Info Systems Security Officer - Administration

SkyWater Technology Foundry, Inc.Bloomington, MN
$78,240 - $117,360Hybrid

About The Position

The Information Systems Security Officer provides day-to-day support to the ISSO, ISSM, and Cyber Governance, Risk, and Compliance (GRC) function across both governed environments (commercial and federal) while developing along a structured path from analyst toward security engineer. The role assists with security documentation, authorization and audit evidence, continuous monitoring records, and SOC and incident-response activity, and receives supervised, hands-on exposure to control implementation, system hardening, secure configuration, and remediation validation. This is a developmental and supervised role that supports, rather than independently owns, ISSO, ISSM, and Cyber GRC deliverables. Commercial work follows NIST CSF 2.0, CMMC, and SOX, evidenced in Drata. Federal work follows RMF, NISPOM, and DFARS 252.204-7012, and for ATO, classified, air-gapped, isolated, or CUI/FCI systems is performed only through the ISSM, ISSE, and ISSO approved authorization structure, evidenced in eMASS.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related field. (Four years of relevant professional experience may be considered in place of the degree. Sufficient certifications and industry training may also be considered in place of the degree.)
  • One or more years of relevant professional, internship, military, or substantive academic experience in cybersecurity, IT, systems administration, information assurance, or federal compliance support.
  • Exposure to federal information-security requirements, cybersecurity controls, or the NIST Risk Management Framework, and to maintaining organized technical documentation or compliance evidence.
  • Foundational familiarity with the NIST 800 series (including SP 800-53 and SP 800-171) and the NIST Risk Management Framework and authorization lifecycle.
  • Basic understanding of security controls, continuous monitoring, assessment evidence, and findings management.
  • Basic systems-administration aptitude across Windows, Linux, networking, identity, or cloud domains.
  • Strong documentation, organization, and evidence-handling discipline, with the ability to work within defined authorization and change-management structures.
  • Effective communication with technical, compliance, and leadership stakeholders, and working knowledge of Microsoft Word, Excel, and PowerPoint.
  • Demonstrated interest in developing toward a security engineering role.
  • CompTIA Security+ CE required at the time of hire or within six months of the date of hire (preferred minimum certification).
  • Must meet applicable DoD 8140.03 and DoD Cyber Workforce Framework qualification requirements for the assigned work role and proficiency level, at minimum equivalent to the legacy DoD 8570.01-M Information Assurance Technician Level II baseline and complete any component- or customer-specific requirements for the assigned role.
  • US Citizen with minimum Secret Clearance eligibility (TS/SCI preferred). Must be able to obtain and maintain the clearance and system access required for assigned duties.
  • Must comply with need-to-know, information-handling, personnel-security, facility-security, and authorized-system requirements, and perform federal-system work only within the assigned ISSM, ISSE, and ISSO authorization structure.

Nice To Haves

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related engineering-adjacent field.
  • Two to three years in IT, systems administration, security operations, federal compliance, or information assurance.
  • Hands-on support of eMASS entries, SSP maintenance, POA&M tracking, evidence collection, control assessments, or continuous monitoring, in a government-contractor, cleared, regulated, CUI, or classified environment.
  • Experience supporting technical remediation, vulnerability management, system hardening, or configuration validation, and personal lab, scripting, or homelab experience demonstrating initiative.
  • Basic scripting using PowerShell, Python, Bash, or an equivalent language, and familiarity with DISA STIGs, CIS Benchmarks, and secure configuration practices.
  • Familiarity with Windows or Linux administration, Active Directory, Microsoft Entra ID, networking, cloud, virtualization, or endpoint management, and with vulnerability scanners, GRC platforms (Drata), or authorization systems (eMASS).

Responsibilities

  • Collect, organize, index, review, and maintain control evidence across NIST CSF 2.0, CMMC, NIST SP 800-171, and SOX, supporting Cyber GRC in Drata as the commercial system of record.
  • Support commercial audit readiness, including self-assessments, control reviews, evidence refreshes, and SOX and CMMC assessment activities.
  • Track commercial findings, control deficiencies, and remediation through documented closure or approved risk disposition.
  • Assist with commercial continuous monitoring, including evidence refreshes, configuration reviews, and control-status updates in Drata.
  • Support the ISSO with day-to-day maintenance of federal security artifacts, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control implementation statements, authorization records, and Enterprise Mission Assurance Support Service (eMASS) entries.
  • Assist with eMASS package updates, evidence uploads, control-status updates, milestone tracking, and package-quality reviews.
  • Support assessment and authorization (A&A) package preparation, self-inspections, and government or customer assessment activities under ISSO and ISSM direction.
  • Assist with federal continuous monitoring aligned to NIST SP 800-53 and DFARS 252.204-7012, including evidence refreshes, vulnerability-status and security-control reviews, configuration reviews, change documentation, and authorization-package updates.
  • Preserve authorization-boundary evidence, and perform work on classified, air-gapped, isolated, or CUI/FCI systems only through approved ISSM, ISSE, ISSO, system-administration, and change-management channels.
  • Identify and report undocumented changes, configuration deviations, and missing or expired evidence affecting authorization posture; treat undocumented deviations within a boundary as potential findings and escalate to the ISSO and ISSM.
  • Support NISPOM and ICD-aligned handling, security training records, authorized-user records, and other system-specific compliance records as assigned.
  • Monitor and respond to SOC alerts and detections, and support incident response activations across commercial and federal environments, following environment-specific handling on authorized systems.
  • Work alongside Security Architecture and Engineering to gain hands-on experience with control implementation, secure configuration, and system hardening, evaluating configurations against DISA STIGs, CIS Benchmarks, and organization-approved baselines.
  • Review vulnerability scan results and configuration findings to help determine whether corrective actions adequately address identified deficiencies and support technical validation of remediation as a structured engineering-development activity.
  • Maintain accurate, traceable, assessment-ready documentation in approved systems of record, and coordinate with GRC, Security Engineering, system administrators, and system owners to collect evidence and track assigned actions.
  • Participate in structured training, mentoring, technical labs, and progressively independent assignments that build toward a security engineering role.
  • Performing other duties as assigned. Duties may be modified with concurrence of the Contracting Officer, contractor Program Manager and Information Systems Security Manager (ISSM).

Benefits

  • 401k match
  • life insurance
  • opportunities to purchase SkyWater stock at a discounted rate
  • medical
  • dental
  • mental health benefits
  • vision
  • legal planning
  • short- and long-term disability
  • paid time off
  • paid holidays
  • on-site fitness facility
  • on-site self-serve market
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service