FSO/ISSM

Posted Yesterday
Be an Early Applicant
Oxnard, CA, USA
In-Office
Mid level
Hardware
The Role
Dual-role FSO/ISSM responsible for NISP compliance and DoD RMF accreditation. Manage eMASS SSPs, conduct risk/vulnerability assessments, maintain DISS/NISS records, oversee physical security (CCTV, access control), administer security training, and liaise with government security agencies.
Summary Generated by Built In
Job Summary & Responsibilities

Job Summary:
In this role, you will serve as the Facility Security Officer (FSO) for the Oxnard, CA site, with full responsibility for ensuring compliance with the National Industrial Security Program (NISP). In this dual-function position, you will also act as the Information Systems Security Manager (ISSM), overseeing the security of classified information systems across multiple Mercury locations.

 

As the FSO, you will manage all aspects of NISP compliance, implement and enforce security policies and procedures, and ensure full adherence to U.S. Government requirements. As the ISSM, you will be responsible for the overall security posture of classified information systems, including configuration, protection, assessment, and accreditation under the DoD Risk Management Framework (RMF).

 

Key responsibilities include aligning security program goals with organizational objectives, assessing and mitigating risk, ensuring regulatory compliance, protecting personnel, information, facilities, and business operations.

 

Job Responsibilities:

  • Collaborate with the Corporate ISSM to ensure all accredited information systems meet RMF requirements.
  • Prepare, maintain, and upload System Security Plans (SSPs) and supporting artifacts in eMASS.
  • Ensure SSPs accurately reflect system configuration and required security controls.
  • Support certification testing and assessments conducted by the Cognizant Security Agency (CSA).
  • Maintain facility information system records in eMASS.
  • Develop and maintain procedures supporting Configuration Management (CM) for security relevant hardware, software, and firmware.
  • Conduct risk and vulnerability assessments of classified systems and verify the effectiveness of security controls.
  • Ensure compliance with DoD certification and accreditation requirements, including DoDI 8510.01 (RMF for DoD IT).
  • Install, update, and maintain security-related software tools to detect malicious code, viruses, and unauthorized intrusions.
  • Provide Security guidance to and regularly interact with Program Managers, Engineering/Production, Management, and Human Resources.
  • Responsible for the administration and coordination of the DOD and other industrial security programs and activities to ensure compliance with 32 CFR 117 and other government and company security policies and procedures.
  • Coordinate due diligence and risk assessments whose objective is to identify improvements in the existing physical security controls in place for non-NISP security function at assigned facilities.
  • Maintain and provide security classification guidance of DD254’s, Security Classification Guides, and other documents related to security requirements for assigned programs.
  • Operate and maintain a security education, training, and awareness program to include indoctrinations, annual refresher training, debriefings, courier, travel, event specific briefings, and OPSEC procedures.
  • Respond to intrusion alarms as needed.
  • Manage physical security for the site, including intrusion detection, access control, CCTV, security hardware, and GSA approved containers.
  • Respond to intrusion alarms as necessary.
  • Be the direct liaison for the facility with the Defense Counterintelligence and Security Agency (DSCA) and other government agencies.

 Required Qualifications:

  • Typically requires 4 years of experience in cybersecurity, information systems security, RMF, and Certification & Accreditation (C&A) processes.
  • Active Secret Clearance.
  • Experience working with eMASS and RMF procedures.
  • Demonstrated ability to conduct thorough risk assessments and manage complex documentation.
  • Experience of network assets and peripheral equipment.
  • Maintain facility and personnel information in DISS and NISS. 

Preferred Qualifications:

  • Experience with large, multi‑facility networks in Windows and Linux environments.
  • Familiarity with cyber incident response, including preservation, containment, and eradication.
  • CISSP, CASP, or similar certification.
  • FSO & ISSM Certification with in 6 months of hire.
  • Master's degree in Information Systems or related field.
  • High initiative, strong attention to detail, analytical skills, and organizational capability.
  • Ability to work effectively both independently and collaboratively.

 

#LI-RL1

 

"This position requires you to access information that is subject to U.S. export regulations. You may only access such information if you are a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. government."

Preferred Qualifications
Why should you join Mercury Systems?

Mercury Systems is a technology company that makes the world a safer, more secure place. We push processing power to the tactical edge, making the latest commercial technologies profoundly more accessible for today's most challenging aerospace and defense missions. From silicon to system scale, Mercury enables customers to accelerate innovation and turn data into decision superiority. Headquartered in Andover, Massachusetts, Mercury employs more than 2,300 people in 24 locations worldwide. To learn more, visit mrcy.com

Our Culture

We are committed to making Mercury a great place to work, no matter where our employees are located. We offer a casual and enjoyable atmosphere that allows employees to learn and grow. We help and care for one another and work as one to achieve results for us and for our customers. We value communication and transparency, and strive to foster two-way dialogue at all levels of the organization. We are committed to lifelong learning, offering comprehensive skills training and tuition reimbursement. Whether you're just starting out on your career journey or you are an experienced professional, it's important to us that you feel recognized and rewarded for your contributions.

To find out more about Why Mercury?, or visit the Mercury Community or find answers to general questions at Mercury FAQs

Mercury Systems is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex (including pregnancy), sexual orientation, gender identity, national origin, genetic information, creed, citizenship, disability, protected veteran or marital status.

As an equal opportunity employer, Mercury Systems is committed to a diverse workforce. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Veterans' Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants that require accommodation in the job application process may contact the number below for assistance.

(978) 256-1300

Click here read about our recent press release.

Skills Required

  • 4 years of experience in cybersecurity, information systems security, RMF, and Certification & Accreditation (C&A) processes
  • Active Secret Clearance
  • Experience working with eMASS and RMF procedures
  • Ability to conduct thorough risk and vulnerability assessments and manage complex security documentation
  • Experience with network assets and peripheral equipment
  • Maintain facility and personnel information in DISS and NISS
  • Authorized access eligibility (U.S. citizen, lawful permanent resident, protected individual, or eligible to obtain required authorizations)
  • Experience with large, multi-facility networks in Windows and Linux environments
  • Familiarity with cyber incident response (preservation, containment, eradication)
  • CISSP, CASP, or similar certification
  • FSO & ISSM Certification within 6 months of hire
  • Master's degree in Information Systems or related field
  • High initiative, strong attention to detail, analytical and organizational skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Andover, MA

What We Do

Mercury Systems is the leader in making trusted, secure mission-critical technologies profoundly more accessible to the aerospace and defense industries. Optimized for customer and mission success, our innovative solutions power more than 300 critical aerospace and defense programs.

Similar Jobs

Toast Logo Toast

Senior Analyst, Product & Pricing (Finance & Strategy)

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
San Francisco, CA, USA
5000 Employees
102K-163K Annually

Toast Logo Toast

Data Analyst

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
San Francisco, CA, USA
5000 Employees
125K-200K Annually

Toast Logo Toast

Sales Manager

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
Los Angeles, CA, USA
5000 Employees
183K-293K Annually

Granica Logo Granica

Senior Software Engineer

Artificial Intelligence • Big Data • Cloud • Machine Learning • Software • Business Intelligence • Data Privacy
In-Office
Mountain View, CA, USA
45 Employees
190K-250K Annually

Similar Companies Hiring

Red 6 Thumbnail
Aerospace • Hardware • Software • Virtual Reality • Defense
Orlando, Florida
186 Employees
Blissway Thumbnail
Computer Vision • Fintech • Hardware • Internet of Things • Machine Learning • Software • Transportation
Denver, CO
24 Employees
Fairly Even Thumbnail
Hardware • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account