Job Requirements
Los Angeles, CA
Clearance Unspecified Polygraph not specified
Early Career (2+ yrs experience)
$104,000 - $143,000
Job Description
Apex is looking for an Information Systems Security Officer (ISSO) to keep assigned systems secure, documented, and ready for customer or third-party review. You will work with system owners, IT, engineering, the SOC, and the Cybersecurity Lead to make sure security requirements are implemented in the environment and supported by evidence that holds up under review.
The primary focus is NIST SP 800-171 and CMMC Level 2. This role will also support ATO activities, SOC 2 Type II, ISO-aligned compliance work, and other customer security requirements as Apex grows.
Responsibilities
- Serve as the security point of contact for operations and keep teams informed on the current cyber posture.
- Work with the Cybersecurity team to assess requirements, risk findings, and due dates for contracts.
- Maintain the SSP, system inventory, policies, procedures, and supporting evidence for our CUI environment.
- Track NIST SP 800-171 and CMMC Level 2 implementation at the specific artifact level.
- Support ATO and RMF activities including creating and updating security documentation and writing POA&Ms with target completion dates.
- Validate evidence from our cybersecurity suite including CrowdStrike, Palo Alto, Tenable, and Jira.
- Lead vulnerability and configuration remediation with system owners; make sure ownership, expectations, and target dates are clear.
- Lead security reviews on privileged accounts, terminated users, vulnerability results, and other security requests from the program.
Requirements
- Active TS/SCI clearance required
- US Citizenship required
- 3 or more years of experience as an ISSO, security compliance analyst, security engineer, system administrator with security responsibilities, or a similar role
- Strong working knowledge of NIST SP 800-171, CMMC Level 2, POA&M management, control evidence, and assessment preparation
- Experience maintaining an SSP or equivalent system security documentation and supporting formal security reviews
- Ability to understand and validate evidence from identity, cloud, endpoint, network, vulnerability, and logging platforms
- Strong follow-through across multiple teams and the ability to write security documentation that clearly reflects what is actually implemented
Preferred Qualifications
- Experience with ATO, RMF, NIST SP 800-53, SOC 2 Type II, ISO 27001, DFARS 252.204-7012, SPRS, STIGs, or classified system security
- Experience with Microsoft GCC High, CrowdStrike, Palo Alto, Tenable, AWS GovCloud, Entra ID, or similar enterprise security platforms
- Security+, CGRC, CISSP, or a comparable security certification
-Experience supporting aerospace, defense, national security, ATO, RMF, or other regulated technical environments
The primary focus is NIST SP 800-171 and CMMC Level 2. This role will also support ATO activities, SOC 2 Type II, ISO-aligned compliance work, and other customer security requirements as Apex grows.
Responsibilities
- Serve as the security point of contact for operations and keep teams informed on the current cyber posture.
- Work with the Cybersecurity team to assess requirements, risk findings, and due dates for contracts.
- Maintain the SSP, system inventory, policies, procedures, and supporting evidence for our CUI environment.
- Track NIST SP 800-171 and CMMC Level 2 implementation at the specific artifact level.
- Support ATO and RMF activities including creating and updating security documentation and writing POA&Ms with target completion dates.
- Validate evidence from our cybersecurity suite including CrowdStrike, Palo Alto, Tenable, and Jira.
- Lead vulnerability and configuration remediation with system owners; make sure ownership, expectations, and target dates are clear.
- Lead security reviews on privileged accounts, terminated users, vulnerability results, and other security requests from the program.
Requirements
- Active TS/SCI clearance required
- US Citizenship required
- 3 or more years of experience as an ISSO, security compliance analyst, security engineer, system administrator with security responsibilities, or a similar role
- Strong working knowledge of NIST SP 800-171, CMMC Level 2, POA&M management, control evidence, and assessment preparation
- Experience maintaining an SSP or equivalent system security documentation and supporting formal security reviews
- Ability to understand and validate evidence from identity, cloud, endpoint, network, vulnerability, and logging platforms
- Strong follow-through across multiple teams and the ability to write security documentation that clearly reflects what is actually implemented
Preferred Qualifications
- Experience with ATO, RMF, NIST SP 800-53, SOC 2 Type II, ISO 27001, DFARS 252.204-7012, SPRS, STIGs, or classified system security
- Experience with Microsoft GCC High, CrowdStrike, Palo Alto, Tenable, AWS GovCloud, Entra ID, or similar enterprise security platforms
- Security+, CGRC, CISSP, or a comparable security certification
-Experience supporting aerospace, defense, national security, ATO, RMF, or other regulated technical environments
group id: 91136884