Amentum Logo

Amentum

Information System Security Officer (ISSO)

Posted Yesterday
Be an Early Applicant
In-Office
Sunnyvale, CA, USA
175K-200K Annually
Senior level
In-Office
Sunnyvale, CA, USA
175K-200K Annually
Senior level
Supports NASA information-system cybersecurity throughout the system life cycle. Responsibilities include developing System Security Plans, managing RMF and A&A documentation, tracking POA&Ms and risk decisions, reviewing threats and vulnerabilities, supporting patching and remediation, evaluating cloud security, analyzing logs, testing contingency plans, and advising system owners on security controls, privacy assessments, and compliance requirements.
The summary above was generated by AI

Amentum is seeking an Information System Security Official for a contract at the National Aeronautics and Space Administration (NASA), Sunnyvale, CA location. The Information System Security Official (ISSO) services provide cybersecurity Subject Matter Experts (SMEs) to support NASA Information Systems.

Amentum is a leading provider of engineering, scientific, and program management support services to some of the top agencies in the U.S. Government, including NASA, Defense Advanced Research Projects Agency (DARPA), the Department of Homeland Security and the Intelligence Community. 

Job Duties and Responsibilities: 

  • Develop and maintain detailed and accurate System Security Plans (SSP), including security documentation for component and interface specifications, to support appropriate cybersecurity and privacy throughout the information systems’ life cycle 

  • Assist the Information System Owner (ISO) and Information System Security Manager (ISSM) in ensuring that all components of the information system are appropriately updated and patched in accordance with Federal and NASA requirements 

  • Support the Government with identifying and prioritizing essential system functions or sub-systems required to support essential capabilities or business functions for restoration or recovery after a system failure or during a system recovery event based on overall system requirements for continuity and availability 

  • Provide technical guidance to address the adequacy and effectiveness of information security policies, procedures, and practices

  • Ensure that cybersecurity design and development activities are properly documented (providing a functional description of security implementation) and updated as necessary

  • Ensure Privacy Threshold Assessments (PTA) and Privacy Impact Assessments (PIA) are conducted as required

  • Review cyber intelligence threats reports, including but not limited to SOC MARs, SARs, and DHS/CISA Emergency Directives, in order to identify threats to the information system and develop mitigations 

  • Provide subject matter expertise and recommendations as part of RMF process activities and development of related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials) 

  • Evaluate cloud service providers’ security posture and develop associated recommendations for restrictions, conditions and control responsibility parsing 

  • Write Plan of Action and Milestones (POA&M’s) and Risk Based Decisions (RBD’s) for the System Security Plan (SSP) controls within the NASA Risk Information Security Compliance System (RISCS) tool.   

  • Ensure contingency plans and system controls are reviewed and tested in accordance with the Agency requirements.  

  • Analyze system logs to identify potential issues and perform routine audits of systems and applications.  

  • Ensure critical vulnerabilities that require immediate attention are remediated, as identified in the Security Operation Center (SOC) Mitigation Action Recommendation (MAR).  

  • Ensure the installation of security/vulnerability patch updates, operating system level patches and upgrades to include new versions.

  • Provide IT security support to communication systems as needed and serve as a technical resource to Information System Security Officer(s) (ISSO) and other IT professionals  

  • The contractor shall assist in the development and updating of the System Security Plan, Contingency Plan, Disaster Recovery Plans, Risk Assessment Report, annual review package, work instructions, policies, and procedural guides affecting the overall IT and security posture of the environment 

  • Support the Assessment and Authorization (A&A) process by preparing associated documentation, building, and tracking Plan of Action and Milestones (POA&M), and monitoring A&A activities  

Required Qualifications:

  • Must have an active Top Secret US Government Clearance, with the ability to obtain an SCI Clearance. Please note US Citizenship is required to maintain a Top Secret Clearance.

  • Bachelor of Science degree with 5 years of professional experience in cybersecurity design and development activities

  • Strong oral and written communication skills

Desired qualifications:

  • SCI clearance eligibility

  • Experience in NASA Security or served as an ISSO in other agencies.

  • Experience in NASA Risk Information Security Compliance System and Assessment and Authorization.

  • Experience with Cloud Services and classified networks.

  • Certification level to meet DoD 8140 IAT or DoD 8570 IAT Level II certification or higher.

       

Compensation Details:

$175K-$200K

       

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.


Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance


Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

       

Original Posting:

08/19/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

       

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed,  marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.

Similar Jobs

11 Days Ago
In-Office
113K-153K Annually
Mid level
113K-153K Annually
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Serve as an ISSO for classified computing domains, implementing RMF A&A processes, performing security and risk assessments, configuration management, continuous monitoring, incident response support, and interfacing with government customers to ensure compliance with cybersecurity standards and directives.
Top Skills: AcasAudit ReductionCnssi 1253DaagDisa StigsHbssIcd-503JsigNessusNist Sp 800RmfScap
3 Days Ago
In-Office
115K-150K Annually
Senior level
115K-150K Annually
Senior level
Aerospace • Professional Services • Defense
Serve as the Information System Security Officer for a high-visibility DoD program. Implement and enforce RMF-based security controls, perform vulnerability assessments (ACAS, STIGs, SCAP), continuous monitoring, risk analyses, and support ATO documentation (SSPs, POA&Ms). Use SolarWinds or Splunk for monitoring and collaborate across teams to ensure compliance with DISA, NIST, CNSSI, JSIG, and SAP/ICD policies.
Top Skills: Assured Compliance Assessment Solution (Acas)Disa Security Technical Implementation Guides (Stigs)Security Content Automation Protocol (Scap) Compliance CheckerSolarwindsSplunk
3 Days Ago
In-Office
90K-110K Annually
Junior
90K-110K Annually
Junior
Aerospace • Professional Services • Defense
Support DoD RMF compliance, vulnerability management, DISA STIG implementation, and continuous monitoring for classified systems. Perform vulnerability scans, review audit logs, track POA&Ms, assist with SSPs/SARs, and support ATO efforts while coordinating remediation with system owners.
Top Skills: AcasCnssi 1253Disa Approved Products List (Apl)Disa StigDod 5205.07Icd 705JsigLinuxNetwork DevicesNiap Common CriteriaNist Sp 800-53RmfSap PolicyScap Compliance CheckerWindows

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account