- Location
- Huntsville, AL
- Type
- Full-time
- Department
- Administration
- Experience
- 3+ years
- Education
- Bachelor
- Clearance
- Required
- Source
- ApplicantPro
Description
Position Title: Information Systems Security Officer (ISSO) Experience Level: Mid-Level (3–5 years) Department: Security Reports To: Senior FSO/ISSM Location: Huntsville Job Type: Full-Time
Job Summary
We are seeking a highly motivated and detail-oriented Information Systems Security Officer (ISSO) with 3 to 5 years of experience to join our security team. In this role, you will be responsible for ensuring the operational security posture of our information systems. You will play a critical role in maintaining compliance with industry standards, conducting risk assessments, managing vulnerabilities, and supporting incident response efforts.
Key Responsibilities
· Security Compliance & Governance: Maintain and enforce information security policies, standards, and procedures. Ensure all assigned systems comply with relevant regulatory and organizational requirements.
· Risk & Vulnerability Management: Coordinate and conduct regular vulnerability scans, analyze results, and collaborate with system administrators to ensure timely patching and remediation.
· System Security Plans (SSP): Hands-on experience updating control implementation statements, tracking POA&Ms (Plans of Action and Milestones), and maintaining security documentation within eMass.
· Access Control & Monitoring: Monitor user access controls, perform periodic access reviews, and audit system logs to detect unauthorized activities or policy violations.
· Incident Response Support: Assist the Incident Response team during security incidents, helping to contain, investigate, and document breaches or anomalies.
Required Qualifications
· Clearance: Must have an active Secret US Government Clearance. Please note US Citizenship is required to maintain a Secret Clearance.
· Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (equivalent work experience will be considered).
· Experience: 3 to 5 years of direct experience in an information security role (e.g., ISSO, Security Analyst, or Security Administrator).
Technical Knowledge:
· Solid understanding of network security principles, firewalls, intrusion detection/prevention systems (IDS/IPS), and Identity and Access Management (IAM).
· Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7) and SIEM platforms (e.g., Splunk, Sentinel).
· Practical knowledge of at least one major security framework, such as NIST SP 800-37/53, ISO/IEC 27001, CIS Controls, or SOC 2.
Certifications: Active security certification is highly preferred (e.g., CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), or Certified Information Systems Security