ISSO Support Specialist
Position Summary
Creek Technologies is seeking an experienced Information Systems Security Officer (ISSO) Support Specialist to provide direct cybersecurity and Information Assurance support to Information Systems Security Officers (ISSOs) and Information System Security Managers (ISSMs) supporting highly classified environments.
The successful candidate will assist with Risk Management Framework (RMF) activities, security documentation and certifications, vulnerability assessments, compliance audits, media accountability, and the day-to-day security operations of Special Access Program (SAP) and Sensitive Compartmented Information (SCI) environments. This position requires extensive knowledge of Department of Defense (DoD) cybersecurity requirements and the ability to operate effectively within Top Secret/SCI environments.
Primary Responsibilities
- Provide direct support to the Information Systems Security Officer (ISSO) and Information System Security Manager (ISSM) for cybersecurity, Information Assurance (IA), and information system security activities.
- Assist with planning, organizing, implementing, and overseeing day-to-day security operations supporting SAP and SCI facilities and information systems.
- Monitor and verify classified information systems and communications environments for compliance with applicable cybersecurity requirements, including NIST SP 800-53, CNSSI 1253, JSIG, and applicable DoD and Department of the Air Force security directives.
- Prepare, review, maintain, and coordinate security documentation required to support system authorization, certification, and continuous monitoring activities across multiple classification levels.
- Support Risk Management Framework (RMF) activities, including implementation, validation, documentation, and ongoing monitoring of required security controls.
- Assist the ISSM and ISSO with processes related to acquiring, deploying, operating, maintaining, and supporting secure information system environments.
- Provide cybersecurity and Information Assurance recommendations to ISSOs, ISSMs, Information System Owners (ISOs), system administrators, and other program personnel.
- Support SAP Enterprise IT Portfolio Management and associated Information Assurance activities.
- Conduct periodic security reviews, assessments, and required audits of SAP information system environments to ensure continuous compliance with established security requirements.
- Prepare, maintain, and organize security records, audit documentation, system logs, and supporting materials for government review.
- Perform routine vulnerability, configuration, and compliance scanning of information system assets and provide findings and recommendations to the ISSO.
- Assist with tracking identified vulnerabilities, security deficiencies, remediation activities, and compliance requirements.
- Maintain and continuously update comprehensive inventories and accountability records for optical, digital, and other controlled media across multiple SAP facilities.
- Assist system administrators with the secure operation and maintenance of assigned information systems.
- Support the proper sanitization, disposition, and disposal of IT assets and data storage devices in accordance with approved security policies and procedures.
- Assist with cybersecurity incident identification, documentation, reporting, and coordination as required.
- Provide technical guidance and cybersecurity support to program personnel, junior specialists, and supporting contractors.
- Establish and maintain effective working relationships with AFRL field units, HQ AFMC staff offices, Air Staff, AFOSI, SAF, and other Department of Defense organizations.
- Perform additional cybersecurity and information system security duties as required in support of mission objectives.
Required Qualifications
- Demonstrated experience supporting information systems security, cybersecurity, Information Assurance, or related functions within DoD or other classified government environments.
- Experience supporting Information Systems Security Officers (ISSOs), Information System Security Managers (ISSMs), or comparable cybersecurity personnel.
- Working knowledge of the DoD Risk Management Framework (RMF) and security control implementation and assessment.
- Knowledge of applicable cybersecurity frameworks and guidance, including:
- NIST SP 800-53
- CNSSI 1253
- Joint Special Access Program Implementation Guide (JSIG)
- Applicable DoD and Department of the Air Force cybersecurity and security directives
- Experience preparing and maintaining cybersecurity, system authorization, assessment, audit, or compliance documentation.
- Experience conducting or supporting vulnerability and compliance scanning of information systems.
- Ability to analyze security findings, identify compliance deficiencies, and communicate recommended corrective actions.
- Experience working with classified information systems and following established handling, accountability, and security procedures.
- Strong documentation, organizational, analytical, and communication skills.
