Bold Thinking. World Changing. At SkyWater, our ingenuity helps improve lives around the world by manufacturing U.S. made semiconductors that are essential ingredients of modern life. Automotive safety enhancements, life-saving medical devices, consumer electronics and American security require semiconductors. Working in our Minnesota headquarters, Florida, or Texas location - employees join together to improve the world.
Explore what's possible. Joining our U.S. - based team means contributing to and learning about the commercialization of some of the most exciting technologies the world has ever seen. We are turning "science fiction" into everyday reality through technologies such as superconducting, 3D integrated circuits or computer chips, carbon nanotubes, photonic logic devices, micro electro-mechanical systems and other emerging device topologies. We manufacture products for aerospace and defense, medical, automotive, consumer and industrial markets, to name a few. Our customers include emerging leaders who rely on our intellectual property security and quality manufacturing services.
Step into the future. SkyWater's values of Integrity, Excellence, Collaboration, Empowerment and Growth Mindset guide us to cultivate an empowered, learning environment. We also invest in developing highly skilled, dedicated employees - and employees who are entering the workforce for the first time, from the military, and a variety of educational backgrounds.
Are you bold thinking? Find your place on our team and help us change the world!
The Information Systems Security Officer provides day-to-day support to the ISSO, ISSM, and Cyber Governance, Risk, and Compliance (GRC) function across both governed environments (commercial and federal) while developing along a structured path from analyst toward security engineer. The role assists with security documentation, authorization and audit evidence, continuous monitoring records, and SOC and incident-response activity, and receives supervised, hands-on exposure to control implementation, system hardening, secure configuration, and remediation validation. This is a developmental and supervised role that supports, rather than independently owns, ISSO, ISSM, and Cyber GRC deliverables. Commercial work follows NIST CSF 2.0, CMMC, and SOX, evidenced in Drata. Federal work follows RMF, NISPOM, and DFARS 252.204-7012, and for ATO, classified, air-gapped, isolated, or CUI/FCI systems is performed only through the ISSM, ISSE, and ISSO approved authorization structure, evidenced in eMASS.
Responsibilities:
Commercial Environment (SkyWater Technology: NIST CSF 2.0, CMMC, SOX)
- Collect, organize, index, review, and maintain control evidence across NIST CSF 2.0, CMMC, NIST SP 800-171, and SOX, supporting Cyber GRC in Drata as the commercial system of record.
- Support commercial audit readiness, including self-assessments, control reviews, evidence refreshes, and SOX and CMMC assessment activities.
- Track commercial findings, control deficiencies, and remediation through documented closure or approved risk disposition.
- Assist with commercial continuous monitoring, including evidence refreshes, configuration reviews, and control-status updates in Drata.
Federal Environment (SkyWater Federal: RMF, NISPOM, DFARS 252.204-7012)
- Support the ISSO with day-to-day maintenance of federal security artifacts, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control implementation statements, authorization records, and Enterprise Mission Assurance Support Service (eMASS) entries.
- Assist with eMASS package updates, evidence uploads, control-status updates, milestone tracking, and package-quality reviews.
- Support assessment and authorization (A&A) package preparation, self-inspections, and government or customer assessment activities under ISSO and ISSM direction.
- Assist with federal continuous monitoring aligned to NIST SP 800-53 and DFARS 252.204-7012, including evidence refreshes, vulnerability-status and security-control reviews, configuration reviews, change documentation, and authorization-package updates.
- Preserve authorization-boundary evidence, and perform work on classified, air-gapped, isolated, or CUI/FCI systems only through approved ISSM, ISSE, ISSO, system-administration, and change-management channels.
- Identify and report undocumented changes, configuration deviations, and missing or expired evidence affecting authorization posture; treat undocumented deviations within a boundary as potential findings and escalate to the ISSO and ISSM.
- Support NISPOM and ICD-aligned handling, security training records, authorized-user records, and other system-specific compliance records as assigned.
- Security Operations and Engineering Development
- Monitor and respond to SOC alerts and detections, and support incident response activations across commercial and federal environments, following environment-specific handling on authorized systems.
