Information System Security Officer (ISSO) - Huntsville, AL

Military Spouse Corporate Career NetworkHuntsville, AL
$100,219 - $111,180Onsite

About The Position

This role serves in an Information System Security Officer (ISSO)-type capacity, supporting the system’s cybersecurity posture throughout development, deployment, operations, and sustainment. The position involves performing continuous monitoring activities in accordance with RMF and program requirements, including reviewing security logs, audit records, alerts, vulnerability results, configuration changes, and security-relevant events. The ISSO will analyze security events and log data to identify anomalous activity, potential indicators of compromise, control deficiencies, and compliance concerns, coordinating escalation and response activities as appropriate. This role requires working with system development, deployment, and operations teams to implement and maintain secure system architectures, designs, configurations, and operational procedures, while championing the cybersecurity perspective in decisions related to security controls. The position supports the development, maintenance, and execution of Continuous Monitoring (ConMon) plans, including recurring security control assessments, evidence collection, status reporting, and risk tracking. The ISSO will produce and maintain cybersecurity design documentation, system security documentation, security operating procedures, and other artifacts supporting authorization and ongoing system security, as well as the Security Control Traceability Matrix (SCTM), inheritable control sets, and control implementation statements. The role also involves leading or supporting NIST SP 800-37 Risk Management Framework (RMF) activities, coordinating with various teams to plan, implement, assess, and document security requirements and controls, and tracking security findings, vulnerabilities, control deficiencies, and remediation activities. Additionally, the ISSO will review and map evidence from applicable security requirement sources within the SCTM and RMF evidence package, support system accreditation/certification evaluation and test activities, participate actively in Agile teams, contribute to incident-response preparedness, and plan and execute project tasks supporting cybersecurity, ISSO, RMF, and continuous-monitoring activities.

Requirements

  • Bachelor's degree in Engineering, or a related Science or Mathematics field, plus a minimum of 2 years of relevant experience; or Master's degree, plus 6 months relevant experience.
  • Department of Defense Secret security clearance is required at time of hire.
  • Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information.
  • Due to the nature of work performed within our facilities, U.S. citizenship is required.
  • Strong security mindset and comfort questioning system behavior or operational practices that conflict with key security principles.
  • Experience reviewing, analyzing, and communicating the significance of security logs, audit records, alerts, and vulnerability data.
  • Working knowledge of continuous monitoring, vulnerability management, incident reporting/escalation, security control assessment, and remediation tracking.
  • Knowledge of NIST RMF, NIST SP 800-53 security controls, and DoD cybersecurity authorization processes.
  • Self-directed, self-starting ability with the discipline to manage recurring monitoring, evidence collection, and reporting responsibilities.
  • Ability to execute complex technical and administrative cybersecurity tasks with limited supervision.
  • Excellent ability to communicate security issues, mission impacts, risk decisions, and corrective actions to technical teams, management, and customers.
  • Ability to balance compliance, security risk, operational mission needs, and engineering constraints.

Nice To Haves

  • Cybersecurity System Engineering, Information System Security Officer (ISSO) duties, Risk Management Framework, and Defense in Depth.
  • Experience with security operations, security information and event management (SIEM) tools, log review, audit analysis, vulnerability management, and continuous monitoring.
  • Experience supporting system authorization packages, annual/ongoing assessments, control validation, POA&M management, and authorization-to-operate (ATO) activities.
  • Active cybersecurity certifications such as ISC2 CISSP (preferred), Security+, CEH, CAP, CISM, or similar credentials.
  • Ground-to-satellite communications knowledge and/or ground operations experience.
  • Experience performing requirements analysis, requirements definition, requirements management, functional analysis, performance analysis, system design, and technical trade studies under the leadership of a Lead Cybersecurity System Engineer.
  • Experience analyzing customer requirements, developing system security requirements, and defining allocations to lower-level elements and components.
  • Experience developing and evaluating systems, networks, and information systems to ensure designs meet applicable government security specifications.
  • Experience with Secure Software Factory and Secure DevSecOps practices.
  • Multi-level security domain expertise and cross-domain solution familiarity.
  • Ability to decompose security requirements quickly using an Agile, lightweight approach while avoiding unnecessary requirements bloat and clearly communicating and tracking impacts.
  • Experience supporting programs or organizations with relationships across partners such as Iridium, SDA, Northrop Grumman, York, and Lockheed Martin.
  • Agile program experience.
  • TS/SCI preferred.

Responsibilities

  • Serve in an Information System Security Officer (ISSO)-type capacity, supporting the system’s cybersecurity posture throughout development, deployment, operations, and sustainment.
  • Perform continuous monitoring activities in accordance with RMF and program requirements, including reviewing security logs, audit records, alerts, vulnerability results, configuration changes, and security-relevant events.
  • Analyze security events and log data to identify anomalous activity, potential indicators of compromise, control deficiencies, and compliance concerns; coordinate escalation and response activities as appropriate.
  • Work with system development, deployment, and operations teams to implement and maintain secure system architectures, designs, configurations, and operational procedures.
  • Champion the cybersecurity perspective in decisions related to the implementation, assessment, operation, and verification of security controls.
  • Support the development, maintenance, and execution of Continuous Monitoring (ConMon) plans, including recurring security control assessments, evidence collection, status reporting, and risk tracking.
  • Produce and maintain cybersecurity design documentation, system security documentation, security operating procedures, and other artifacts supporting authorization and ongoing system security.
  • Produce and maintain the Security Control Traceability Matrix (SCTM), inheritable control sets, and control implementation statements to support test traceability and audit readiness.
  • Lead or support NIST SP 800-37 Risk Management Framework (RMF) activities to develop and maintain the body of evidence required for security authorization and ongoing authorization activities.
  • Coordinate with development, test, system administration, and operational teams to plan, implement, assess, and document security requirements and controls.
  • Track security findings, vulnerabilities, control deficiencies, and remediation activities; support development and maintenance of Plans of Action and Milestones (POA&Ms).
  • Review and map evidence from applicable security requirement sources—including STIGs, NCDSMO, DISA guidance, and customer requirements—within the SCTM and RMF evidence package.
  • Support system accreditation/certification evaluation and test activities to ensure technical security features—including identification, authentication, access control, labeling, auditing, and accountability—are implemented and operating as intended.
  • Participate actively in Agile teams to organize, prioritize, execute, and provide status for cybersecurity and continuous-monitoring work efforts.
  • Contribute to incident-response preparedness and coordination by supporting log availability, audit configuration, event triage, reporting, and post-event corrective actions.
  • Plan and execute project tasks supporting the cybersecurity, ISSO, RMF, and continuous-monitoring activities described above.

Benefits

  • 401(k) matching
  • flexible time off
  • paid parental leave
  • healthcare benefits
  • health and wellness programs
  • employee resource and social groups
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service