EVONA · 5 hours ago
Information Systems Security Officer
EVONA is a fast-growing space technology company focused on transforming satellite operations through modern, cloud-native mission operations software. The Information Systems Security Officer (ISSO) will establish and maintain information security policies, lead the Risk Management Framework process, and collaborate with various stakeholders to ensure compliance and security of classified systems.
Responsibilities
Develop and enforce information security policies, standards, and procedures aligned with CNSSI 1253, NIST SP 800-53, NIST SP 800-60, and applicable federal regulations
Ensure policies remain current and responsive to evolving threats and vulnerabilities
Conduct regular risk and vulnerability assessments
Implement mitigation strategies and manage RMF activities
Maintain IATT and ATO status through formal assessments and continuous monitoring
Support government-led security control assessments
Develop and maintain an Incident Response Plan
Lead investigations, containment, and remediation of security incidents
Review and adjudicate SIEM alerts and events
Create and maintain System Security Plans (SSPs) within eMASS for SECRET and/or UNCLASS systems
Collect and manage required artifacts, including policies, procedures, compliance evidence, and vulnerability reports
Deliver security awareness and training for users of classified systems
Act as a trusted security point of contact across technical and non-technical teams
Continuously improve security processes and controls
Qualification
Required
US Citizenship
Active SECRET clearance, TS/SCI strongly preferred
Bachelor's degree in Information Security, Computer Science, or a related field
5+ years of experience in information security supporting government-authorized systems
Strong knowledge of RMF, CNSSI, and NIST frameworks
Hands-on experience with SIEM, IDS/IPS, STIG hardening, and vulnerability management tools
Exposure to Kubernetes, cloud-based classified environments, CI/CD pipelines, and secure network architecture
IAT Level II certification required (e.g., CompTIA Security+ or equivalent)
Strong communication and stakeholder management skills
Analytical mindset with the ability to manage multiple priorities in a fast-paced environment
Applicants must meet US export control requirements and be eligible to work on ITAR-regulated programs
Preferred
IAT Level III preferred (e.g., CISSP, CISM, or equivalent)
Benefits
Generous time off
Comprehensive health coverage
Retirement contribution
Regular company offsites