Federal Cloud Information Systems Security Officer (ISSO) – Tenable / Air-Gapped Environment -- (Clearance Required, Secret) MD, OK, UT, PA, AL

Hewlett Packard EnterpriseAll, Oklahoma, United States of America, MD
$105,500 - $243,000Hybrid

About The Position

Hewlett Packard Enterprise (HPE) is seeking a Federal Cloud Information Systems Security Officer (ISSO) to join their SecOps Engineering function. This role is responsible for ensuring the security, compliance, and operational effectiveness of classified cloud environments, with a primary focus on Tenable (Tenable.sc / Nessus) vulnerability scanning operations within an air-gapped architecture. The ideal candidate will have a strong background in ISSO oversight, hands-on vulnerability management, and secure cloud engineering, with the ability to work in classified, disconnected environments. This position requires deep knowledge of federal security frameworks, an automation mindset, and the ability to thrive in a fast-paced, mission-critical setting. The role is designated as 'Remote/Teleworker' but requires travel to customer sites 2-3 times a week. US Citizenship and a Secret or Top Secret clearance are mandatory.

Requirements

  • US Citizen
  • Secret Clearance Required
  • DD8750 - Security Plus or higher Security Certification (CISSP, CASP, etc)
  • One or more of the following: AWS Certified Solution Architect, Microsoft Certified Azure Solution Architect, Google Certified Professional Cloud Architect
  • Networking: TCP/IP, DNS, firewalls, segmentation, secure enclaves
  • Operating Systems: Windows Server, Linux (RHEL, Ubuntu), system hardening
  • Security Tools: Tenable.sc / Nessus (expert-level required)
  • SIEM (Splunk, Elastic, QRadar)
  • Endpoint security (CrowdStrike, SentinelOne)
  • Cloud & Hybrid Security: AWS GovCloud, Azure Government, hybrid cloud architectures
  • Strong knowledge of NIST RMF / 800-53 controls
  • Strong knowledge of DISA STIGs and SRGs
  • Strong knowledge of ATO lifecycle processes
  • Vulnerability Management Expertise: Scan policy development and tuning, Credentialed vs non-credentialed scanning, STIG audit file management and compliance validation, Risk prioritization based on mission impact (not just CVSS), POA&M lifecycle management
  • Incident Response & forensic analysis
  • Vulnerability assessment and remediation tracking
  • Security hardening across OS, applications, and network devices
  • Log analysis, event correlation, and threat intelligence integration
  • Strong troubleshooting and root cause analysis
  • Bachelor's degree preferred or Associate degree holder (technical field) with 6-8 years working experience in related fields desired.

Nice To Haves

  • Scripting (Python, Bash, PowerShell)
  • Experience operating in classified or air-gapped environments
  • Experience supporting DISA or other DoD customers
  • Familiarity with eMASS and ATO documentation systems
  • Operating systems Level certifications are a plus

Responsibilities

  • Serve as primary ISSO supporting ATO, RMF, and continuous monitoring activities
  • Develop and maintain ATO artifacts (SSP, POA&M, SAR, control narratives) aligned to NIST 800-53
  • Ensure compliance with DISA STIGs and federal security standards
  • Support audits and assessments, including evidence collection and vulnerability closure validation
  • Own and operate Tenable platform and distributed Nessus scanners in an air-gapped environment
  • Configure scan policies, audit files, credentials, repositories, and scan zones
  • Execute and manage credentialed vulnerability scans, STIG compliance scans, and port and discovery scans
  • Manage offline plugin and audit content updates in accordance with air-gapped constraints
  • Ensure full asset coverage, scan accuracy, and remediation tracking across all environments
  • Generate and deliver vulnerability reports supporting ATO and DISA reporting requirements
  • Analyze scan results to identify false positives, credential failures, and scan gaps
  • Translate scan findings into POA&M entries and track remediation to closure
  • Maintain secure operations within a disconnected/isolated environment (no outbound connectivity)
  • Manage manual update processes for plugins, definitions, and audit content
  • Ensure proper segmentation, scanner placement, and network reachability for scan execution
  • Support data export, sanitization, and reporting workflows for external consumption
  • Monitor logs, alerts, and scan outputs to detect security events
  • Support incident response lifecycle: detection, containment, eradication, recovery
  • Correlate vulnerability data with active threats and mission risk
  • Work with Cloud, Network, and Platform Engineering teams to integrate security into system design, remediate vulnerabilities, improve hardening baselines, and provide technical guidance on secure configurations and STIG implementation
  • Automate vulnerability management, reporting, and compliance processes
  • Improve efficiency in scan execution, data parsing, and remediation workflows
  • Contribute to continuous improvement of security posture

Benefits

  • Health & Wellbeing comprehensive suite of benefits that supports their physical, financial and emotional wellbeing
  • Personal & Professional Development programs catered to helping you reach any career goals
  • Unconditional Inclusion
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service