1

Isso Issm Jobs in Colorado (NOW HIRING)

Prior performance in roles such as ISSO or ISSM; Desired : * SAP Experience; Training: * DoD 8570.01-M IAM Level I (in lieu of IAT Level II) * Combatting Trafficking in Persons (CTIP) Security ...

Showing results 21-40

Isso Issm information

What is an Information Systems Security Officer (ISSO)?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.

What are the key skills and qualifications needed to thrive as an ISSO or ISSM?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What are the main challenges faced by an ISSO or ISSM when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

What job categories do people searching Isso Issm jobs in Colorado look for?

The top searched job categories for Isso Issm jobs in Colorado are:

What cities in Colorado are hiring for Isso Issm jobs?

Cities in Colorado with the most Isso Issm job openings:

Infographic showing various Isso Issm job openings in Colorado as of September 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Hybrid job distribution.

Cybersecurity Risk & Exposure Subject Matter Expert IV

Colorado Springs, CO • On-site

Invictus International
Investigation and Physical Security Services • 201 - 500 employees

Other

Posted yesterday

New


Job description

Title: Lead Cybersecurity Risk & Exposure Subject Matter Expert IV

Location: Colorado Springs, CO

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details:
  • Serve as the senior SME for operational cyber risk, vulnerability/exposure analysis, and continuous monitoring supporting a DoD cyber defense mission
  • Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize the exposures most likely to create operational or mission risk
  • Lead complex exposure and impact assessments, including development of plausible exploitation scenarios, attack paths, affected-system analysis, compensating-control considerations, and risk-informed courses of action
  • Provide expert vulnerability, asset, architecture, and security-control context to SOC leadership, Cybersecurity Operations Analysts, Threat Analysts, incident responders, and engineering teams during significant investigations and proactive defensive activity
  • Lead analysis of ACAS/Tenable results, runZero asset information, STIG/configuration findings, system documentation, and other approved data to identify systemic weaknesses, exploitable conditions, and remediation priorities
  • Own the SOC-side process for coordinating material cyber findings with affected system ISSOs/ISSMs, system owners, administrators, engineers, and authorization stakeholders; ensure operational findings are translated into appropriate mitigation, continuous-monitoring, POA&M, or RMF actions without duplicating system ISSO responsibilities
  • Establish and maintain checklists, TTPs, guides, procedures, quality standards, and reporting methods for exposure analysis, risk prioritization, remediation validation, and SOC-to-system-security coordination
  • Lead review of remediation evidence, recurring vulnerabilities, exposure trends, control weaknesses, and SOC-derived findings to identify systemic risk and recommend enterprise or site-level corrective actions
  • Develop briefings, executive summaries, risk assessments, metrics, dashboards, and technical products that communicate operational exposure, remediation progress, control effectiveness, and mission impact to technical and leadership audiences
  • Advise SOC leadership on vulnerability/exposure trends, high-risk assets, recurring security weaknesses, remediation priorities, and opportunities to improve the integration of vulnerability management, threat information, and cyber defense operations
  • Mentor senior and developing analysts and provide technical quality review of exposure assessments, risk conclusions, remediation recommendations, and stakeholder coordination products
  • Experience integrating vulnerability management, continuous monitoring, RMF/ISSO processes, and SOC or incident-response operations in a DoD/IC or similarly complex enterprise environment is highly desired
Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum of eight (8) years of relevant experience in addition to education level
  • Demonstrated expert knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
  • Demonstrated experience establishing exposure-analysis methodology, leading complex risk assessments, prioritizing remediation, and translating operational cyber findings into continuous-monitoring or RMF actions is strongly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

#J-18808-Ljbffr