Information System Security Officer (ISSO)

NoblisHuntsville, AL
Onsite

About The Position

Noblis is seeking an Information System Security Officer (ISSO) to support the Threat Systems Management Office (TSMO) in Huntsville, AL. The TSMO's mission is to manage Army Threat System Programs, encompassing the full lifecycle of threat systems for testing and training in live, virtual, and constructive environments. They design, build, and test representations of operational and emerging hostile systems with identical performance capabilities to the identified threat, ensuring these systems are continually updated with state-of-the-art technology. TSMO also conducts threat assessment and analysis in conjunction with Army, Navy, and other joint services. The TSMO utilizes simulators, simulation models, foreign material acquisition, commercial-off-the-shelf (COTs) products, and new development efforts to provide relevant Electronic Warfare (EW), Information Operations (IO), integrated air defense (IADs), and command and control (C2) capabilities for Operational Test and Evaluation (OT&E) events, including Network Integration Evaluations (NIEs) and Combatant Commander events. The ISSO will lead the Risk Management Framework (RMF) process for assigned systems, supporting the entire DoD RMF lifecycle from system categorization and control implementation to assessment, authorization, and continuous monitoring. This role requires a strong understanding of developing RMF packages for Authority to Operate (ATO) and proficiency with the Enterprise Mission Assurance Support Service (eMASS) system for data input, record maintenance, and navigation. The ISSO will identify system vulnerabilities, determine appropriate security controls, and prepare documentation for ATO activities. They will also conduct vulnerability and security compliance assessments using tools like ACAS/Nessus, SCAP Compliance Checker (SCC), STIG Viewer, and Evaluate-STIG, analyzing results, documenting deficiencies, supporting remediation, and maintaining compliance evidence with NIST, DoD, DISA, and Army cybersecurity requirements.

Requirements

  • Bachelor's degree in a related field or 7+ years direct experience.
  • Minimum 5 years of experience in cybersecurity/Information Assurance, with demonstrated RMF/ISSO experience.
  • Demonstrated experience with DoD RMF and obtaining and maintaining ATOs.
  • Demonstrated hands-on experience with eMASS.
  • Experience conducting vulnerability and STIG/compliance scans using ACAS/Nessus, SCC, STIG Viewer, Evaluate-STIG, or equivalent tools.
  • Working knowledge of NIST SP 800-53 and DoD cybersecurity policies.
  • DoD 8570/8140-compliant IAT Level II certification (Security+ CE or higher).
  • Active DoD Secret clearance with the ability to obtain a Top Secret clearance
  • Superior attention to detail and organizational skills.
  • Excellent communications skills.
  • US Citizenship
  • Strong analytical and problem-solving skills

Nice To Haves

  • Prior official assignment as an ISSO or ISSM
  • Prior experience serving as an ISSO supporting DoD or Army systems.
  • Top Secret/SCI security clearance.
  • Experience supporting classified and/or multi-level security environments.
  • Experience with Windows, Linux, VMware, and system security/hardening.
  • Desired Certifications: CISSP, SecurityX / CASP+, CySA+, or other applicable cybersecurity certifications.

Responsibilities

  • Serves as an Information Systems Security Officer and will develop and advise on RMF packages, strategies, and technical components to ensure compliance with NIST 800-53 security controls.
  • Assist in the implementation of the required government policy (i.e., NISPOM, NIST, DoD), and documenting process activities.
  • Develop security artifacts to support the Information Assurance program to include System Security Plans (SSP), Plan of Action and Milestones (POA&M), System Diagrams, System User Guides, Privileged User Guides, and other documentation as needed.
  • Perform self-assessments of systems and networks within the environment, using passive evaluation audit tools such as: STIG Viewer, SCAP Compliance Checker (SCC), and active evaluations through ACAS/NESSUS.
  • Track enterprise reporting and efficiencies through automatic generation of required security compliance reports, integration of security tools, system documentation, and other artifacts utilizing the Enterprise Mission Assurance Support Service.
  • Track security updates for Windows and Linux-based operating systems, VMWare based products, and associated software applications to ensure compliance.
  • Periodically conduct a review of system audits, monitor corrective actions until all actions are closed, and identify deficiencies during RMF assessment activities.

Benefits

  • health
  • life
  • disability
  • financial
  • retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service