Jobs and Careers
SY

Information Systems Security Officer Level 2

System High Corporation
United Statesfull_timeVerifiedPosted 30 Oct 2025

About the role

Job Details

Job Location CHANTILLY, VA 1 (DAGGER-HIDALGO) - Chantilly, VAPosition Type Full Time

Description

Position Overview

The Level 2 ISSO position is a mid-level information system security professional that provides advice and assistance to the Government regarding secure configuration and operation of customer’s IT assets. Level 2 ISSOs apply knowledge and experience with standard information system security concepts, practices, and procedures. ISSO Level 2 duties include, but are not limited to the following:

 

  • Manage the day-to-day system security including physical and environmental protection, incident handling, and information system security training and awareness.
  • Maintain the system security plan (SSP), and other related documents, following IC, and DoD applicable policies, procedures, and templates.
  • Support initial risk analysis and present results to the Information System Owner and PSO.
  • Participate in assessment and integration, verification, and validation (IV&V) testing activities.
  • Assess the security impact of system changes, updating the SSP, managing and monitoring changes to the system, and disposal of the system in accordance with IC, and DoD security policies and practices, as outlined in the approved SSP.
  • Notify the ISSM, PSO, and Information System Owner when changes occur that may affect accreditation authorization, thus initiating the re-certification/re-accreditation process.
  • Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
  • Maintain and update IT asset records in XACTA Assessment Engine on behalf of the Information System Owner.
  • Process information systems access requests, ensuring all users have the requisite SCI security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the IS.
  • Initiate, with the approval of the ISSM, protective or corrective measures when a security incident or vulnerability is discovered.
  • Ensure configuration management (CM) for the security relevant IS software, hardware, and firmware is maintained and documented. If a CM board exists, the ISSO may support the CM board if so designated by the ISSM.
  • Ensure system recovery processes are monitored to ensure that security features and procedures are properly restored.
  • Ensure system security requirements are addressed during all phases of the system life cycle.
  • Ensure that customer security systems comply with appropriate assessment and authorization standards.
  • Responsible for controlling, labeling, virus scanning, and appropriately transferring data (uploading/downloading) between various customer information systems as required.
  • Perform requested uploads/downloads, virus scanning, and software updates for applicable information systems and local and wide area networks (LAN/WANs), perform Automated Out-processing & Relocation System (AORS) reviews, Public Key Infrastructure (PKI) vetting, Portable Electronic Device (PED) registrations, and conduct customer Management Information System (NMIS)/Secret Collateral Management Information System (SCMIS)/Unclassified Management Information System (UMIS) user briefings.
  • Support comprehensive investigations into all customer related data spills and IT incidents at both government and contractor sites.
  • The contractor shall support information protection needs, system security requirements, system security architecture, and verify information protection effectiveness as related to customer mission requirements.
  • Provide guidance on system security, assessment and authorization issues, and INFOSEC policy and security vulnerabilities.
  • Provide advice and guidance to customer program personnel and Program Security Officers on all Information System (IS) security issues across all customer activities.
  • The contractor shall support the Government POC in managing the acquisition, operation, storage, inventory, and disposition of all Communications Security (COMSEC) related material and equipment as required.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

System High Corporation

View company profile →