Cybersecurity ISSO
17 days ago
Mesa
Job Description Location: Mesa, AZ with occasional travel CONUS Clearance: Eligibility for Government Security Clearance required Job Type: Full-Time | Contract Travel: Occasional CONUS/OCONUS Medical Requirements: Ability to meet Army Conus Replacement Center (CRC) MOD-17 medical requirements for deployment. Company Overview Elevated Technologies, LLC is a premier provider of cutting-edge technology solutions, specializing in information technology, aviation maintenance, and intelligence, surveillance, and reconnaissance (ISR) platforms. We deliver mission-critical services to government and commercial clients with a steadfast commitment to excellence and security. We are seeking a highly skilled Cybersecurity Information Systems Security Officer (ISSO) to support Foreign Military Sales (FMS) programs, ensuring compliance with rigorous cybersecurity standards. Position Overview The Cybersecurity ISSO will oversee the development, implementation, and continuous monitoring of cybersecurity and information assurance measures for the ASRR Aerostat System under a DoD FMS program. This role ensures compliance with U.S. and host-nation cybersecurity policies, managing the secure design, accreditation, and sustainment of airborne and ground-based systems. The ISSO will drive robust cyber hygiene, secure network architecture, and effective risk management throughout the system lifecycle. Key Responsibilities Cybersecurity Oversight & Risk Management Framework (RMF) • Architecture & Design: Lead the development and integration of secure system architecture for the ASRR, ensuring compliance with DoDI 8500.01, DoDI 8510.01 (RMF), AR 25-2, and Combatant Command (CCMD) cybersecurity requirements., • ATO Accreditation: Spearhead efforts to achieve and maintain Authorization to Operate (ATO) for DoD and host-nation systems, managing all RMF lifecycle phases, including documentation, control implementation, and assessments. Coordinate with U.S. Government Authorizing Officials (AOs) and Partner Nation Security Accreditation Authorities (SAA)., • RMF Process: Oversee security categorization, control selection, implementation, assessment, authorization, and continuous monitoring for government and host-nation systems. Develop and maintain RMF artifacts, including: • System Security Plan (SSP) per NIST SP 800-18, • Network Management Plan, • Security control implementation documentation per NIST SP 800-53, • Plan of Action and Milestones (POA&M), • Ports, Protocols, and Services (PPS) list per CNSSI 4009 and DoDI 8551.01, • System Architecture Diagrams, Data Flows, and Interconnection Descriptions per DISN Connection Process Guide, • Information Assurance Design Review documents, • Ensure electromagnetic protection and physical/technical controls meet SDIP-29/1 Zone 2 and NATO CIS AC/322-D/0048-REV3 requirements., • Apply DISA STIGs/SRGs across ASRR components, managing deviations through POA&M justifications., • Design and implement a continuous monitoring program, including vulnerability scanning, POA&M tracking, and patch validation in a System Integration Lab (SIL)., • Manage patch and configuration processes per NIST SP 800-35, SP 800-39, and CNSSI 1253., • Lead Integrated Product Teams (IPTs) for cybersecurity and network engineering across airborne and ground systems., • Develop and execute cyber incident response plans per DFARS 252.204-7012, ensuring timely reporting of incidents affecting Covered Defense Information (CDI)., • Clearance: Eligibility for a Government Security Clearance., • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field. Master’s degree or advanced cybersecurity studies preferred., • Experience: Minimum 7 years of hands-on cybersecurity engineering experience, with a proven track record of deploying and maintaining security solutions. Demonstrated progression to senior-level roles aligned with ISSO responsibilities., • Technical Skills:, • Expertise in applying STIGs and SCAP tools for system hardening and compliance., • Proficiency in conducting credentialed vulnerability scans (e.g., Nessus, ACAS), leveraging RMF toolkits, and remediating infrastructure systems., • Strong knowledge of network security architecture, enclave segmentation, cross-domain solutions (CDS), endpoint protection, encryption, and secure patching., • Experience with System Integration Labs (SILs), configuration management repositories, and continuous monitoring environments., • Regulatory Knowledge: In-depth understanding of DoD 8500.01, DoD 8510.01 (RMF), AR 25-2, CNSSI 1253, NIST SP 800-37, 800-53, 800-171, FISMA, and ATO processes., • Certifications: DoD 8570.01-M IAT Level II or higher and IAM Level III certifications (e.g., CompTIA Security+, SSCP, CASP, CISSP, CISM, GSLC)., • Communication: Exceptional written and verbal skills, adept at engaging technical and non-technical stakeholders., • Advanced Certifications: CISSP-ISSEP, CISSP-ISSMP, CAPM, or equivalent project management certifications., • Cloud Security: Familiarity with cloud security frameworks (e.g., AWS, Azure)., • NATO Regulations: Knowledge of NATO cybersecurity frameworks (e.g., AC/322-D/0048-Rev3) and SDIP-29/1 Zone 2 TEMPEST protections., • FMS Experience: Prior support for Foreign Military Sales or multinational defense programs (e.g., NATO).