Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Journeyman Cybersecurity Specialist (ISSO Focus) image - Rise Careers
Job details

Journeyman Cybersecurity Specialist (ISSO Focus)

Location: Multiple DAF Bases (NCR and CONUS)

Job Category: Information Technology

Time Type: Full-time

Clearance Requirement: Current DoD Secret Clearance required

Security Suitability: Must be able to obtain and maintain a favorable background investigation

Employee Type: W2 and 1099 options available

Citizenship: US Citizen, no Dual Citizenship



NexThreat is seeking a Journeyman Cybersecurity Specialist with a focus on Information Systems Security Officer (ISSO) responsibilities to support the Department of the Air Force (DAF). This role involves supporting the implementation and maintenance of cybersecurity programs at multiple DAF Bases. You will work as part of a team to ensure compliance with DoD and DAF cybersecurity policies, conduct risk assessments, and support the Risk Management Framework (RMF) process. Experience with site surveys is preferred.


Key Responsibilities:

·      Support the development, implementation, and maintenance of cybersecurity plans, policies, and procedures in accordance with DoD, DAF, and RMF requirements.

·    Conduct required reviews as appropriate within environment (e.g., Technical Surveillance, Countermeasure Reviews [TSCM], TEMPEST countermeasure reviews, EMSEC).

·      Assist in the assessment and authorization (A&A) process for information systems, including documentation preparation, security control assessment, and risk mitigation.

·      Conduct vulnerability scans and assist in the remediation of identified vulnerabilities.

·      Monitor security controls and system logs to identify potential security incidents and policy violations.

·      Participate in incident response activities, including investigation, containment, eradication, and recovery.

·      Provide cybersecurity guidance and support to system owners, administrators, and users.

·      Maintain accurate and up-to-date records of system configurations, security documentation, and incident reports.

·      Collaborate with other cybersecurity personnel and stakeholders to ensure a consistent and effective security posture.

·      Participate in cybersecurity meetings and interact with USG RMF personnel.

·      Conduct site surveys to assess controls.

·      Adhere to all applicable Communications Security (COMSEC) regulations, policies, and procedures.

·      Maintain COMSEC-related documentation.

·      Stay current with relevant cybersecurity regulations, policies, and best practices.


Unique Skills/Tasks/Software:

·      Required: Experience with the DoD Risk Management Framework (RMF) process.

·      Preferred: Experience with tools such as ACAS, SCAP, eMASS, Xacta, Splunk, and Microsoft Sentinel.

·      Understanding of NIST SP 800-series publications, particularly those related to risk management and security controls.


Preferred Certifications:

·      CompTIA Security+ (Foundational Qualification)

·      (ISC)² CAP (Certified Authorization Professional)

·      GIAC Security Essentials Certification (GSEC)


Qualifications:

·      Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or 4 years of relevant experience in lieu of a degree.

·      3 years of experience in cybersecurity, with a focus on ISSO responsibilities or similar roles.

·      Strong understanding of cybersecurity principles, practices, and technologies.

·      Experience with security control implementation, assessment, and documentation.

·      Familiarity with vulnerability management and incident response processes.

·      Excellent verbal and written communication skills.

·      Ability to work both independently and as part of a team.

·      Ability to obtain and maintain a Common Access Card (CAC).


NexThreat Glassdoor Company Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
NexThreat DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of NexThreat
NexThreat CEO photo
Unknown name
Approve of CEO

Average salary estimate

$75000 / YEARLY (est.)
min
max
$60000K
$90000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Journeyman Cybersecurity Specialist (ISSO Focus), NexThreat

NexThreat is on the lookout for a talented Journeyman Cybersecurity Specialist with a focus on Information Systems Security Officer (ISSO) responsibilities to join our dynamic team at Joint Base Elmendorf-Richardson, Alaska. In this full-time role, you will lend your expertise to ensure the security and compliance of systems at multiple Department of the Air Force (DAF) bases. Your day-to-day tasks will include supporting the development and maintenance of cybersecurity policies, conducting risk assessments, and helping to implement security solutions that meet DoD standards. If you have experience conducting vulnerability scans or handling incident response activities, you'll find this role particularly rewarding. Collaborating with other security personnel and stakeholders, you’ll help foster a consistent, effective security posture across the board. Engaging in site surveys and monitoring security controls will be part of your responsibilities, ensuring that all systems not only operate efficiently but also comply with the latest regulations. We seek someone with a strong background in cybersecurity principles and practices who possesses qualifications such as a Bachelor's degree in Cybersecurity or Computer Science. If you're ready to take on an important role in enhancing national security through cybersecurity, apply now and join us in safeguarding critical systems.

Frequently Asked Questions (FAQs) for Journeyman Cybersecurity Specialist (ISSO Focus) Role at NexThreat
What are the primary responsibilities of a Journeyman Cybersecurity Specialist at NexThreat?

The primary responsibilities of a Journeyman Cybersecurity Specialist at NexThreat include support for the development and implementation of cybersecurity plans, conducting risk assessments, and ensuring compliance with DoD and DAF policies. You will be involved in the assessment and authorization (A&A) process, vulnerability scanning, incident response activities, and providing guidance to system owners and users. Essentially, you'll play a key role in maintaining a secure environment across multiple DAF bases.

Join Rise to see the full answer
What qualifications are needed for the Journeyman Cybersecurity Specialist position at NexThreat?

To qualify for the Journeyman Cybersecurity Specialist position at NexThreat, candidates should ideally have a Bachelor's degree in Cybersecurity, Computer Science, or a related field, or have 4 years of relevant experience. Additionally, a minimum of 3 years of experience in cybersecurity focusing on ISSO responsibilities is required. It's important to have a strong understanding of cybersecurity principles, practices, and regulatory requirements.

Join Rise to see the full answer
What cybersecurity tools should a Journeyman Cybersecurity Specialist be familiar with?

A Journeyman Cybersecurity Specialist at NexThreat should be familiar with several key tools including ACAS, SCAP, eMASS, Xacta, Splunk, and Microsoft Sentinel. Familiarity with these tools will be instrumental in conducting vulnerability assessments, managing security controls, and ensuring effective incident response. Understanding NIST SP 800-series publications is also crucial for this position.

Join Rise to see the full answer
Is a security clearance required for the Journeyman Cybersecurity Specialist role at NexThreat?

Yes, a current DoD Secret Clearance is required for the Journeyman Cybersecurity Specialist role at NexThreat. Additionally, candidates must be eligible to obtain and maintain a Common Access Card (CAC) as part of the role's responsibilities. This is critical as it ensures that you can effectively navigate the security requirements necessary for the position.

Join Rise to see the full answer
What skills are necessary for success as a Journeyman Cybersecurity Specialist at NexThreat?

Successful candidates for the Journeyman Cybersecurity Specialist position at NexThreat should possess excellent verbal and written communication skills, a deep understanding of cybersecurity principles and technologies, and the ability to work independently and as part of a team. Familiarity with security control implementation, assessment, vulnerability management, and incident response processes are also essential skills that enhance effectiveness in this role.

Join Rise to see the full answer
Common Interview Questions for Journeyman Cybersecurity Specialist (ISSO Focus)
Can you explain the Risk Management Framework (RMF) process?

The Risk Management Framework (RMF) process is critical for assessing and managing risk for information systems. In an interview, you should explain that RMF consists of six steps: Categorize, Select, Implement, Assess, Authorize, and Monitor. Each step involves a detailed examination of security controls and their effectiveness. Employers look for professionals who can demonstrate both theoretical knowledge and practical application of RMF.

Join Rise to see the full answer
How do you approach vulnerability management?

In your response, emphasize the systematic approach you take to vulnerability management, which includes continuous scanning, risk assessment, prioritizing vulnerabilities based on severity, and applying timely patches. Discussing experience with tools like ACAS or Splunk will also be advantageous. Highlight that effective communication with stakeholders is key to remediating vulnerabilities properly.

Join Rise to see the full answer
Describe your experience with incident response.

When answering this question, share specific examples of incidents you've managed, including the steps taken for identification, containment, eradication, and recovery. Highlight any frameworks or guidelines you've followed (like NIST) and tools used during your response. Providing quantifiable results (like reduced downtime or restored services) can strengthen your answer.

Join Rise to see the full answer
What steps would you take to prepare for a security assessment?

Prepare your response by outlining a systematic approach: first, review existing documentation and security controls, closely follow compliance requirements, and conduct internal audits or readiness assessments. Mention any tools or frameworks you’d incorporate, such as using eMASS to track compliance. The goal is to ensure that you're fully prepared for an external security assessment.

Join Rise to see the full answer
How do you stay current with cybersecurity trends and best practices?

Show your commitment by discussing various methods you use to stay informed, such as subscribing to cybersecurity journals, attending conferences, and participating in professional organizations like (ISC)². Talk about how you implement learned best practices in your current role, emphasizing continuous professional development as a necessity in the ever-evolving cybersecurity field.

Join Rise to see the full answer
What do you consider to be the biggest cybersecurity threat today?

This target answer should discuss prevalent threats such as ransomware, insider threats, or advanced persistent threats (APTs). Explain your reasoning by citing recent events or incidents in the industry. It's important to show that you are not only aware of current trends but also understand the implications they have on cybersecurity measures.

Join Rise to see the full answer
How would you ensure compliance with DoD and DAF cybersecurity regulations?

In your answer, discuss your familiarity with regulations such as NIST SP 800-series and how you would regularly audit and update security policies to reflect compliance. Mention conducting training for staff and keeping abreast of any updates to regulations. Compliance isn't just about following procedures; it's about fostering a culture of security within the organization.

Join Rise to see the full answer
Can you describe a successful cybersecurity project you've led or contributed to?

Choose a project where you played a key role, outlining your contributions from planning through execution and reflection. Highlight your teamwork, communication, and problem-solving skills. Emphasizing a measurable positive outcome, such as decreased security incidents or improved compliance, will illustrate your effectiveness in the role.

Join Rise to see the full answer
What methodologies do you follow for conducting security assessments?

Explain the methodologies you utilize, such as NIST or ISO standards, and talk about how you tailor your assessments based on specific organizational needs. Mention the importance of various assessments like vulnerability assessments and penetration testing, along with effective reporting practices that communicate results clearly to stakeholders.

Join Rise to see the full answer
How do you handle documentation of security policies and procedures?

Your answer should reflect an understanding of the importance of accurate documentation. Discuss the practices you follow, like regularly updating documentation, ensuring clarity, and facilitating accessibility for all relevant stakeholders. Highlight how thorough documentation plays a crucial role in compliance and knowledge transfer within the organization.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
NexThreat Hybrid Joint Base Elmendorf-Richardson, Alaska
Posted 2 days ago
Cerebras Systems Hybrid Sunnyvale CA or Toronto Canada
Posted 7 days ago
The Internet of Behaviors Company Remote Remote, Greater Pretoria Region, South Africa
Posted 7 days ago
Photo of the Rise User
Visa Remote Basingstoke, United Kingdom
Posted 2 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
EngFlow Inc. Remote No location specified
Posted 3 days ago
Photo of the Rise User
Posted 2 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!