Dynamic Aviation→
Information Systems Security Officer (ISSO) at Dynamic… · Bridgewat…
Job Description
Live an Adventure, Master your Craft, Find your Purpose
At Dynamic Aviation, we solve unique challenges for our customers with innovative aviation solutions. Our focus is on operations that serve, protect, and enhance the lives of families and communities worldwide. Whether modifying aircraft to help protect our service members overseas, performing geographical mapping for scientific research, or working to suppress large wildfires on the West Coast, we serve with integrity and excellence.
Position Summary: The Information Systems Security Officer (ISSO) is responsible for supporting the security, compliance, and ongoing authorization of organizational information systems, with particular emphasis on systems that process, store, or transmit Controlled Unclassified Information (CUI) and other sensitive information. This role works closely with IT, System Owners, Business Stakeholders, leadership and third-party security partners to implement and maintain security controls, monitor system security, manage compliance documentation, identify and remediate vulnerabilities and support cybersecurity assessments and audits. This position plays a key role in maintaining compliance with applicable cybersecurity requirements including CMMC Level 2, NIST SP 800-171, DFARS requirements and organizational security policies and procedures.
Key Responsibilities:
• Security & Compliance Management – Maintain compliance with applicable cybersecurity requirements, including CMMC Level 2, NIST SP 800-171, DFARS, ITAR, PCI DSS, and company security policies.
• Security Control Oversight – Ensure required security controls are implemented, operating effectively, documented, and periodically reviewed.
• CMMC & Audit Readiness – Maintain continuous readiness for C3PAO and other cybersecurity assessments, including coordinating evidence collection, control validation, and remediation. SPRS score maintenance and subcontractor flow-down compliance.
• Security Documentation – Maintain the System Security Plan (SSP), POA&Ms, policies, procedures, risk assessments, control evidence, and other required compliance documentation.
• Vulnerability & Risk Management – Identify, assess, track, and coordinate remediation of vulnerabilities, security deficiencies, and compliance gaps. Experience with Tenable.IO vulnerability management preferred.
• Daily hands-on SIEM/XDR review
• Access & System Security – Review access controls, privileged accounts, system configurations, security baselines, logging, encryption, and other protections for sensitive systems and CUI.
• Security Monitoring & Incident Response – Actively monitor security events and alerts and Coordinate with IT and security/SOC providers to monitor security events, investigate incidents, document findings, and work directly with IT and security/SOC providers through appropriate remediation.
• Technology & Vendor Security Reviews – Evaluate new applications, SaaS platforms, AI tools, hardware, vendors, and system changes for cybersecurity and compliance risks.
• CUI Protection & Scope Management – Help maintain the security boundary for systems that store, process, or transmit CUI and ensure appropriate handling and protection requirements are followed.
• Policy & Security Awareness/Tracking/Reporting – Develop and maintain cybersecurity policies, standards, procedures, and security-awareness requirements. Tracking and reporting on Security Awareness metrics.
• Cross-Functional Coordination – Work with IT, Legal, Contracts, business owners, leadership, vendors, consultants, and assessors to address cybersecurity and compliance requirements.
• Continuous Improvement – Monitor changes in cybersecurity requirements and threats and recommend improvements to strengthen the organization's overall security posture.
• Other duties as assigned
Required Qualifications
• Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or a related field; equivalent relevant experience may be considered in lieu of a degree.
• 3+ years of experience in cybersecurity, information security, IT security, systems administration, IT compliance, or a related technical field.
• Working knowledge of cybersecurity frameworks and requirements, particularly NIST SP 800-171 and CMMC Level 2.
• Hands-on experience working in a DoD/DoW contractor or subcontractor environment.
• Experience with Tenable.io, Microsoft Sentinel, and Microsoft Defender for Endpoint (or comparable SIEM/XDR/vulnerability management platforms)
• CompTIA Security+ CE certification
• Understanding of core security concepts, including access control, identity management, least privilege, encryption, vulnerability management, system hardening, logging, monitoring, and incident response.
• Experience implementing, maintaining, or assessing technical and administrative security controls.
• Experience creating and maintaining cybersecurity documentation, including policies, procedures, System Security Plans (SSPs), POA&Ms, risk assessments, and compliance evidence.
• Familiarity with Microsoft Windows, Active Directory, Microsoft 365, Azure/Entra ID, and enterprise security technologies.
• Ability to identify cybersecurity risks and compliance gaps and coordinate remediation with technical teams and system owners.
• Strong analytical, troubleshooting, organizational, and documentation skills.
• Strong written and verbal communication skills, with the ability to communicate cybersecurity requirements and risks to both technical and non-technical stakeholders.
• Ability to appropriately handle Controlled Unclassified Information (CUI) and other sensitive or proprietary information. Ability to work independently, manage multiple priorities, and collaborate effectively with IT teams, business stakeholders, vendors, auditors, and leadership.
Preferred Qualifications
• Certified CMMC Professional (CCP)
• Experience with Governance, Risk, and Compliance (GRC) system documentation
Additional Requirements
• Ability to travel as required
• US Citizenship
• Possess or able to obtain and maintain a US Passport
• Ability to travel domestically as well as internationally
• Ability to obtain and maintain a DOD Secret Clearance
Working Conditions
• Hybrid work environment; Monday through Friday, typically 7 a.m.–4 p.m. or 8 a.m.–5 p.m., with flexibility based on business needs
• Primarily office work, with occasional work in aircraft hangars and exposure to aircraft noise, weather, and normal aviation maintenance hazards
• Frequent use of hands and fingers for typing, writing, and operating office equipment
• Ability to view computer screens for extended periods, with close vision and the ability to adjust focus
• Occasional standing, walking, bending, or reaching within the office environment and on aircraft
• Ability to lift and move items up to approximately 10–20 pounds (e.g., files, office supplies)
• Effective verbal and written communication abilities
• Ability to maintain focus and perform repetitive tasks with attention to detail
Pay Band: $88,600. - $112,000. Starting pay is determined by experience, qualifications, and internal equity, and typically falls between the minimum and midpoint of the pay range.
It is the policy of Dynamic Aviation to prohibit and eliminate discrimination on grounds of race, color, religion, sex, (including pregnancy, childbirth or related medical conditions), sexual orientation, gender identity, national origin, ancestry, age, disability, veteran status, marital status, or any other characteristics protected by law. It is also Dynamic Aviation's policy to provide equal employment for all and comply with any affirmative action obligations pursuant to the Federal Executive Orders, 11246 and 11375, as amended.