Junior Information System Security Officer (ISSO)
Location: NAWS China Lake (Ridgecrest, CA)
Security Clearance Requirement: Top Secret
Telework Eligible? No, work will be performed on-site at NAWS China Lake
What You’ll Do:
Join a mission-focused cybersecurity team protecting critical DoD information systems. As a Junior Information System Security Officer (ISSO), you’ll play a hands-on role in vulnerability management, RMF compliance, and continuous monitoring, gaining valuable experience while directly supporting a mission-critical program. If you’re detail oriented, technically driven, and ready to grow in a high-impact security environment, this is your opportunity to make a difference.
Key Responsibilities:
- Support the implementation and enforcement of cybersecurity policies, standards, and procedures in alignment with DoD RMF requirements.
- Perform vulnerability assessments using tools such as ACAS, SCAP Compliance Checker, and DISA STIG benchmarks to identify and remediate security gaps.
- Apply and validate DISA STIG configurations across Windows, Linux, and network devices to ensure compliance with DoD security standards.
- Assist in continuous monitoring activities, including reviewing audit logs, tracking POA&M items, and supporting security control assessments.
- Contribute to the development and maintenance of RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and related artifacts supporting ATO efforts.
- Coordinate with system owners, engineers, and ISSMs to track vulnerabilities, implement mitigations, and support remediation timelines.
- Review and verify compliance of hardware and software against NIAP Common Criteria certifications and the DISA Approved Products List (APL).
- Support preparation of security authorization packages and interface agreements (MOAs/MOUs) for interconnected systems.
- Conduct risk assessments and assist in identifying mitigation strategies to protect classified and unclassified DoD information systems.
- Participate in cybersecurity working groups and cross-functional meetings to ensure alignment with program milestones and mission objectives.
- Provide user awareness support and assist with incident response documentation and reporting activities.
This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.