- Ability to work collaboratively with cybersecurity professionals, system administrators, program personnel, government stakeholders, and supporting contractors.
- Ability to work in SAP and SCI environments and comply with all applicable security requirements.
- Must be willing and able to execute a Non-Disclosure Agreement (NDA).
Security Clearance Requirements
- Active Top Secret (TS) security clearance required.
- Must possess or be eligible for Sensitive Compartmented Information (SCI) access as required by the position.
- Position is designated Special-Sensitive and requires continued eligibility for access to classified information and systems.
Preferred Qualifications
- Previous cybersecurity or ISSO/ISSM support experience within the Department of the Air Force, AFRL, AFMC, or another DoD organization.
- Experience supporting Special Access Programs (SAPs).
- Experience with SAP and SCI information system environments.
- Experience performing RMF assessments, continuous monitoring, vulnerability management, security control validation, or system authorization activities.
- Familiarity with secure media management, sanitization, destruction, and IT asset disposition requirements.
- Relevant DoD cybersecurity certification or industry certification such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent
Benefits
Creek Technologies offers a competitive salary, performance incentives, comprehensive medical, dental, and vision insurance, 401(k) with company match, paid time off, paid holidays, professional development opportunities, and the opportunity to support mission-critical national security and defense programs.
Other:
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
We recognize that people come with a wealth of experience and talent beyond just the technical requirements of the job. If your experience is close to what you see listed here, please still consider applying. Diversity of experience and skills combined with passion is a key to innovation and excellence; therefore, we encourage people from all backgrounds to apply to our positions. Please let us know if you require accommodation during the interview process.
Creek Technologies Company is proud to be an equal opportunity employer that is committed to diversity and inclusion in the workplace. Creek Technologies considers all applicants for employment without regard to race, color, sex, sexual orientation, gender, gender identity, age, religion, nation origin, pregnancy, child or spousal support withholding, disability, marital status, genetic information, citizenship/immigration status, military/veteran status, or any other status protected by federal, state, or local law. Creek Technologies makes hiring decisions based solely on qualifications, merits and business needs at the time. Upon request, Creek Technologies will reasonably accommodate applicants with a disability who need accommodation during the application process, unless accommodation creates an undue hardship for the company.
What they ask for
Required
- Demonstrated experience supporting information systems security, cybersecurity, Information Assurance, or related functions within DoD or other classified government environments.
- Experience supporting Information Systems Security Officers (ISSOs), Information System Security Managers (ISSMs), or comparable cybersecurity personnel.
- Working knowledge of the DoD Risk Management Framework (RMF) and security control implementation and assessment.
- Knowledge of applicable cybersecurity frameworks and guidance, including: NIST SP 800-53 CNSSI 1253 Joint Special Access Program Implementation Guide (JSIG) Applicable DoD and Department of the Air Fo
- Experience preparing and maintaining cybersecurity, system authorization, assessment, audit, or compliance documentation.
- Experience conducting or supporting vulnerability and compliance scanning of information systems.
- Ability to analyze security findings, identify compliance deficiencies, and communicate recommended corrective actions.
- Experience working with classified information systems and following established handling, accountability, and security procedures.
- Strong documentation, organizational, analytical, and communication skills.
- Ability to work collaboratively with cybersecurity professionals, system administrators, program personnel, government stakeholders, and supporting contractors.
- Ability to work in SAP and SCI environments and comply with all applicable security requirements.
- Must be willing and able to execute a Non-Disclosure Agreement (NDA).
Preferred
- Previous cybersecurity or ISSO/ISSM support experience within the Department of the Air Force, AFRL, AFMC, or another DoD organization.
- Experience supporting Special Access Programs (SAPs).
- Experience with SAP and SCI information system environments.
- Experience performing RMF assessments, continuous monitoring, vulnerability management, security control validation, or system authorization activities.
- Familiarity with secure media management, sanitization, destruction, and IT asset disposition requirements.
- Relevant DoD cybersecurity certification or industry certification such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent