1

Isso Issm Jobs in Minnesota (NOW HIRING)

It will be required to work in close coordination with the ISSM and ISO in monitoring the ... Perform ISSO duties in support of in-house and external customers * Conduct security impact ...

Isso Issm information

What are the main challenges faced by an ISSO or ISSM when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What are the key skills and qualifications needed to thrive as an ISSO or ISSM?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

What is an Information Systems Security Officer (ISSO)?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.
What are popular job titles related to Isso Issm jobs in Minnesota? For Isso Issm jobs in Minnesota, the most frequently searched job titles are:
What job categories do people searching Isso Issm jobs in Minnesota look for? The top searched job categories for Isso Issm jobs in Minnesota are:
What cities in Minnesota are hiring for Isso Issm jobs? Cities in Minnesota with the most Isso Issm job openings:
Infographic showing various Isso Issm job openings in Minnesota as of July 2026, with employment types broken down into 94% Full Time, 4% Part Time, and 2% Contract. Highlights an 94% Physical, 3% Hybrid, and 3% Remote job distribution.

Info Systems Security Officer - Administration

skywater

Minneapolis, MN

Other

Posted 4 days ago


Job description

The Information Systems Security Officer provides day-to-day support to the ISSO, ISSM, and Cyber Governance, Risk, and Compliance (GRC) function across both governed environments (commercial and federal) while developing along a structured path from analyst toward security engineer. The role assists with security documentation, authorization and audit evidence, continuous monitoring records, and SOC and incident-response activity, and receives supervised, hands-on exposure to control implementation, system hardening, secure configuration, and remediation validation. This is a developmental and supervised role that supports, rather than independently owns, ISSO, ISSM, and Cyber GRC deliverables. Commercial work follows NIST CSF 2.0, CMMC, and SOX, evidenced in Drata. Federal work follows RMF, NISPOM, and DFARS 252.204-7012, and for ATO, classified, air-gapped, isolated, or CUI/FCI systems is performed only through the ISSM, ISSE, and ISSO approved authorization structure, evidenced in eMASS.

Responsibilities:

Commercial Environment (SkyWater Technology: NIST CSF 2.0, CMMC, SOX)

  • Collect, organize, index, review, and maintain control evidence across NIST CSF 2.0, CMMC, NIST SP 800-171, and SOX, supporting Cyber GRC in Drata as the commercial system of record.
  • Support commercial audit readiness, including self-assessments, control reviews, evidence refreshes, and SOX and CMMC assessment activities.
  • Track commercial findings, control deficiencies, and remediation through documented closure or approved risk disposition.
  • Assist with commercial continuous monitoring, including evidence refreshes, configuration reviews, and control-status updates in Drata.

Federal Environment (SkyWater Federal: RMF, NISPOM, DFARS 252.204-7012)

  • Support the ISSO with day-to-day maintenance of federal security artifacts, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control implementation statements, authorization records, and Enterprise Mission Assurance Support Service (eMASS) entries.
  • Assist with eMASS package updates, evidence uploads, control-status updates, milestone tracking, and package-quality reviews.
  • Support assessment and authorization (A&A) package preparation, self-inspections, and government or customer assessment activities under ISSO and ISSM direction.
  • Assist with federal continuous monitoring aligned to NIST SP 800-53 and DFARS 252.204-7012, including evidence refreshes, vulnerability-status and security-control reviews, configuration reviews, change documentation, and authorization-package updates.
  • Preserve authorization-boundary evidence, and perform work on classified, air-gapped, isolated, or CUI/FCI systems only through approved ISSM, ISSE, ISSO, system-administration, and change-management channels.
  • Identify and report undocumented changes, configuration deviations, and missing or expired evidence affecting authorization posture; treat undocumented deviations within a boundary as potential findings and escalate to the ISSO and ISSM.
  • Support NISPOM and ICD-aligned handling, security training records, authorized-user records, and other system-specific compliance records as assigned.
  • Security Operations and Engineering Development 
  • Monitor and respond to SOC alerts and detections, and support incident response activations across commercial and federal environments, following environment-specific handling on authorized systems.
  • Work alongside Security Architecture and Engineering to gain hands-on experience with control implementation, secure configuration, and system hardening, evaluating configurations against DISA STIGs, CIS Benchmarks, and organization-approved baselines.
  • Review vulnerability scan results and configuration findings to help determine whether corrective actions adequately address identified deficiencies and support technical validation of remediation as a structured engineering-development activity.
  • Maintain accurate, traceable, assessment-ready documentation in approved systems of record, and coordinate with GRC, Security Engineering, system administrators, and system owners to collect evidence and track assigned actions.
  • Participate in structured training, mentoring, technical labs, and progressively independent assignments that build toward a security engineering role.

The job also requires performing other duties as assigned. Duties may be modified with concurrence of the Contracting Officer, contractor Program Manager and Information Systems Security Manager (ISSM).

 

Required Qualifications:

Education: Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related field.

  • Four years of relevant professional experience may be considered in place of the degree.
  • Sufficient certifications and industry training may also be considered in place of the degree.

 

Experience and Skills:

  • One or more years of relevant professional, internship, military, or substantive academic experience in cybersecurity, IT, systems administration, information assurance, or federal compliance support.
  • Exposure to federal information-security requirements, cybersecurity controls, or the NIST Risk Management Framework, and to maintaining organized technical documentation or compliance evidence.
  • Foundational familiarity with the NIST 800 series (including SP 800-53 and SP 800-171) and the NIST Risk Management Framework and authorization lifecycle.
  • Basic understanding of security controls, continuous monitoring, assessment evidence, and findings management.
  • Basic systems-administration aptitude across Windows, Linux, networking, identity, or cloud domains.
  • Strong documentation, organization, and evidence-handling discipline, with the ability to work within defined authorization and change-management structures.
  • Effective communication with technical, compliance, and leadership stakeholders, and working knowledge of Microsoft Word, Excel, and PowerPoint.
  • Demonstrated interest in developing toward a security engineering role.

 

Certifications & DoD Framework:

  • CompTIA Security+ CE required at the time of hire or within six months of the date of hire (preferred minimum certification).
  • Must meet applicable DoD 8140.03 and DoD Cyber Workforce Framework qualification requirements for the assigned work role and proficiency level, at minimum equivalent to the legacy DoD 8570.01-M Information Assurance Technician Level II baseline and complete any component- or customer-specific requirements for the assigned role.

 

Clearance & Security Requirements

  • US Citizen with minimum Secret Clearance eligibility (TS/SCI preferred). Must be able to obtain and maintain the clearance and system access required for assigned duties.
  • Must comply with need-to-know, information-handling, personnel-security, facility-security, and authorized-system requirements, and perform federal-system work only within the assigned ISSM, ISSE, and ISSO authorization structure.
  • Occasional travel up to 10% may be required.

Desired Qualifications:

Education:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related engineering-adjacent field.

 

Experience:

  • Two to three years in IT, systems administration, security operations, federal compliance, or information assurance.
  • Hands-on support of eMASS entries, SSP maintenance, POA&M tracking, evidence collection, control assessments, or continuous monitoring, in a government-contractor, cleared, regulated, CUI, or classified environment.
  • Experience supporting technical remediation, vulnerability management, system hardening, or configuration validation, and personal lab, scripting, or homelab experience demonstrating initiative.

 

Skills and Certifications:

  • Basic scripting using PowerShell, Python, Bash, or an equivalent language, and familiarity with DISA STIGs, CIS Benchmarks, and secure configuration practices.
  • Familiarity with Windows or Linux administration, Active Directory, Microsoft Entra ID, networking, cloud, virtualization, or endpoint management, and with vulnerability scanners, GRC platforms (Drata), or authorization systems (eMASS).

 

 

Physical Requirements & Environmental Conditions:

Ability to perform standard office and workstation functions, including extended computer use, documentation review, data entry, technical analysis, and virtual collaboration, with on-site engagements as needed. The position may require access to secure facilities, controlled work areas, authorized information systems, and air-gapped or isolated environments. Reasonable accommodation will be made for qualified individuals with disabilities.