Information System Security Officer (ISSO)

AmentumSunnyvale, CA
Onsite

About The Position

Amentum is seeking an Information System Security Official for a contract at the National Aeronautics and Space Administration (NASA), Sunnyvale, CA location. The Information System Security Official (ISSO) services provide cybersecurity Subject Matter Experts (SMEs) to support NASA Information Systems. Amentum is a leading provider of engineering, scientific, and program management support services to some of the top agencies in the U.S. Government, including NASA, Defense Advanced Research Projects Agency (DARPA), the Department of Homeland Security and the Intelligence Community.

Requirements

  • Must have an active Top Secret US Government Clearance, with the ability to obtain an SCI Clearance.
  • US Citizenship is required to maintain a Top Secret Clearance.
  • Bachelor of Science degree with 5 years of professional experience in cybersecurity design and development activities
  • Strong oral and written communication skills

Nice To Haves

  • SCI clearance eligibility
  • Experience in NASA Security or served as an ISSO in other agencies.
  • Experience in NASA Risk Information Security Compliance System and Assessment and Authorization.
  • Experience with Cloud Services and classified networks.
  • Certification level to meet DoD 8140 IAT or DoD 8570 IAT Level II certification or higher.

Responsibilities

  • Develop and maintain detailed and accurate System Security Plans (SSP), including security documentation for component and interface specifications, to support appropriate cybersecurity and privacy throughout the information systems’ life cycle
  • Assist the Information System Owner (ISO) and Information System Security Manager (ISSM) in ensuring that all components of the information system are appropriately updated and patched in accordance with Federal and NASA requirements
  • Support the Government with identifying and prioritizing essential system functions or sub-systems required to support essential capabilities or business functions for restoration or recovery after a system failure or during a system recovery event based on overall system requirements for continuity and availability
  • Provide technical guidance to address the adequacy and effectiveness of information security policies, procedures, and practices
  • Ensure that cybersecurity design and development activities are properly documented (providing a functional description of security implementation) and updated as necessary
  • Ensure Privacy Threshold Assessments (PTA) and Privacy Impact Assessments (PIA) are conducted as required
  • Review cyber intelligence threats reports, including but not limited to SOC MARs, SARs, and DHS/CISA Emergency Directives, in order to identify threats to the information system and develop mitigations
  • Provide subject matter expertise and recommendations as part of RMF process activities and development of related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials)
  • Evaluate cloud service providers’ security posture and develop associated recommendations for restrictions, conditions and control responsibility parsing
  • Write Plan of Action and Milestones (POA&M’s) and Risk Based Decisions (RBD’s) for the System Security Plan (SSP) controls within the NASA Risk Information Security Compliance System (RISCS) tool.
  • Ensure contingency plans and system controls are reviewed and tested in accordance with the Agency requirements.
  • Analyze system logs to identify potential issues and perform routine audits of systems and applications.
  • Ensure critical vulnerabilities that require immediate attention are remediated, as identified in the Security Operation Center (SOC) Mitigation Action Recommendation (MAR).
  • Ensure the installation of security/vulnerability patch updates, operating system level patches and upgrades to include new versions.
  • Provide IT security support to communication systems as needed and serve as a technical resource to Information System Security Officer(s) (ISSO) and other IT professionals
  • Assist in the development and updating of the System Security Plan, Contingency Plan, Disaster Recovery Plans, Risk Assessment Report, annual review package, work instructions, policies, and procedural guides affecting the overall IT and security posture of the environment
  • Support the Assessment and Authorization (A&A) process by preparing associated documentation, building, and tracking Plan of Action and Milestones (POA&M), and monitoring A&A activities

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service