Information Systems Security Officer (Onsite- Scott Air Force Base, IL)
Ellumen, named a Top Workplace by the Washington Post, is a dynamic small business headquartered in Silver Spring, MD. We specialize in providing a wide range of information technology and ancillary services to both government and commercial clients. Our team is currently seeking a remote Information Systems Security Officer to o provide Information Assurance / Information Protection (IA/IP) services at Scott Air Force Base (SAFB), IL
The Information System Security Office is responsible for implementing and maintaining information assurance and cybersecurity controls for Air Force information systems. The ISSO supports mission assurance by protecting the confidentiality, integrity, and availability of Department of Defense and Air Force data and networks in compliance with DoD, AF, and Air Combat Command (ACC) cybersecurity policies, standards, and regulations.
Responsibilities
- Implement, monitor, and enforce information assurance (IA) and cybersecurity policies, plans, and procedures for assigned systems.
- Ensure cybersecurity controls are selected, implemented, documented, and operate as intended throughout the system lifecycle.
- Support Risk Management Framework (RMF) activities including development/maintenance of Security Plans (SSP), Plans of Actions & Milestones (POA&M), Continuous Monitoring (ConMon), and Assessment & Authorization (A&A) packages.
- Conduct periodic security assessments, audits, and compliance reviews to identify vulnerabilities and track remediation.
- Reviewing scan results, security logs, event alerts, and configurations.
- Track and report remediation status; update documentation and plans as vulnerabilities are mitigated.
- Identify, log, report, and help coordinate response to security incidents, working system owners and leadership.
- Provide security assessments, corrective actions, and compliance guidance.
- Maintain current and accurate security documentation and records for reporting to leadership and higher-level cybersecurity offices.
- Coordinate and document configuration changes and assess their security impact.
Qualifications
- Bachelor's degree in Cybersecurity, Information Systems, or a related technical field preferred.
- Minimum of 3 years of hands-on experience supporting RMF or similar compliance frameworks.
- Knowledge of NIST RMF standards (800-37, 800-53, 800-30).
- Experience with cybersecurity tools and risk management platforms (e.g., eMASS, ACAS, STIGs, SCAP tools).
- Active DoD 8570.01-M certification (e.g., Security+, CAP, or CISSP).
- Strong written and verbal communication skills.
- Ability to work independently and collaboratively in a fast-paced environment.
- Sec+ certification and CAP or International Information System Security Certification Consortium (ISC)2, Certified in Governance, or Risk and Compliance.
- Active U.S. government Secret security clearance
|