Information Systems Security Officer (Part-time, Remote)
Koniag Government ServicesAbout the role
Arlluk Technology Solutions, LLC a Koniag Government Services company, is seeking an Information Systems Security Officer with a Secret security clearance to support ATS and our government customer. This position is remote and part-time.
Koniag Government Services is seeking a Part-Time Information Systems Security Officer (ISSO) to support and maintain the security posture of critical Department of War (DOW) information systems. The ideal candidate will be a detail-oriented professional with extensive expertise in the DOD Risk Management Framework (RMF), DISA regulations, and STIG compliance. Initially supporting one primary program, this role requires flexibility to potentially expand support to additional programs as requirements evolve. The successful candidate will manage vulnerabilities via ACAS and HBSS, maintain Authority to Operate (ATO) accreditations, and possess the strong organizational skills necessary to ensure continuous cybersecurity compliance in a mission-critical, team-based environment.
Essential Functions, Responsibilities & Duties may include, but are not limited to:
The Information Systems Security Officer will be responsible for maintaining the security posture of multiple DOW information systems and ensuring compliance with all applicable cybersecurity frameworks and regulations. Principal responsibilities will include but are not limited to:
• Develop and maintain System Administration Documentation that maps interdependencies and critical paths for successful system refreshes, working closely with government stakeholders to identify agency interdependencies
• Create and update Configuration and Architecture Diagrams in relation to critical paths and system interdependencies
• Provide comprehensive RMF documentation to the ISSM in accordance with DOD accreditation processes
• Verify compliance with STIG, DISA Chief Technology Office (CTO), and INFOCON guidelines and requirements
• Validate security postures and update findings for assigned databases based on Assured Compliance Assessment Solution (ACAS) and Host Based Security System (HBSS) reports and logs
• Adhere to CYBERCOM Information Assurance Vulnerability Alerts (IAVAs) by applying required patches and maintaining Plan of Action and Milestones (POA&M) documentation
• Conduct STIG Checklist reviews and provide detailed reports of all findings in accordance with RMF frequency requirements
• Generate monthly Cybersecurity Reports containing patch schedules for all servers, accreditation status, POA&M status, IAVA status, ACAS scan remediation status, and DISA CTO compliance status
• Develop system and cybersecurity policies and plans to identify and respond to threats in compliance with DOW and DISA regulations
• Audit access controls and permissions for CSS, COPS, and FABS systems in accordance with DOW and DISA compliance requirements
• Provide incident response and recovery support as necessary
• Support obtaining and maintaining Authority to Operate (ATO) accreditations for CSS and COPS/FABS systems
• Maintain security posture for CSS, COPS/FABS, and EDMS systems
• Support DISA ISSO/ISSM with security information to respond to taskers and emerging cybersecurity requirements
• Support development and maintenance of Incident Response Plans (IRPs) and Continuity of Operations Plans (COOPs)
• Interpret, plan for, prioritize, and implement actions necessary to maintain compliance with DOD and DISA cybersecurity requirements
Education and Experience:
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field from an accredited college or university
• 5+ years of experience as an ISSO supporting DOW information systems
• Current DOD 8570.01-M IAT Level II or IAM Level II certification (CISSP, CISM, or CAP certification)
• Experience working within the Risk Management Framework (RMF)
Clearance Requirement:
• Active Secret security clearance
Required Skills and Competencies:
• Comprehensive knowledge of DOD Risk Management Framework (RMF) and accreditation processes
• Expertise in Security Technical Implementation Guides (STIGs) and STIG compliance verification
• Proficiency with ACAS (Nessus) scanning tools and vulnerability management
• Experience with Host Based Security System (HBSS) including ePO administration
• Strong understanding of DISA CTO requirements and INFOCON procedures
• Knowledge of CYBERCOM IAVAs and patch management processes
• Ability to develop and maintain POA&Ms and track remediation efforts
• Experience creating technical documentation including system architecture diagrams and security plans
• Proficiency in conducting security assessments and audits
• Knowledge of access control principles and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s