Entry Level- Information System Security Officer (ISSO) -
Information System Security Officer (ISSO)
The Information System Security Officer (ISSO) will provide cybersecurity and information assurance support for assigned federal information systems and cloud services. This is an entry-level cybersecurity position intended for a candidate with foundational information security knowledge and some experience coordinating projects, tasks, schedules, deliverables, or technical teams.
The ISSO will work under the direction of senior cybersecurity personnel and will support Risk Management Framework (RMF), system authorization, continuous monitoring, vulnerability management, POA&M management, audit readiness, and cybersecurity compliance activities. The position will also provide project coordination support by tracking cybersecurity activities, maintaining schedules and action items, coordinating meetings and stakeholder responses, following up on remediation activities, and helping ensure cybersecurity deliverables are completed on time.
The ideal candidate is an organized, technically capable early-career cybersecurity professional who can learn federal cybersecurity processes, communicate effectively with technical and non-technical stakeholders, and help keep multiple security activities moving toward completion.
Required Qualifications
- Foundational knowledge or practical experience in cybersecurity, information assurance, information systems, or a related technical field
- Understanding of basic information security concepts, including access control, vulnerability management, security monitoring, incident management, system configuration, and risk management
- Familiarity with cybersecurity frameworks, standards, or compliance requirements such as NIST, FISMA, NIST SP 800-53, NIST Risk Management Framework (RMF), FedRAMP, or similar frameworks
- Some experience performing project coordination, technical coordination, or administrative coordination, including activities such as:
- Tracking tasks, action items, milestones, and due dates
- Coordinating meetings and documenting decisions or meeting outcomes
- Following up with technical teams and stakeholders
- Maintaining project documentation, status reports, trackers, or schedules
- Identifying overdue activities, dependencies, or issues requiring escalation
- Strong organizational skills and attention to detail
- Ability to develop clear written documentation and communicate effectively with technical personnel, management, and Government stakeholders
- Ability and willingness to learn federal cybersecurity processes, tools, terminology, and documentation requirements
- Must be a U.S. Citizen
- Must be eligible to successfully complete and maintain a Tier 4 background investigation
Responsibilities
- Assist senior ISSOs and Government cybersecurity personnel with implementation and maintenance of the NIST Risk Management Framework
- Support development, review, and maintenance of cybersecurity documentation, including System Security Plans (SSPs), control implementation statements, inventories, diagrams, procedures, assessment evidence, POA&Ms, and continuous-monitoring artifacts
- Assist with security control assessments, authorization activities, ATO package preparation, and remediation tracking
- Track vulnerabilities, findings, remediation activities, POA&M items, due dates, and responsible parties
- Collect and organize cybersecurity evidence from system administrators, engineers, application teams, cloud administrators, and other stakeholders
- Review cybersecurity documentation and evidence for completeness, consistency, and proper organization before senior-level or Government review
- Assist with continuous monitoring, audit preparation, compliance reviews, and recurring cybersecurity reporting
- Coordinate cybersecurity meetings, maintain action-item trackers, document decisions, and follow up with responsible stakeholders
- Maintain schedules and status information for authorization, assessment, remediation, and other cybersecurity activities
- Identify schedule risks, unresolved actions, missing documentation, or dependencies and elevate them to the appropriate senior ISSO or project lead
- Assist with vulnerability-management activities and the review of findings generated by enterprise security tools
- Support cybersecurity activities involving enterprise and cloud technologies such as Microsoft 365, Azure, Entra ID, ServiceNow, CSAM/GRC platforms, Splunk, Microsoft Defender, Tenable/Qualys, Okta, Palo Alto, Zscaler, and related technologies
- Participate in cybersecurity reviews, working groups, audits, assessments, and meetings with Government and Contractor personnel
- Perform other cybersecurity and project coordination activities in support of the federal information security program
Preferred Qualifications
- Approximately 0-3 years of professional experience in cybersecurity, information technology, project coordination, technical support, systems administration, compliance, or a related field
- Internship, military, academic, help desk, system administration, network administration, SOC, GRC, or other experience providing exposure to cybersecurity operations
- Experience supporting a federal agency, Government contractor, regulated organization, or other security-conscious environment
- Exposure to ATO packages, SSPs, POA&Ms, security controls, vulnerability scanning, continuous monitoring, or cybersecurity audits
- Familiarity with Microsoft Azure, Microsoft 365, Entra ID, ServiceNow, Splunk, Tenable, Qualys, Microsoft Defender, or similar enterprise IT/security technologies
- Associate's or bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Project Management, or a related discipline, although equivalent practical experience will be considered
- Cybersecurity certification such as CompTIA Security+, ISC2 Certified in Cybersecurity (CC), Microsoft SC-900, Microsoft AZ-900, Microsoft SC-200, Microsoft SC-300, or another relevant entry-level or professional certification
- Project management or project coordination training or certification, such as CAPM, is desirable but not required
Certifications
Cybersecurity certifications are desirable but are not required at the time of hire. Candidates who demonstrate strong foundational cybersecurity knowledge, organizational ability, and the aptitude to develop into a federal ISSO role will be considered.
Relevant certifications may include:
- CompTIA Security+
- ISC2 Certified in Cybersecurity (CC)
- Microsoft SC-900 - Security, Compliance, and Identity Fundamentals
- Microsoft AZ-900 - Azure Fundamentals
- Microsoft SC-200 - Security Operations Analyst Associate
- Microsoft SC-300 - Identity and Access Administrator Associate
- CAPM - Certified Associate in Project Management
- Other relevant cybersecurity, cloud, information technology, or project management certifications
Corporate Resources
Unlike traditional ISSO positions that are primarily compliance and documentation focused, this role is backed by a broader cybersecurity and engineering organization. You will have access to a large cybersecurity laboratory environment, engineering resources, and reach-back subject matter experts across cloud, networking, identity, systems engineering, application security, vulnerability management, security operations, and federal cybersecurity compliance.
You will be able to use these resources to investigate technical issues, validate security approaches, reproduce and assess configurations, evaluate emerging technologies, and develop practical solutions to security and compliance challenges. The position offers an opportunity to lead not only the execution of RMF activities, but also to help shape the technical approaches, processes, tools, and practices used by the cybersecurity team.
Technical Environment and Professional Resources
You will be supported by capabilities beyond those normally available to an embedded ISSO team, including:
- Access to a dedicated cybersecurity and engineering laboratory for testing, validation, prototyping, and technical investigation
- Reach-back access to experienced cybersecurity, cloud, network, systems, identity, application, and infrastructure SMEs
- Opportunities to work directly with engineers to translate security findings and control requirements into implementable technical solutions
- Ability to evaluate and test security tools, configurations, architectures, and remediation approaches outside of the production environment
- Access to organizational lessons learned, technical expertise, reusable engineering approaches, and cybersecurity research developed across other federal programs
- Opportunity to help mature the team's RMF, continuous monitoring, vulnerability management, security engineering, and automation practices
- Ability to influence the technical direction and operating model of a growing federal cybersecurity team
63k -120k Depending on experience and/or certifications