Senior Information Security Systems Officer in Lakehurst, New Jersey at Castellum Inc
Explore Related Opportunities
Job Description
JOB SUMMARY
Specialty Systems, Inc. has an immediate opening for a Senior Information Systems Security Officer (ISSO) to join our team of technical professionals supporting our Department of Defense customer at Joint Base McGuire-Dix-Lakehurst (JB MDL), NJ. In this position, you will play a key technical role in the development, integration, accreditation, and sustainment of complex, mission-critical Department of Defense systems.
The Senior ISSO will serve as the primary technical lead responsible for planning, developing, coordinating, and maintaining Risk Management Framework (RMF) authorization packages, including driving new systems through the Authorization to Operate (ATO) process. This position requires a hands-on cybersecurity professional capable of translating DoD/DoN security requirements into actionable engineering activities and developing the objective evidence necessary to support successful system accreditation.
The ideal candidate will possess extensive RMF experience combined with a strong technical understanding of system architectures, network security, vulnerability management, DISA STIGs, and the accreditation of systems incorporating Commercial-Off-the-Shelf (COTS)/vendor hardware, software, and specialized equipment.
Working closely with Government cybersecurity leadership, systems engineers, software developers, vendors, Security Control Assessors (SCAs), and Authorizing Official (AO) representatives, the Senior ISSO will help ensure cybersecurity requirements are addressed throughout system design, development, integration, testing, deployment, and sustainment.
As a member of our team, you will experience the professional satisfaction of playing a key role in ensuring that our Department of Defense customers' systems, which directly impact our country's warfighting and peacekeeping capabilities, are secure, operational, and performing at optimal levels.
Work Location and Schedule: This position is located at our customer's site at Joint Base MDL. The position follows the customer's Compressed Work Schedule (CWS), consisting of four 9-hour days (Monday–Thursday) and an 8-hour Friday during the first week, followed by four 9-hour days (Monday–Thursday) and the second Friday off, providing a three-day weekend every other week.
RESPONSIBILITIES
- Serve as the primary technical owner responsible for developing, coordinating, and maintaining the system's RMF/ATO authorization package under the direction of Government cybersecurity leadership.
- Serve as the program’s Subject Matter Expert (SME) for DoD, DoN, and DISA cybersecurity policies, requirements, and compliance activities.
- Develop and execute the RMF authorization strategy, including system categorization, control selection and tailoring, implementation, assessment preparation, authorization, and continuous monitoring.
- Monitor cybersecurity risks and develop mitigation plans to ensure compliance with government requirements and mission objectives.
- Interface with Government program managers, engineers, Authorizing Officials, Security Control Assessors, and other stakeholders to resolve cybersecurity issues.
- Develop, populate, and maintain authorization packages within eMASS, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plans of Action and Milestones (POA&Ms), and supporting cybersecurity artifacts.
- Establish and document system authorization boundaries, including identification of hardware, software, network components, external interfaces, information flows, and inherited versus system-specific security controls.
- Evaluate system architectures, network diagrams, interface designs, and engineering documentation to identify cybersecurity requirements and potential security risks.
- Coordinate with engineering teams to map applicable security controls to system components and obtain the technical evidence necessary to demonstrate control implementation.
- Plan and coordinate vulnerability assessments, security control testing, STIG evaluations, and cybersecurity readiness reviews.
- Develop and maintain an RMF execution schedule, identifying required artifacts, assessment activities, dependencies, risks, and milestones necessary to support the targeted ATO date.
- Coordinate directly with Government ISSM/ISSO personnel, SCAs, AO representatives, and other stakeholders to resolve authorization issues and support accreditation decisions.
QUALIFICATIONS:
Education, Certifications, and Experience
- A bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field with 5+ years of cybersecurity experience, including experience supporting DoD or Department of the Navy (DoN) programs OR Master’s degree in Cybersecurity, Information Assurance, Engineering, or related field with 3+ years of relevant experience
- Must have a Secret level or higher clearance.
- Demonstrated experience developing and maintaining RMF authorization packages, including direct responsibility for preparing systems for an initial ATO or significant authorization update.
- Strong working knowledge of DoD RMF processes, NIST SP 800-37, NIST SP 800-53, DoD/DoN cybersecurity requirements, and DISA STIGs/SRGs.
- Hands-on experience with eMASS, including security control documentation, artifact management, assessment findings, POA&Ms, and continuous monitoring.
- Preferred certifications include CISSP, CASP+/SecurityX, CISM, GSLC, Security+, or an equivalent certification satisfying applicable DoD 8140 qualification requirements.
Technical Skills
- Experience leading RMF/ATO activities for new or significantly modified DoD systems, particularly systems incorporating COTS/vendor hardware, proprietary software, embedded controllers, or specialized mission equipment.
- Experience defining and documenting authorization boundaries for complex networked systems or System-of-Systems (SoS) environments.
- Familiarity with vendor cybersecurity assessments, hardware/firmware vulnerabilities, software dependencies, supply-chain risk management (C-SCRM), and vendor-controlled configuration or patching processes.
- Experience developing technical mitigations and compensating controls for equipment that cannot fully satisfy applicable STIG/SRG requirements.
- Experience working directly with SCAs, AO representatives, and Government cybersecurity leadership during new system authorization efforts.
- Familiarity with secure cloud, hybrid-cloud, tactical, or isolated laboratory network environments.
Specialty Systems, Inc. provides equal employment opportunity (EEO) to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, genetic information, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable federal, state, and local laws and offers equal opportunity for VEVRAA Protected Veterans. Specialty Systems, Inc. will not discriminate against employees and job applicants who inquire about, discuss, or disclose compensation information.
Reasonable accommodation that do not cause an undue hardship on the company may be made to enable individuals with disabilities to perform essential functions, as long as that would not hinder or prevent performance of duties or be of a safety concern.
PHYSICAL DEMANDS:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of the job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is required to reach with hands and arms. The employee is frequently required to sit, stand and walk. The employee may be required to move ten pounds and could occasionally lift or move up to twenty-five pounds.
Disclaimer: The listed duties are not intended to serve as a comprehensive list of all duties performed by all employees in this classification, only a representative summary of primary duties and responsibilities.