Information Systems Security Officer (ISSO)

@ Canvas II, LLC.
Canvas II, LLC.canvasii,llc..com

Information Systems Security Officer (ISSO)

Eglin AFB, FL
Posted 5 days ago

About the job

A company focused on cybersecurity and network security, seeking an ISSO to oversee security programs, conduct audits, manage security plans, and ensure compliance with NIST and USAF guidelines.

Requirements

  • Experience with security audits
  • Knowledge of NIST SP 800-53
  • Experience with eMASS and ACAS
  • Understanding of RMF lifecycle
  • Familiarity with cybersecurity incident handling

Qualifications

  • Prior experience as ISSO or similar role
  • Knowledge of DoD cybersecurity policies
  • Strong analytical skills
  • Security certifications preferred
  • Excellent communication skills

Full job description

Essential Duties and Responsibilities

  • Under general direction, this role carries out all phases of information systems/networks security program that involves access to computers and computerized data enabling company to meet contractual requirements for networks security.
  • Conducts regular audits to ensure that systems are being operated securely, and information systems security policies and procedures are being implemented as defined in security plans.
  • Develop, update, and manage Authorization to Operate (ATO) packages. Navigate and maintain system records within the Enterprise Mission Assurance Support Service (eMASS).
  • Execute continuous monitoring strategies. Review audit logs, analyze vulnerability scans, and verify system configuration baselines remain intact.
  • Implement, enforce, and assess NIST SP 800-53 security controls. Apply and verify Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
  • Utilize the Assured Compliance Assessment Solution (ACAS) to scan for, identify, and coordinate the remediation of system vulnerabilities.
  • Identify, report, and track cybersecurity incidents and data spills in accordance with USAF and DoW incident response directives.
  • Draft, review, and maintain System Security Plans (SSP), continuous tracking of Plan of Action and Milestones (POA&M), and system-specific operating procedures.
  • Deep understanding of the NIST RMF lifecycle, DoDI 8510.01, and USAF-specific guidance (e.g., AFI 17-101, Risk Management Framework for Air Force Information Technology).
Show full description