Senior Information System Security Officer (ISSO) – WSMR, New Mexico

ASRC Federal•White Sands Missile Range, NM
•Onsite

About The Position

ASRC Federal Technology Solutions LLC is seeking an experienced Information System Security Officer (ISSO) to support the DEVCOM-CBC and the Transformation Decision Analysis Center (TDAC) organization at White Sands Missile Range, NM. This role is crucial for developing, implementing, and maintaining cybersecurity policies, standards, and procedures to ensure compliance with Department of Defense (DoD), Army, and DEVCOM CBC regulations. The ISSO will provide cybersecurity support to the DEVCOM-CBC TDAC G6 Cybersecurity Branch, focusing on Risk Management Framework (RMF) activities, cybersecurity assessments, and incident response. The position requires a strong understanding of cybersecurity principles, analytical skills, and effective communication abilities to manage a diverse portfolio of compliance and accounts across various system types.

Requirements

  • Bachelor’s degree (BA/BS) in Computer Science, Information Technology, Engineering, or a related field or 4 additional years of experience (for a total of 5 years) in lieu of the degree
  • 5 or more years of hands-on RMF EMASS Authorization duties
  • Working knowledge of DoD and Army cybersecurity regulations including Army Regulation 25-2, DoD 8140, and DoD RMF policy
  • Experience with Active Directory account management and STIG/SRG audit processes
  • Familiarity with the Army Account Validation System (AVS) or equivalent DoD workforce compliance tracking platforms
  • Active Secret security clearance

Nice To Haves

  • Direct experience with eMASS, POA&M and RMF processes and responsibilities
  • Experience serving as an Enhanced Trusted Agent for PKI hardware token issuance
  • Experience performing Software Assurance or Hardware Assurance reviews for DoD networks
  • Familiarity with NSA and Army data sanitization and destruction policy
  • Experience coordinating Negligent Disclosure of Classified Information or classified spill incident response
  • CISSP, CASP+, or CISM certification
  • Experience supporting DEVCOM or Army G6 cybersecurity programs

Responsibilities

  • Maintain current Authority to Operate (ATO) status for DEVCOM systems and provide RMF guidance and support to other ACC locations with similar systems.
  • Develop, update, and/or modify system-level artifacts (e.g., TTPs, plans, policies, procedures, hardware/software lists, data flow, system architecture diagrams, PIAs, Ports/Protocols/Services, MOA/MOU, etc.) and ensure they are associated with corresponding controls in eMASS.
  • Obtain, run, analyze, and import all applicable vulnerability scanners and compliance checkers as required, including STIGs, Nessus/ACAS Scans, etc.
  • Track and report IAVAs related to DEVCOM systems.
  • Create, modify, and/or maintain all aspects of the implementation plan and test results, as defined by DOD, Army, NETCOM, and DEVCOM requirements.
  • Manage Plans of Action and Milestones (POA&M), including development, status updates, milestone tracking, and closure.
  • Manage assigned network packages within eMASS and maintain accurate, current authorization documentation.
  • Create, modify, and/or maintain all aspects of CONMON.
  • Utilize existing or develop custom solutions to facilitate RMF requirements, reduce timelines and provide up-to-date status reporting of compliance.
  • Update and track cybersecurity test results, implementation plans, and risk assessments.
  • Evaluate STIG checklists and document compliance status, deficiencies, and required remediation actions.
  • Perform first-response coordination for Negligent Disclosure of Classified Information incidents in accordance with organization SOPs for incident response.
  • Conduct vulnerability management activities, including identifying, tracking, and coordinating corrective actions.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service