Job Requirements
Newport, RI
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
We are seeking an experienced Information Systems Security Officer (ISSO) to support cybersecurity compliance and accreditation activities supporting a Department of Defense (DoD) cloud environment. The ideal candidate will possess extensive experience navigating the Navy Authorization to Operate (ATO) process and will serve as a cybersecurity resource responsible for guiding the system through the DoD Risk Management Framework (RMF) lifecycle.
This position will work closely with government stakeholders, engineering teams, cloud architects, and program leadership to achieve and maintain authorization while ensuring compliance with DoD cybersecurity requirements.
Primary Responsibilities:
Lead cybersecurity activities throughout the DoD Risk Management Framework (RMF) lifecycle.
Manage the development, review, and maintenance of RMF artifacts and authorization documentation.
Serve as the primary ISSO supporting the achievement of a Navy Authorization to Operate (ATO).
Coordinate directly with government Authorizing Officials (AO), Information System Security Managers (ISSM), validators, and cybersecurity representatives.
Build and maintain effective working relationships with Navy cybersecurity organizations to facilitate the authorization process.
Utilize eMASS to manage security controls, documentation, findings, and authorization packages.
Coordinate Security Technical Implementation Guide (STIG) implementation and validation across Windows, Linux, networking, and cloud environments.
Conduct security control assessments against NIST SP 800-53 requirements.
Support vulnerability management, POA&M development, and continuous monitoring activities.
Collaborate with engineering teams to implement secure cloud architectures within Azure Government and/or AWS GovCloud.
Assist with DoD Cloud Security Requirements Guide (SRG) compliance activities.
Support future Secret-level accreditation efforts and classified system expansion.
Provide cybersecurity guidance throughout system design, implementation, and operational phases.
Develop executive-level status reports and communicate cybersecurity risks to technical and non-technical stakeholders.
Job Requirements
Active Secret Security Clearance
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience)
5+ years supporting DoD cybersecurity programs
Demonstrated experience implementing the DoD Risk Management Framework (RMF)
Extensive experience with Navy Authorization to Operate (ATO) processes
Strong working knowledge of:
NIST SP 800-53
DoD RMF
Security Controls Assessment process
POA&M management
Continuous Monitoring
Experience using eMASS
Active DoD CAC (preferred) or ability to obtain eMASS access
Experience implementing and remediating Security Technical Implementation Guides (STIGs)
Familiarity with Microsoft Azure Government and/or AWS GovCloud
Understanding of FedRAMP security requirements and cloud compliance
Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG)
Excellent communication and documentation skills
Highly Desired Qualifications:
Extensive experience obtaining Navy ATOs
Existing relationships within Navy cybersecurity organizations
Current Navy CAC with Flank Speed access
Ability to access SIPRNet on a regular basis
Experience supporting Secret or higher classified information systems
Xacta experience
TS/SCI Security Clearance
CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certifications
Preferred Qualifications
Navy or NAVSEA cybersecurity programs
DoD Cloud environments
Microsoft Azure Government
AWS GovCloud
FedRAMP Moderate/High environments
Continuous Authorization (cATO)
DISA STIG automation
Vulnerability management platforms (ACAS, Tenable, Nessus)
Enterprise Identity and Access Management
Secure cloud architecture
This position will work closely with government stakeholders, engineering teams, cloud architects, and program leadership to achieve and maintain authorization while ensuring compliance with DoD cybersecurity requirements.
Primary Responsibilities:
Lead cybersecurity activities throughout the DoD Risk Management Framework (RMF) lifecycle.
Manage the development, review, and maintenance of RMF artifacts and authorization documentation.
Serve as the primary ISSO supporting the achievement of a Navy Authorization to Operate (ATO).
Coordinate directly with government Authorizing Officials (AO), Information System Security Managers (ISSM), validators, and cybersecurity representatives.
Build and maintain effective working relationships with Navy cybersecurity organizations to facilitate the authorization process.
Utilize eMASS to manage security controls, documentation, findings, and authorization packages.
Coordinate Security Technical Implementation Guide (STIG) implementation and validation across Windows, Linux, networking, and cloud environments.
Conduct security control assessments against NIST SP 800-53 requirements.
Support vulnerability management, POA&M development, and continuous monitoring activities.
Collaborate with engineering teams to implement secure cloud architectures within Azure Government and/or AWS GovCloud.
Assist with DoD Cloud Security Requirements Guide (SRG) compliance activities.
Support future Secret-level accreditation efforts and classified system expansion.
Provide cybersecurity guidance throughout system design, implementation, and operational phases.
Develop executive-level status reports and communicate cybersecurity risks to technical and non-technical stakeholders.
Job Requirements
Active Secret Security Clearance
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience)
5+ years supporting DoD cybersecurity programs
Demonstrated experience implementing the DoD Risk Management Framework (RMF)
Extensive experience with Navy Authorization to Operate (ATO) processes
Strong working knowledge of:
NIST SP 800-53
DoD RMF
Security Controls Assessment process
POA&M management
Continuous Monitoring
Experience using eMASS
Active DoD CAC (preferred) or ability to obtain eMASS access
Experience implementing and remediating Security Technical Implementation Guides (STIGs)
Familiarity with Microsoft Azure Government and/or AWS GovCloud
Understanding of FedRAMP security requirements and cloud compliance
Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG)
Excellent communication and documentation skills
Highly Desired Qualifications:
Extensive experience obtaining Navy ATOs
Existing relationships within Navy cybersecurity organizations
Current Navy CAC with Flank Speed access
Ability to access SIPRNet on a regular basis
Experience supporting Secret or higher classified information systems
Xacta experience
TS/SCI Security Clearance
CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certifications
Preferred Qualifications
Navy or NAVSEA cybersecurity programs
DoD Cloud environments
Microsoft Azure Government
AWS GovCloud
FedRAMP Moderate/High environments
Continuous Authorization (cATO)
DISA STIG automation
Vulnerability management platforms (ACAS, Tenable, Nessus)
Enterprise Identity and Access Management
Secure cloud architecture
group id: 10126936