Senior ISSO / ISSE (eMASS and ACAS)

Empower AIQuantico, VA
Onsite

About The Position

Empower AI is seeking a Senior ISSO / ISSE to combine information systems security officer and security engineering responsibilities for the systems managed by an enterprise IT Customer Support Services program supporting a Department of War agency across NIPRNet, SIPRNet, and JWICS enclaves. The role owns the eMASS RMF packages and continuous monitoring for assigned systems as ISSO, and as ISSE engineers and validates STIG/SRG baselines, designs control implementations, leads ACAS vulnerability remediation engineering, and ensures new solutions (endpoint, ITSM/dashboards, collaboration, communications, automation and AI) are designed to achieve and maintain ATO. The Senior ISSO/ISSE produces the weekly Vulnerability Scan Analysis Report and monthly STIG Compliance Report, prepares systems for assessments, and serves as the go-to security engineering expert for engineers and the Risk Management Support Lead. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED.

Requirements

  • Bachelor's degree and a minimum of 10 years of related experience (a Master's degree with 8 years of related experience, or an additional 4 years of related experience in lieu of a degree, may be substituted).
  • Must be a U.S. Citizen.
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start.
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting.
  • Must possess and maintain a current DoD 8570/8140 IASAE Level II baseline certification (e.g., CISSP or Associate, CASP+ CE, or CSSLP).
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision.
  • Minimum of 10 years of cybersecurity experience, including at least 5 years performing information systems security engineering for DoD or Federal systems.
  • Expert knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, DoDI 8510.01, DoDI 8500.01, and DISA STIGs/SRGs.
  • Hands-on experience engineering and validating STIG-compliant configurations for Windows Server, Active Directory, VMware, Linux (RHEL), and network/communications devices, using STIG Viewer, SCAP, and ACAS/Nessus.
  • Experience leading RMF technical package development in eMASS and successfully achieving ATOs.
  • Experience performing security impact analysis and integrating secure development practices (NIST SP 800-218 SSDF) into application and automation delivery.
  • Working knowledge of DoD Zero Trust Strategy/Reference Architecture, DoD ICAM Strategy, and supply chain risk management controls.
  • Excellent technical writing and communication skills; ability to explain security requirements to engineers, developers, and Government stakeholders.

Nice To Haves

  • CISSP-ISSEP or CISSP-ISSAP, CASP+ CE, CSSLP, or GIAC security engineering certifications.
  • Experience supporting Department of War ( DoW ), DoD, or Intelligence Community systems across NIPRNet, SIPRNet, and JWICS enclaves.
  • Experience securing ServiceNow, Microsoft 365 GCC High/Power Platform, Power BI, and Cisco unified communications environments.
  • Experience with cloud security (DISA CCSRG, FedRAMP, IL4/IL5) and automated compliance/Infrastructure-as-Code security tooling.
  • Experience with security engineering for AI/ML and automation capabilities.
  • Familiarity with DoDAF 2.02 architecture views and DoD Cyber Workforce Framework role qualification requirements.

Responsibilities

  • Own the eMASS RMF packages and continuous monitoring for assigned systems as ISSO: SSP, SAR inputs, POA&M management, control implementation statements, artifact collection, ATO expiration tracking and reaccreditation, and assessment preparation and liaison with assessors.
  • Lead ACAS/Nessus vulnerability management engineering: analyze weekly scan results, determine root causes and remediation or mitigation, drive resolver groups to closure within policy timeframes , and produce the weekly Vulnerability Scan Analysis Report.
  • Engineer and validate STIG/SRG-compliant baselines and security control implementations for endpoint, ITSM/dashboard, collaboration, and communications systems using STIG Viewer and SCAP tooling, and produce the monthly STIG Compliance Report.
  • Perform security impact analysis for changes and new capabilities (including automation and AI), integrate secure development (NIST SP 800-218) requirements, and align designs to DoD Zero Trust and ICAM strategies.
  • Lead security engineering for in-scope systems: define security architectures, select and tailor NIST SP 800-53 controls, and design control implementations for endpoint infrastructure, ITSM/dashboard platforms, collaboration and web platforms, and VoIP/VTC/mobile communications.
  • Engineer, validate , and maintain STIG/SRG-compliant baseline configurations for Windows, Linux (RHEL), VMware, Active Directory, network printers, communications equipment, and cloud/SaaS components, using STIG Viewer, SCAP, and automated compliance tooling.
  • Lead vulnerability remediation engineering: analyze ACAS/Nessus results, determine root causes, design and validate remediation or mitigations, and provide technical inputs to POA&Ms and the weekly Vulnerability Scan Analysis Report.
  • Develop and review RMF technical artifacts in eMASS , including control implementation statements, architecture and data flow diagrams, hardware/software lists, ports/protocols/services, and evidence packages, and prepare systems for security control assessments.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service