Information Systems Security Officer (ISSO)

PeopleTec, Inc.Huntsville, AL
Onsite

About The Position

PeopleTec is currently seeking an Information Systems Security Officer (ISSO) to support our Huntsville, AL location. This is a Senior Information Systems Security Officer (ISSO) position responsible for overseeing risk management, security compliance, and cybersecurity operations for the cloud-based information systems supporting the Guam Defense System (GDS). This role serves as a key technical and compliance advisor, ensuring systems conform to the Risk Management Framework (RMF), National Institute of Standards and Technology (NIST) guidelines, and DoD Cloud Computing Security Requirements Guide (SRG) for Impact Level 6 (IL6) data.

Requirements

  • Minimum of nine (9) years of progressive experience in cybersecurity, information assurance, systems engineering, or related IT fields.
  • At least seven (7) years of direct experience serving as an ISSO or ISSM within a cleared DoD or Intelligence Community (IC) environment.
  • Minimum of three (3) years of hands-on experience securing and managing cloud-based systems (AWS, Azure, or GCP), specifically within federal, defense, or high-security hybrid/multicloud environments (IL5/IL6).
  • Proven experience implementing RMF (NIST SP 800-37, 800-53, 800-137) for tactical, strategic, or defense systems.
  • Mastery of RMF, NIST SP 800-series, CNSSI 1253, and DoD 8500-series instructions.
  • Strong understanding of cloud service models (IaaS, PaaS, SaaS), shared responsibility models, identity and access management (IAM), secure virtual networking, encryption standards (at rest and in transit), and container security (Kubernetes, Docker).
  • Proficiency with enterprise vulnerability management, log aggregation, and system assessment tools.
  • Exceptional written and verbal communication skills, with the ability to translate complex technical vulnerabilities into business/mission risk for senior military leaders.
  • Strong analytical, troubleshooting, and problem-solving skills in high-stakes, fast-paced environments.
  • Candidate must hold an active certification meeting the DoDM 8140.03 IAM Level III requirement: CISSP, GISP, CASP+, or equivalent IAM Level III-approved certification.
  • Candidate must also hold at least one (1) active cloud security or cloud architecture certification from a major provider or recognized organization: CCSP, AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Google Professional Cloud Security Engineer.
  • Ability to travel
  • Must be a U.S. Citizen
  • Active Secret security clearance is required at the time of hire, with the ability to obtain Top-Secret/SCI.

Nice To Haves

  • Familiarity with the operational environment of Integrated Air and Missile Defense (IAMD) systems, Joint All-Domain Command and Control (JADC2) initiatives, and cross-domain solution (CDS) implementation is highly preferred.

Responsibilities

  • Lead and coordinate Risk Management Framework (RMF) Steps 1–6 for GDS, ensuring successful Assessment & Authorization (A&A) cycles and securing/maintaining Authorities to Operate (ATOs).
  • Author and maintain comprehensive cybersecurity documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and boundary diagrams.
  • Design and execute continuous monitoring strategies for GDS cloud environments to capture, analyze, and report real-time compliance and threat vectors.
  • Perform regular vulnerability scans and configurations checks of cloud infrastructure, containerized environments, and serverless applications. Analyze results and collaborate with GDS cloud engineers to prioritize and execute remediation plans.
  • Deploy and utilize enterprise security tools to detect, investigate, and mitigate vulnerabilities and advanced persistent threats (APTs).
  • Support incident response teams during active security events. Lead post-incident forensic investigations, root-cause analyses, and the implementation of permanent remediation measures.
  • Provide expert security architecture recommendations to engineering and DevOps teams implementing DevSecOps pipelines, automated infrastructure-as-code (IaC) deployments, and Zero Trust architectures.
  • Track and report cybersecurity risks, system compliance drift, and mitigation progress directly to GDS program leadership and government Authorizing Officials (AOs).

Benefits

  • continuing-education opportunities
  • robust training programs
  • "People First" benefits package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service