user avatar

Information Systems Security Officer

SMS Data Products Group, Inc

Posted today

Job Requirements

Edwards, CA
Secret Polygraph Unspecified
Career Level not specified
$90,000 - $110,000

Job Description

SMS is seeking an Information Systems Security Officer (ISSO) I to support the Air Force Research Laboratory (AFRL) at Edwards Air Force Base. The ISSO I provides cybersecurity, Assessment and Authorization (A&A), and Risk Management Framework (RMF) support throughout the system lifecycle. The position develops and maintains security documentation, evaluates risk, supports security control testing and continuous monitoring, and works with system owners, administrators, cybersecurity personnel, assessors, and government stakeholders to support system authorization and maintain compliance with applicable DoD, Department of the Air Force, NIST, and DISA requirements.

Since 1976, SMS has specialized in modernizing legacy IT and sustaining complex enterprise environments for federal agencies. With the goal of building long-term partnerships with our customers, we invest in our employees by providing the training, tools, and support they need to keep critical missions operational, improve performance, and reduce risk. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com .

Submit your resume today!

Job Responsibilities
  • Develop, maintain, and update System Security Plans (SSPs), risk assessments, Plans of Action and Milestones (POA&Ms), and other RMF/A&A authorization artifacts.
  • Categorize information systems and support security-control selection using DoDI 8510.01, NIST SP 800-60, applicable RMF baselines, and the RMF IT Categorization and Selection Checklist (ITCSC).
  • Evaluate system risks and vulnerabilities using RMF methodology and recommend mitigation or remediation strategies.
  • Collaborate with system owners, system administrators, cybersecurity personnel, assessors, and other stakeholders throughout the A&A process.
  • Ensure security controls are incorporated into system design and operations; support testing, validation, and collection of evidence demonstrating control effectiveness.
  • Use vulnerability and compliance tools such as Nessus or SCAP to identify technical vulnerabilities, support remediation, and validate secure configurations.
  • Validate systems against applicable DISA Security Technical Implementation Guides (STIGs), document deviations, and coordinate corrective actions.
  • Establish and support continuous monitoring activities, maintain visibility of system security posture, and provide status to the ISSM and Authorizing Official (AO).
  • Maintain accurate documentation for system changes, secure configurations, cybersecurity incidents, threats, deficiencies, mitigations, and authorization decisions.
  • Support assessment teams by providing required documentation, evidence, and system access for security-control testing.
  • Verify systems meet applicable security criteria before AO review and support ATO/DTO risk decisions with clear summaries of system risk posture.
  • Provide DoD RMF and cybersecurity subject-matter support to technical teams, customers, and decision-makers.
  • Ensure required users and administrators complete System Rules of Behavior and Authorized Use Agreements in accordance with applicable Air Force, Space Force, and AFRL RMF guidance.

Required Qualifications
  • 3+ years of cybersecurity, information assurance, information system security, or related experience, including experience supporting RMF activities.
  • Working knowledge of DoD RMF and A&A processes, including SSPs, POA&Ms, security controls, risk assessments, continuous monitoring, and authorization documentation.
  • Familiarity with DoDI 8510.01, NIST guidance, DISA STIGs, and applicable DoD cybersecurity requirements.
  • Experience supporting vulnerability assessment, security compliance, and remediation activities; familiarity with tools such as Nessus, SCAP, ACAS, or Tenable.
  • Technical understanding of enterprise infrastructure, Microsoft Windows, Linux, networking, and common cybersecurity technologies sufficient to support system security activities.
  • Strong documentation, analytical, organizational, and communication skills with the ability to coordinate across technical and non-technical stakeholders.
  • Ability to obtain and maintain a DoD Secret Security Clearance.
  • Ability to obtain and maintain applicable DoD 8140 workforce qualification requirements within the required timeframe.
  • Maintain an IAT level II certification.

Desired Qualifications
  • Experience supporting DoD, Department of the Air Force, AFRL, classified, research, laboratory, engineering, or scientific computing environments.
  • Experience preparing or maintaining DoD RMF authorization packages and using eMASS or a similar governance, risk, and compliance platform.
  • Experience implementing or validating DISA STIGs and supporting cybersecurity assessments, inspections, audits, or authorization activities.
  • Relevant cybersecurity certification such as CompTIA Security+, CySA+, ISC2 Certified in Cybersecurity (CC), CISSP, or another applicable certification.

Salary Range - $90,000 - $110,000

SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Req # 2026-5560
group id: 10118452