Information Systems Security Officer (ISSO) in North Charleston, South Carolina at Geodesicx Inc
Explore Related Opportunities
Job Description
Geodesicx is looking for an Information Systems Security Officer to join our team in the Charleston, SC area.
Summary
The Information Systems Security Officer (ISSO) Contractor will serve as a primary cybersecurity technical advisor and Risk Management Framework (RMF) executor in support of the Program Manager Advanced Amphibious Assault (PM AAA) Information Systems Security Manager (ISSM). This role is critical to ensuring the cybersecurity posture and successful accreditation of all systems and sub-systems on current and future United States Marine Corps (USMC) Amphibious Combat Vehicle (ACV) variants, with a specific focus on deployed Command, Control, Communications, and Computers (C4) systems.
This is an Assessment and Authorization (A&A) focused role. The candidate will steer accreditation efforts, develop comprehensive RMF documentation, and drive Authority to Operate (ATO) packages through the Department of Defense (DoD) lifecycle in accordance with the Risk Management Framework (DoDI 8510.01). The ISSO will act as the ISSM’s right hand, managing the tactical execution of the cybersecurity program, ensuring operational systems and networks remain compliant, secure, and fully accredited.
Responsibilities
- Lead the planning, coordination, and execution of A&A events, including RMF ATO efforts for current and future PM AAA Vehicle Variants and support software.
- Develop, review, endorse, and maintain A&A documentation System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms) in accordance with DoD, Department of Navy (DoN), and Marine Corps policies.
- Upload all artifacts and maintain system information repositories within Enterprise Mission Assurance Support Service (eMASS).
- Support periodic security events including the Annual Security Review (ASR), Independent Verification and Validation (IV&V), and Annual Federal Information Security Modernization Act (FISMA) Reviews.
- Advise the ISSM in ensuring information ownership responsibilities and baselines are established for ACV C4 systems (including accountability, access approvals, and special handling).
- Perform required compliance assessments for C4 systems deployed on PM AAA Family of Vehicles (FoVs); review, document, and maintain all results.
- Assess, mitigate, track, and document vulnerabilities on the Information Technology (IT) Security POA&M.
- Initiate protective or corrective measures required to maintain the accredited security posture of deployed C4 systems, enforcing DoD, DON, and local Privacy Act policies.
Required Skills
- Clearance: Active U.S. Government Security Clearance (Secret or higher)
- Citizenship: Must be a U.S. Citizen.
- RMF Expertise: Proven, hands-on experience preparing and walking DoD RMF accreditation packages (ATOs) through the complete lifecycle in accordance with DoDI 8510.01, NIST SP 800-53 Rev 5, CNSSI 1253, and ICD 503.
- A&A Tooling: Direct experience utilizing eMASS and/or Marine Corps Compliance and Authorization Support Tool (MCCAST) to build, track, and submit system artifacts and ATO packages.
- Vulnerability Scanning & Compliance: Demonstrated capability implementing, verifying, and operating mandatory DoD compliance tools, specifically:
- Assured Compliance Assessment Solution (ACAS) / Nessus
- Security Content Automation Protocol (SCAP) Compliance Checker (SCC)
- Host Based Security System (HBSS) / Endpoint Security Solutions (ESS)
- STIG & IAVM: Extensive experience applying, documenting, and mitigating Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Information Assurance Vulnerability Management (IAVM) notices.
Desired Skills
- Prior experience supporting USMC System Commands (MARCORSYSCOM) or specifically Portfolio Acquisition Executive-Marine Corps (PAE-MC) / PM AAA.
- Familiarity with the ACV platform, tactical C4 systems, or ground combat vehicle architectures.
- Experience securing and accrediting embedded systems, tactical edge networks, and standalone tactical variants.
- Familiarity with Marine Corps specific cybersecurity workflows (e.g., MCSC SEAL CYB Branch interactions).
- Strong verbal and written communication skills to effectively translate complex technical vulnerabilities into executive-level risk assessments for the ISSM and Program Manager.