Information System Security Officer (ISSO) III
Job Description
Job Description
Location: Hanscom AFB, MA
Security Clearance: Active TS/SCI [Required] Must be able to obtain a CI Poly
Job Type: Full-Time
Target Salary Range*: $132,000-$141,000
*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
Position Overview
The Information System Security Officer (ISSO) is responsible for maintaining the appropriate operational security posture of an information system and works closely with the ISSM and ISO. The ISSO manages the security aspects of information systems and supports day-to-day security operations, including physical and environmental protection, personnel security, incident handling, and security training and awareness.
The position primarily supports Special Access Programs (SAPs) for Department of Defense (DoD) agencies, including HQ Air Force, the Office of the Secretary of Defense (OSD), and Military Compartments efforts. The ISSO provides day-to-day support for Collateral, Sensitive Compartmented Information (SCI), and SAP activities.
Key ResponsibilitiesInformation System Security Operations
- Assist the ISSM in meeting duties and responsibilities.
- Work closely with the ISSM and ISO to monitor information systems and their environments of operation.
- Conduct continuous monitoring activities for assigned authorization boundaries.
- Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
- Perform ISSO duties in support of in-house and external customers.
- Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
Authorization and Configuration Management
- Prepare, review, and update authorization packages.
- Assist Department of Defense, National Agency, and Contractor organizations with assessment and authorization (A&A) efforts.
- Develop and update authorization documentation.
- Implement configuration management across authorization boundaries.
- Assess the security impact of changes and make recommendations to the ISSM.
- Notify the ISSM when changes occur that might affect the authorization determination of information systems.
- Coordinate changes or modifications to system hardware, software, or firmware with the ISSM and AO/DAO prior to implementation.
Security Compliance and Assessment
- Execute the cybersecurity portion of the self-inspection, including security coordination and review of system assessment plans.
- Identify cybersecurity vulnerabilities and assist with implementing countermeasures.
- Prepare reports on the status of security safeguards applied to computer systems.
- Ensure all information system security-related documentation is current and accessible to properly authorized individuals.
- Ensure audit records are collected, reviewed, and documented, including anomalies.
Media, Security, and Recovery Procedures
- Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media.
- Support physical and environmental protection, personnel security, incident handling, and security training and awareness.
Training
- Attend required technical and security training, including operating system, networking, and security management training, relative to assigned duties.
QualificationsEducation
- Bachelor's degree [Required], or four additional years of experience in lieu of a degree [Required].
Experience
- 5–7 years of related experience, especially in developing RMF packages or bodies of evidence [Required].
- Prior performance in roles such as System/Network Administrator or ISSO [Required].
- 2+ years of SAP experience [Required].
Certifications
- IAT Level II or IAM Level II certification [Required].
Clearance
- TS/SCI clearance [Required].
- Must be willing to obtain a CI Poly [Required].
