🌎
This job posting isn't available in all website languages
📅
25141889 Requisition #
Thanks for your interest in the Information Systems Security Officer - ISSO (66652) position. Unfortunately this position has been closed but you can search our 230 open jobs by clicking here.

What are we looking for?

We are looking for people that have a passion for cybersecurity, a commitment to continuous learning, and a desire to protect citizen’s data.

Education, Experience, and Expertise: 

This position can be hired as a mid-level or senior-level ISSO, depending on experience, education, and expertise.  
    
Mid-level Required:

  • Associate degree or higher in a Risk Management related field; AND
  • 2+ years of fulltime experience in a Risk Management-related role.
  • Alternate combinations of education, experience and certifications will be considered on a case-by-case basis.

Senior-level Required:

  • Associate degree or higher in a Risk Management related field; AND
  • 4+ years of fulltime experience in a Risk Management-related role; AND
  • Either the CAP or the CGRC certifications.
  • Alternate combinations of education, experience and certifications will be considered on a case-by-case basis.

Preferred:

  • Bachelor degree or higher in a Risk Management related field; AND
  • 6+ years of fulltime experience in a Risk Management-related role; AND
  • One or more professional certifications: CAP/CGRC, SSCP, GIAC GCLD, CISSP, CISM, or other security certifications.

If hired as a mid-level ISSO, you will be required to take the CGRC exam during the first year of your employment if you do not already have the CAP or CGRC certification.  If hired as a senior-level ISSO, you will be required to already have the CAP or CGRC certification.  Additional training requirements will vary based on your specific skillsets and the team’s specific needs at the time of hiring.  Training courses may include the ISC2 Governance, Risk and Compliance course, RSA Archer courses, SANS cybersecurity courses, or other training related to this role.  Specific training requirements will be discussed at the time of hiring.

Competencies:

This position is classified by the NICE Framework as Risk Management: Oversees, evaluates, and supports the documentation, validation, assessment, and authorization processes necessary to assure that existing and new information technology systems meet the organization's cybersecurity and risk requirements. Ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives.

The following knowledge, skills, and abilities are required to be successful in this job:

Knowledge of: 

  • Risk Management Framework (NIST 800-37, 39, and 800-53) requirements;
  • Information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption);
  • Computer networking concepts and protocols, and network security methodologies; and
  • Authentication, authorization, and access control methods.

Skill in: 

  • Using a Governance, Risk and Compliance platform;
  • Interfacing with information system owners;
  • Writing security assessment reports, accreditation packages, and Plan of Actions and Milestones;
  • Developing computer or information security policies or procedures; 
  • Maintaining knowledge about emerging industry or technology trends; 
  • Reviewing system security plan documentation;
  • Implementing security measures for computer or information systems;
  • Developing systems security plans;
  • Testing computer system operations to ensure proper functioning; and 
  • Collaborating with others to resolve information technology issues.

Ability to: 

  • Identify systemic security issues based on the analysis of vulnerability and configuration data;
  • Communicating complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means;
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation);
  • Interpret and apply laws, regulations, policies, and guidance relevant to organization cyber objectives;
  • Work with Information System Owners (ISOs) to complete system categorization, select security controls, and perform self-assessments;
  • Identify risks, prioritize those risks, and maintain a Plan of Action and Milestones for escalating and presenting those risks to senior leadership;
  • Gather the information necessary to maintain security and establishes functioning external barriers, including firewalls, and other security measures;
  • Review systems to identify potential security weaknesses, recommend improvements to amend vulnerabilities, implement changes, and document upgrades;
  • Ensure security assessments and authorizations (A&A) of information systems are completed in accordance with the published Policies, Standards and Procedures, providing appropriate level of support for A&A activities; and 
  • Review security assessment reports (SAR) and assist audit teams throughout the assessment and authorization process.

Does this sound like you?  Please tell us how and why by submitting your resume and cover letter.

What can you expect from us in return for your hard work?  Benefits include:

  • Work/life Balance
  • Health Coverage
  • Retirement plans
  • Paid Vacation and Sick Leave and Holidays
  • And more…

Public Service Loan Forgiveness (PSLF) – Employment with the State of Montana may qualify you to receive student loan forgiveness under the PSLF.

Other important information to be aware of.

  • This position requires the successful completion of a criminal background check.
  • Only online applications are accepted.  By applying online, you are able to receive updates and monitor the status of your application.
     

Previous Job Searches

Activity Feed

34
Job shares through State of Montana
Someone applied to the Probation Parole Officer position. 2 days ago
Someone applied to the Heavy Equipment Mechanic 2 - Equipment Development Center position. 2 days ago
Someone applied to the Recreation Therapist position. 6 days ago
Someone applied to the Recreation Manager position. Mar 26, 2026
Someone applied to the Recreation Manager position. Mar 24, 2026

Similar Listings

Lewis And Clark, Montana, United States

📁

Requisition #: 25142062

Lewis And Clark, Montana, United States

📁

Requisition #: 25142081

Lewis And Clark, Montana, United States

📁

Requisition #: 25141194