Information System Security Officer (ISSO) – Contingent Upon Contract Award
jmaresources · Philadelphia, PA, United States
About The Role
Contingent Posting Notice
JMA Resources is recruiting for this position in anticipation of a potential contract award. This position is contingent upon JMA Resources receiving the associated contract award and confirmation of final staffing requirements and funding.
Position Overview
The Information System Security Officer (ISSO) supports cybersecurity compliance, Risk Management Framework (RMF) activities, and ongoing security operations for assigned client systems. This role coordinates security requirements, maintains cybersecurity documentation and system records, supports vulnerability and incident response activities, and works closely with ISSMs, system owners, and other program stakeholders.
Responsibilities
- RMF & Cybersecurity Compliance
- Support Information System Security Managers (ISSMs) in carrying out cybersecurity responsibilities for assigned systems.
- Coordinate cybersecurity processes and activities in accordance with NAVSEA, Department of the Navy, and Department of Defense policies.
- Maintain current cybersecurity policies, procedures, Security Plans, and other required system documentation.
- Track and report Assessment and Authorization (A&A) and Assess Only (AO) status to program and system stakeholders.
- Support identification of security control baselines and applicable overlays.
- Conduct RMF Standard Operating Procedure reviews and support resolution of assessment findings.
- Register and maintain assigned systems in Enterprise Mission Assurance Support Service (eMASS).
- Security Controls & Continuous Monitoring
- Coordinate security control testing with Navy Qualified Validators in support of Risk Assessments and Annual Security Reviews.
- Manage Plans of Action and Milestones (POA&Ms), including tracking vulnerabilities through mitigation and remediation.
- Monitor changes to security system posture and report relevant updates to the ISSM.
- Execute continuous monitoring requirements in accordance with the System Level Continuous Monitoring strategy.
- Review continuous monitoring data, update eMASS records as needed, and escalate issues requiring leadership action.
- Correlate findings from vulnerability assessments, penetration testing, operational testing, and other security activities to applicable RMF controls.
- Participate in change control and configuration management activities.
- Vulnerability & Incident Support
- Conduct cybersecurity vulnerability and threat analysis for assigned systems.
- Maintain vulnerability information in Vulnerability Remediation Asset Manager (VRAM).
- Support cybersecurity incident response, including isolating potentially affected assets, performing initial investigation and data collection, and providing status updates and reporting.
- Coordinate required security changes across organizational levels to maintain compliance with applicable policies and requirements.
- Carry out other related duties as assigned to support evolving client, project, and company needs.
Clearance Level
- Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required. Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines.
Required Qualifications
- Experience:
- At least 6 years of professional cybersecurity experience, including experience with:
- Coordinating and implementing required security changes across multiple levels of an organization.
- Ensuring compliance with established cybersecurity policies and requirements.
- Conducting cybersecurity vulnerability and threat analysis.
- Supporting cyber incident response, including asset isolation, initial investigation, data collection, and status reporting.
- Education/Certification:
- Bachelor’s degree in computer science, information technology, communications systems management, or an equivalent STEM field.
- One of the following certifications:
- Certified Authorization Professional (CAP)
- CompTIA Advanced Security Practitioner Continuing Education (CASP+ CE)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP) or Associate of ISC2
- GIAC Security Leadership Certification (GSLC)
- Certified Chief Information Security Officer (CCISO)
- HealthCare Information Security and Privacy Practitioner (HCISPP)
- Skills:
- Strong knowledge of RMF, A&A, cybersecurity controls, and continuous monitoring activities.
- Experience working with eMASS, POA&Ms, vulnerability tracking, and cybersecurity documentation.
- Ability to analyze security risks, vulnerabilities, and changes in system security posture.
- Strong documentation, organization, and technical communication skills.
- Ability to coordinate effectively with ISSMs, system owners, validators, program managers, and technical teams.
Preferred Qualifications
- Experience supporting Navy or Department of Defense RMF and cybersecurity programs.
- Experience with VRAM, Navy cybersecurity processes, or security control validation activities.
Location & Commitments
- Position: Full Time
- Work Arrangement: Hybrid – On-site at our client site in Philadelphia, Pennsylvania. The number of days on-site will be determined by client needs after hire.
- Travel Requirements: May be required
- Location Preference: Must reside within a 50-mile radius of Philadelphia, Pennsylvania, due to the on-site/hybrid nature of the position.
- Work Hours: A typical workday consists of eight hours, totaling a forty-hour workweek. We understand that there may be times when employees will need to adjust their work hours due to client needs or personal reasons. To help balance these demands, we offer some flexibility in work schedules.
What We Offer
- Competitive salary and discretionary bonuses.
- Comprehensive health benefits, including medical, dental, and vision insurance.
- Flexible Paid Time Off (PTO) and holidays to help you maintain a healthy work-life balance.
- Opportunities for professional development and continued learning.
- Hybrid/remote work arrangement with flexible hours.
- 401(k) retirement plan with company match.
- Employee recognition programs and company events.
JMA Resources is an equal opportunity employer committed to achieving a workforce with an environment free of discrimination and harassment. All aspects of employment, including recruitment, hiring, promotions, transfers, discipline, terminations, wage and salary administration, benefits, and training, are based on business needs, job requirements, and individual qualifications, without regard to race, age, color, physical or mental disability, religion, gender, sexual orientation, gender identity/expression, marital status, national origin, political affiliation or protected veteran status.
At JMA Resources, we are dedicated to fostering an inclusive environment for all qualified individuals. We provide reasonable accommodations to persons with disabilities to ensure equal access throughout the application and hiring process. If you need assistance or require an accommodation, please reach out to Amy Foy, VP of Employee Experience, at [email hidden] .
JMA Resources participates in E-Verify to confirm the identity and employment eligibility of all newly hired employees.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
