of proposed network changes, software installations, or hardware modifications.
- Conduct physical security walk-throughs and environmental control checks for facilities housing classified or sensitive information systems.
- Assist in the preparation and execution of formal command cyber inspections and assist the NQV during official validation events.
Required Qualifications & Clearances
- Clearance: Must possess an active, TS/SCI and be a United States citizen.
- Education: Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field. (Significant operational experience and advanced certifications may substitute for the degree).
- Experience: A minimum of six (6) years of dedicated experience coordinating and implementing security changes, conducting vulnerability analysis, and managing continuous monitoring activities.
- Technical Experience: Demonstrable hands-on experience utilizing ACAS (Tenable/Nessus), HBSS (Trellix/McAfee), Splunk (or similar SIEM), and STIG Viewer.
- Certifications: Must possess and maintain a current DoD 8140/8570 IAM Level II certification (e.g., CAP, CASP+ CE, CISM, CISSP, GSLC, CCISO, or HCISPP).
- Strong working knowledge of Windows and Linux/Red Hat operating system security configurations and Active Directory group policies.
- Ability to work effectively in a fast-paced environment, balancing multiple RMF package deadlines and continuous monitoring requirements simultaneously.
Preferred Qualifications
- Certifications in specific operating systems or security tools (e.g., Linux+, Microsoft Certified Azure Security Engineer, Splunk Core Certified Power User).
- Prior experience serving as an ISSO for a Navy Research, Development, Test, and Evaluation (RDT&E) environment.
- Direct experience writing custom scripts (PowerShell, Python, Bash) to automate security compliance checking and log analysis.
Similar jobs
- CE
Principal IT Architect - AI
Constellation Energy
Baltimore, MD🇺🇸$172.8k - $192k/yrHybrid2 weeks agoMachine LearningAzureGenerative AITechnology - DS
Configuration Management Specialist Mid to Senior Level (Pending Contract Award) - SBG
NewDocument Storage Systems Inc
Alexandria, VA🇺🇸$85k - $115k/yrHybrid11 hours agoComplianceHIPAAMicrosoft OfficeTechnology - MO
Full Stack Engineer (Java, APIs, AWS)
Mutual of Omaha
Stafford, TX🇺🇸$120k - $145k/yrRemote2 weeks agoDockerMicroservicesMongoDB+11Technology - DO
Supervisory IT Specialist (Policy and Planning/Network Services) with Security Clearance
NewDepartment of the Army
Fort Huachuca, AZ🇺🇸$128.2k - $175.2k/yrRemote11 hours agoLESSTechnology - EX
OT Systems Integration Engineer
NewExperis
Kansas City, MO🇺🇸$118 - $130/hrOn-site11 hours agoTechnology - LE
Desktop Support Technician
NewLeidos
Rancho Santa Fe, CA🇺🇸$31 - $34/hrHybridYesterdayTechnology