Information Systems Security Officer (ISSO)
About this role
Job Title: Information Systems Security Officer (ISSO)
Job Location: Al Nakhla, Saudi Arabia
Job Responsibilities
Trace Systems is seeking an experienced Information Systems Security Officer (ISSO) to support the USMTM CITS contract in Riyadh, Kingdom of Saudi Arabia. The ISSO supports cybersecurity posture, authorization, continuous monitoring, vulnerability management, incident response, security-control implementation, audit readiness, and compliance for mission-critical classified and unclassified systems.
- Support implementation and sustainment of the Department of Defense Risk Management Framework for assigned systems and network enclaves.
- Develop, review, and maintain System Security Plans, control implementation statements, system descriptions, contingency and incident response plans, and authorization artifacts.
- Support initial and recurring authorization activities required to obtain and maintain Authority to Operate status.
- Maintain Plans of Action and Milestones, track remediation, validate closure evidence, and coordinate disposition of cybersecurity findings.
- Prepare Security Assessment Reports, risk assessments, control-assessment evidence, and continuous-monitoring documentation.
- Coordinate with Government IAM, ISSM, authorizing officials, assessors, cybersecurity service providers, and higher-level organizations.
- Perform security-impact analyses and provide cybersecurity recommendations through Configuration Control Board processes.
- Monitor security posture using approved vulnerability, compliance, endpoint-security, logging, and scanning tools.
- Review scan results, security bulletins, IAVAs, directives, and notifications; prioritize and coordinate remediation with technical teams.
- Verify implementation of STIGs, security baselines, patches, mitigations, logging, access controls, and corrective actions.
- Support incident triage, reporting, investigation, containment, eradication, recovery, notifications, and after-action activities.
- Review system, application, audit, and security logs for anomalies, unauthorized activity, or indicators of compromise.
- Support account management, privileged access, PKI, token, password, identity lifecycle, certificates, and SIPR credential processes when authorized.
- Support security testing, inspections, audits, assessments, metrics, briefings, awareness, role-based training, and continuity documentation.
- Provide cybersecurity guidance that balances compliance, mission availability, operational risk, and technical requirements.
- Participate in maintenance, emergency response, after-hours support, and on-call activities when cybersecurity events require.
Minimum Qualifications
- Active, in-scope US Government issued Secret clearance.
- Due to the nature of the work and contract requirements: US Citizenship is required.
- Candidates must meet the applicable DoD 8140 qualification requirements for the assigned work role. DoD 8140 Work Role(s): 541 – Vulnerability Assessment Analyst, Proficiency Level: Intermediate; and may qualify through education, military training, certifications, or a combination thereof. DoD identifies Work Role 541 as the Vulnerability Assessment Analyst role.
- Qualifying education or training may include a bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Data Science, Software Engineering or completion of relevant military cyber, information assurance, communications, or network security training.
- Qualifying certifications may include Security+, CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or other DoD 8140-approved certifications applicable to the Vulnerability Assessment Analyst work role. Higher proficiency-level or equivalent DoD 8140-approved certifications applicable to the assigned work role may also be accepted.
- Eight (8) or more years of progressively responsible cybersecurity, information assurance, assessment and authorization, or related security experience.
- Demonstrated experience supporting DoD RMF, authorization packages, ATO sustainment, POA&Ms, continuous monitoring, and control assessments.
- Experience with vulnerability scanning, risk assessment, security-impact analysis, incident response, remediation tracking, DISA STIGs, and security baselines.
- Experience supporting classified information systems or secure Government environments.
- Working knowledge of NIST security controls, DoD cybersecurity policy, and federal information-security requirements.
- Strong analytical, technical writing, documentation, briefing, and stakeholder-coordination skills.
- Ability to relocate to Riyadh, Kingdom of Saudi Arabia.
Desired Qualification
- Previous experience as an ISSO, ISSM, security control assessor, cybersecurity analyst, or information assurance lead on a DoD program.
- Experience supporting Army, CENTCOM, USARCENT, NETCOM, DISA, RCC-SWA, or other enterprise cybersecurity organizations.
- Experience with eMASS, ACAS, SCAP Compliance Checker, endpoint-security platforms, log-management tools, and Government vulnerability-management technologies.
- Experience supporting Windows Server, Active Directory, VMware, networks, SharePoint, voice, and endpoint environments.
- Experience with NIST SP 800-53, cybersecurity inspections, authorization reviews, and overseas or military mission support.
Trace Systems
Trace Systems, headquartered in Vienna, Virginia, was founded to support and defend our nation's security interests at home and abroad–– whenever and wherever. We provide cybersecurity, intelligence, communications, networking and information technology services, systems, and solutions to the United States Department of Defense, Intelligence Community and Department of Homeland Security.
To Apply: We invite you to put your talents to work by joining a growing team of dynamic professionals here at Trace Systems! Be part of a culture at our leading edge company where you can achieve great things while fostering a satisfying and rewarding career progression. Please apply directly through the website at: www.tracesystems.com. #jointracesystems
Trace Systems is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
Company at a glance
Trace Systems Inc. is an industry leader in digital transformation, assured communications, distributed edge architecture, cloud-based cross domain solutions, and global defense services. With expertise in global operations, Trace has established strong geographic footprints across North and South America, Europe, Africa, the Middle East, and Indo-Pacific regions.
Since our founding, Trace has supported mission critical requirements for the Department of Defense (DoD) in nearly every corner of the globe:
We live and work alongside many of our military customers in austere, hazardous, and tactical ‘down-range’ contingency environments such as Iraq and Afghanistan. We understand and are extensively experienced in how to operate and support our customers in these challenging environments.
We support coalition customers globally in CENTCOM, AFRICOM, EUCOM, INDOPACOM, SOUTHCOM, and NORTHCOM. Based on our extensive experience in theater, we know how to navigate the complexities of living and working in challenging or hazardous environments.
We support combatant commands with solutions and services that require rapid response to requirements on a moment’s notice. We have a long history of supporting immediate reaction and response teams as well as short-notice deployments of highly-specialized teams to address cyber security, networking, systems, command center and communications systems and services requirements.
Trace Systems is an Equal Opportunity employer.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?