CareerMoonshot

Information System Security Officer - Classified Systems

Leidos · Alabama

📍 Huntsville, ALvia workdayFirst listed here 2026-09-21
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Leidos.
Leidos Dynetics, reporting through the Digital Sector, is seeking an Information System Security Officer (ISSO) to support classified information systems and cybersecurity operations in Huntsville, Alabama. In this role, you will support the day-to-day cybersecurity compliance and continuous monitoring of classified information systems operating within a DCSA regulated environment. Working under the direction of the Information System Security Manager (ISSM) and in collaboration with other cybersecurity professionals, system administrators, engineers, and program personnel, you will assist in maintaining system authorizations and ensuring continued compliance with applicable cybersecurity requirements. This position provides an opportunity to develop hands-on experience across the Risk Management Framework (RMF) lifecycle while supporting technical security assessments, system hardening, vulnerability management, configuration management, security documentation, and DCSA assessment activities. Location : Work will be performed on-site in the Leidos Dynetics Huntsville office. This role allows for 20% local telework. Clearance: You must currently hold an active Secret clearance to be considered and must be eligible to obtain Top Secret post hire. Primary Responsibilities ISSO’s primary responsibilities include supporting the day-to-day cybersecurity oversight and compliance of classified information systems and assisting with maintenance of system authorizations. Perform security monitoring and compliance reviews of classified information systems and report identified deficiencies, risks, and noncompliance to the ISSM or designated cybersecurity lead. Support the RMF lifecycle by developing, reviewing, and maintaining authorization artifacts and objective evidence within the system Body of Evidence (BoE). Assist with implementation, assessment, and continuous monitoring of applicable security controls in accordance with approved system security plans and established cybersecurity procedures. Perform technical security assessments, including STIG, SCAP, vulnerability scanning, and system configuration reviews. Document security findings and vulnerabilities and work with cybersecurity personnel, system administrators, and engineering teams to support remediation and validation activities. Review Configuration Management requests within delegated authority for hardware, software, system configuration, and security-relevant changes, ensuring changes are properly documented and processed through the Configuration Control Board (CCB). Support periodic technical and administrative assessments of information systems to validate continued compliance with approved security requirements, procedures, and system configurations. Review security-relevant audit information and system logs using available operating system, security monitoring, and SIEM tools. Support cybersecurity incident response activities, including investigation, documentation, evidence preservation, containment, corrective actions, and reporting under the direction of the ISSM or designated cybersecurity lead. Develop, review, and maintain cybersecurity documentation, procedures, assessment artifacts, system records, and other technical documentation. Provide cybersecurity guidance and security awareness support to system users, administrators, engineers, and program personnel within established policies and procedures. Support DCSA assessments, security reviews, inspections, authorization activities, and other internal or external cybersecurity assessments. Collaborate with Information Technology, system administrators, engineers, program management, physical security, and other cybersecurity personnel to identify and resolve information system security issues. Basic Qualifications Bachelor’s degree with 2+ years of relevant cybersecurity, information technology, information assurance, or information systems security experience. Additional relevant experience may be considered in lieu of a degree. Must meet, or be capable of meeting, applicable DoD 8140/DoD Cyber Workforce Framework (DCW F) qualification requirements f or the assigned work role through approved certification, education, training, or experience. Familiarity with the RMF and cybersecurity control implementation, assessment, or compliance activities. Demonstrate direct experience and/or knowledge in one or more of the following areas: cybersecurity, information systems security, system administration, system hardening, vulnerability management, security configuration management, or compliance auditing. Working knowledge of Windows and/or Linux operating systems and associated security concepts and configurations. Familiarity with cybersecurity requirements and standards such as NIST SP 800-53 Rev 5, DISA STIGs, DCSA requirements, the DAAG, NISPOM, or comparable government cybersecurity requirements. Ability to review technical security findings, document deficiencies, and assist with development and validation of corrective actions. Ability to develop and maintain detailed cybersecurity documentation and objective evidence supporting information system compliance. Strong organizational, analytical, written, and verbal communication skills with the ability to manage assigned cybersecurity activities and priorities. Ability to work collaboratively with Information Technology, system administrators, engineers, program personnel, physical security, and other cybersecurity professionals Relevant Experience Considered: Cybersecurity, information assurance, information systems security, system administration, system hardening, or Information Technology. RMF compliance, security control implementation or assessment, continuous monitoring, or authorization package support. Windows, Linux, Active Directory, Group Policy, Delinea, or comparable enterprise technologies. STIG, SCAP, vulnerability scanning, securi

More Alabama jobs

Alabama jobs · Browse all locations