Information Systems Security Officer

Position Summary: The Information Systems Security Officer (ISSO) is responsible for supporting the security, compliance, and ongoing authorization of organizational information systems, with particular emphasis on systems that process, store, or transmit Controlled Unclassified Information (CUI) and other sensitive information. This role works closely with IT, System Owners, Business Stakeholders, leadership and third-party security partners to implement and maintain security controls, monitor system security, manage compliance documentation, identify and remediate vulnerabilities and support cybersecurity assessments and audits. This position plays a key role in maintaining compliance with applicable cybersecurity requirements including CMMC Level 2, NIST SP 800-171, DFARS requirements and organizational security policies and procedures.

Key Responsibilities:

Security & Compliance Management – Maintains compliance with applicable cybersecurity requirements, including CMMC Level 2, NIST SP 800-171, DFARS, ITAR, PCI DSS, and company security policies
Security Control Oversight – Ensures required security controls are implemented, operating effectively, documented, and periodically reviewed
CMMC & Audit Readiness – Maintains continuous readiness for C3PAO and other cybersecurity assessments, including coordinating evidence collection, control validation, and remediation. SPRS score maintenance and subcontractor flow-down compliance
Security Documentation – Maintains the System Security Plan (SSP), POA&Ms, policies, procedures, risk assessments, control evidence, and other required compliance documentation
Vulnerability & Risk Management – Identifies, assesses, tracks, and coordinates remediation of vulnerabilities, security deficiencies, and compliance gaps
Daily hands-on SIEM/XDR review
Access & System Security – Reviews access controls, privileged accounts, system configurations, security baselines, logging, encryption, and other protections for sensitive systems and CUI
Security Monitoring & Incident Response – Actively monitors security events and alerts and coordinates with IT and security/SOC providers to monitor security events, investigate incidents, document findings, and work directly with IT and security/SOC providers through appropriate remediation
Technology & Vendor Security Reviews – Evaluates new applications, SaaS platforms, AI tools, hardware, vendors, and system changes for cybersecurity and compliance risks
CUI Protection & Scope Management – Helps maintain the security boundary for systems that store, process, or transmit CUI and ensures appropriate handling and protection requirements are followed
Policy & Security Awareness/Tracking/Reporting – Develops and maintains cybersecurity policies, standards, procedures, and security-awareness requirements. Track and report Security Awareness metrics.
Cross-Functional Coordination – Works with IT, Legal, Contracts, business owners, leadership, vendors, consultants, and assessors to address cybersecurity and compliance requirements
Continuous Improvement – Monitors changes in cybersecurity requirements and threats and recommends improvements to strengthen the organization's overall security posture
Other duties as assigned

Required Qualifications

Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field; equivalent relevant experience may be considered in lieu of a degree
3+ years of experience in cybersecurity, information security, IT security, systems administration, IT compliance, or a related technical field
Working knowledge of cybersecurity frameworks and requirements, particularly NIST SP 800-171 and CMMC Level 2
Hands-on experience working in a DOD/DOW contractor or subcontractor environment
Experience with Tenable.io, Microsoft Sentinel, and Microsoft Defender for Endpoint (or comparable SIEM/XDR/vulnerability management platforms)
CompTIA Security+ CE certification
Understanding of core security concepts, including access control, identity management, least privilege, encryption, vulnerability management, system hardening, logging, monitoring, and incident response
Experience implementing, maintaining, or assessing technical and administrative security controls
Experience creating and maintaining cybersecurity documentation, including policies, procedures, System Security Plans (SSPs), POA&Ms, risk assessments, and compliance evidence
Familiarity with Microsoft Windows, Active Directory, Microsoft 365, Azure/Entra ID, and enterprise security technologies
Ability to identify cybersecurity risks and compliance gaps and coordinate remediation with technical teams and system owners
Strong analytical, troubleshooting, organizational, and documentation skills
Strong written and verbal communication skills, with the ability to communicate cybersecurity requirements and risks to both technical and non-technical stakeholders
Ability to appropriately handle Controlled Unclassified Information (CUI) and other sensitive or proprietary information. Ability to work independently, manage multiple priorities, and collaborate effectively with IT teams, business stakeholders, vendors, auditors, and leadership

Preferred Qualifications

Certified CMMC Professional (CCP)
Experience with Governance, Risk, and Compliance (GRC) system documentation
Experience with Tenable.IO vulnerability management

Additional Requirements

Ability to travel as required, less than 10%
US Citizenship
Possess or able to obtain US Passport and can travel domestically/internationally
Ability to obtain and maintain a DOD Secret Clearance

Working Conditions

Monday - Friday 7 a.m. - 4 p.m., with flexible hours based on operational needs
Prolonged periods of sitting at a desk and working on a computer
Ability to view computer screens for extended periods, with close vision and the ability to adjust focus
Ability to maintain focus and perform repetitive tasks with attention to detail
Regularly works in office environments and around aircraft hangars

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available