Information Systems Security Officer (isso) Skill Level 1 (government)

AT&T AT&T · Telecom · Columbia, MD

The Information Systems Security Officer (ISSO) supports information assurance programs and ensures the security posture of mission-critical systems, focusing on security authorization activities in alignment with government requirements. Responsibilities include implementing security policies, maintaining system security posture, developing security documentation, administering user authentication, and managing configuration for security-relevant components within a Linux environment. The role requires experience with RMF, NIST standards, and cybersecurity operations for systems processing classified information.

What you'd actually do

  1. Support senior ISSOs in implementing and enforcing information systems security policies, standards, and methodologies.
  2. Maintain the operational security posture of classified information systems, including support for continuous monitoring activities.
  3. Develop system security policy and ensure compliance with applicable requirements.
  4. Evaluate security solutions to ensure they meet security requirements for processing classified information.
  5. Assist with the management of security aspects of information systems and perform day-to-day security operations.

Skills

Required

  • Five (5) years of experience as an ISSO on programs and contracts of similar scope, type; and complexity
  • Bachelor's degree in Computer Science or related discipline or four (4) years of additional experience
  • DOD 8570 compliance with IAT Level I or higher
  • RMF and RMF toolsets (e.g., LATTEART, XACTA, BISCOTTI, WATCHCAT, STE)
  • Compliance and configuration scanning tools (e.g., SCAP-based and host/network scanning solutions)
  • Working knowledge of NIST SP 800-53 (Rev. 3 and/or Rev. 5) and NIST SP 800-37
  • Security documentation development and maintenance (e.g., SSP, POA&M, Security Plan for Exceptions/waivers, BIA, Configuration Management Plan (CMP), After Action Report (AAR), Contingency Plan (CP), Security Assessment Report (SAR), Risk Assessment Report (RAR))
  • Experience supporting information assurance/cybersecurity operations for systems processing classified information
  • Hands-on experience with RMF execution, security control implementation, and security authorization (ATO) support
  • Experience producing and maintaining RMF artifacts and supporting audits, assessments, and continuous monitoring activities
  • Ability to support control selection/tailoring and coordinate security control assessments with technical and program stakeholders
  • Strong written communication skills to produce clear, complete, and compliant security documentation
  • Ability to coordinate across ISSM/ISSO, system owners, engineering, and operations teams to implement controls, manage change, and sustain compliance.

Nice to have

  • TS/SCI with polygraph clearance

What the JD emphasized

  • security authorization activities
  • RMF
  • classified information systems
  • security documentation