What are the responsibilities and job description for the Information System Security Officer (ISSO) position at SECURE RPO LLC?
Job Title: Information System Security Officer (ISSO)Location: Lexington, MA
Work Schedule: 100% Onsite
Employment Type: Contract
Work Schedule: 100% Onsite
Employment Type: Contract
Job Summary
MIT Lincoln Laboratory is seeking an Information System Security Officer (ISSO) to support Air Force Programs within the Cyber Security Team. The ideal candidate will have mid-level experience supporting Risk Management Framework (RMF), Assessment & Authorization (A&A), regulatory compliance, and security control implementation in DoD environments.
Key Responsibilities
- Assist and support compliance activities to ensure system security configuration guidelines are followed and compliance monitoring is maintained.
- Continuously validate organizational compliance with applicable policies, guidelines, procedures, regulations, and laws.
- Ensure Plans of Action & Milestones (POA&M) and remediation plans are in place for vulnerabilities identified during risk assessments, audits, and inspections.
- Promote security awareness across the organization and ensure security principles are reflected in organizational goals.
- Track audit findings and recommendations to ensure appropriate mitigation actions are completed.
- Recommend resource allocations required to securely operate and maintain cybersecurity requirements.
- Provide technical documentation, incident reports, examination findings, summaries, and situational awareness information to key stakeholders.
- Identify potential security violations and report incidents in accordance with established procedures.
- Assist Program Managers and the Information System Security Manager (ISSM) in developing and maintaining:
- System Security Plans (SSP)
- Plan of Action & Milestones (POA&M)
- Risk Assessment Reports
- Continuous Monitoring Strategy
- Ensure systems are operated, maintained, and disposed of in accordance with organizational security policies and procedures.
- Conduct network, system, and application vulnerability scanning, configuration assessments, and remediation.
- Align IT security priorities with the organization''s security strategy.
- Prepare for and participate in periodic compliance assessments.
- Interpret patterns of noncompliance to determine their impact on organizational risk and cybersecurity effectiveness.
Required Qualifications
- Minimum 4 years of experience in:
- System Auditing
- Regulatory & Compliance
- STIGs/SCAP
- Risk Management Framework (RMF)
- Assessment and Authorization (A&A)
- NIST SP 800-37
- NIST 800-53
- Categorization of Systems (CS102.16)
- Selecting Security Controls (CS103.16)
- Implementation of Controls (CS104.16)
- Assessing Security Controls (CS105.16)
- Authorizing Systems (CS106.16)
- Monitoring Security Controls (CS107.16)
- Continuous Monitoring (CS200.16)
- Current DoD 8570 IAT Level II Certification:
- Security CE, GSEC, SSCP, or CCNA Security
Preferred Qualifications (Nice to have)
- Bachelor''s degree (preferred, not required)
- Experience with:
- HBSS
- NIST 800-171
Security Clearance
- Active Top Secret (TS) Clearance with SCI eligibility is required.
- Candidate may be required to successfully complete a Counterintelligence (CI) Polygraph.
- SCI eligibility must be validated prior to submission.
Interview Process
- Phone Screen
- Extensive Zoom Interview with the team
Work Environment
- 100% onsite due to the nature of the work.
Salary : $70 - $75