- Work alongside Security Architecture and Engineering to gain hands-on experience with control implementation, secure configuration, and system hardening, evaluating configurations against DISA STIGs, CIS Benchmarks, and organization-approved baselines.
- Review vulnerability scan results and configuration findings to help determine whether corrective actions adequately address identified deficiencies and support technical validation of remediation as a structured engineering-development activity.
- Maintain accurate, traceable, assessment-ready documentation in approved systems of record, and coordinate with GRC, Security Engineering, system administrators, and system owners to collect evidence and track assigned actions.
- Participate in structured training, mentoring, technical labs, and progressively independent assignments that build toward a security engineering role.
The job also requires performing other duties as assigned. Duties may be modified with concurrence of the Contracting Officer, contractor Program Manager and Information Systems Security Manager (ISSM).
Required Qualifications:
Education: Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related field.
- Four years of relevant professional experience may be considered in place of the degree.
- Sufficient certifications and industry training may also be considered in place of the degree.
Experience and Skills:
- One or more years of relevant professional, internship, military, or substantive academic experience in cybersecurity, IT, systems administration, information assurance, or federal compliance support.
- Exposure to federal information-security requirements, cybersecurity controls, or the NIST Risk Management Framework, and to maintaining organized technical documentation or compliance evidence.
- Foundational familiarity with the NIST 800 series (including SP 800-53 and SP 800-171) and the NIST Risk Management Framework and authorization lifecycle.
- Basic understanding of security controls, continuous monitoring, assessment evidence, and findings management.
- Basic systems-administration aptitude across Windows, Linux, networking, identity, or cloud domains.
- Strong documentation, organization, and evidence-handling discipline, with the ability to work within defined authorization and change-management structures.
- Effective communication with technical, compliance, and leadership stakeholders, and working knowledge of Microsoft Word, Excel, and PowerPoint.
- Demonstrated interest in developing toward a security engineering role.
Certifications & DoD Framework:
- CompTIA Security+ CE required at the time of hire or within six months of the date of hire (preferred minimum certification).
- Must meet applicable DoD 8140.03 and DoD Cyber Workforce Framework qualification requirements for the assigned work role and proficiency level, at minimum equivalent to the legacy DoD 8570.01-M Information Assurance Technician Level II baseline and complete any component- or customer-specific requirements for the assigned role.
Clearance & Security Requirements
- US Citizen with minimum Secret Clearance eligibility (TS/SCI preferred). Must be able to obtain and maintain the clearance and system access required for assigned duties.
- Must comply with need-to-know, information-handling, personnel-security, facility-security, and authorized-system requirements, and perform federal-system work only within the assigned ISSM, ISSE, and ISSO authorization structure.
- Occasional travel up to 10% may be required.
Desired Qualifications:
Education:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related engineering-adjacent field.
Experience:
- Two to three years in IT, systems administration, security operations, federal compliance, or information assurance.
- Hands-on support of eMASS entries, SSP maintenance, POA&M tracking, evidence collection, control assessments, or continuous monitoring, in a government-contractor, cleared, regulated, CUI, or classified environment.
- Experience supporting technical remediation, vulnerability management, system hardening, or configuration validation, and personal lab, scripting, or homelab experience demonstrating initiative.
Skills and Certifications:
- Basic scripting using PowerShell, Python, Bash, or an equivalent language, and familiarity with DISA STIGs, CIS Benchmarks, and secure configuration practices.
- Familiarity with Windows or Linux administration, Active Directory, Microsoft Entra ID, networking, cloud, virtualization, or endpoint management, and with vulnerability scanners, GRC platforms (Drata), or authorization systems (eMASS).
Physical Requirements & Environmental Conditions:
Ability to perform standard office and workstation functions, including extended computer use, documentation review, data entry, technical analysis, and virtual collaboration, with on-site engagements as needed. The position may require access to secure facilities, controlled work areas, authorized information systems, and air-gapped or isolated environments. Reasonable accommodation will be made for qualified individuals with disabilities.
The annual salary range for this role is $78,240- $117,360. Pay offered is based on many factors including, but not limited to, the job-related experience, skills, education, and credentials of each candidate. SkyWater offers an exciting environment where the brightest semiconductor minds come together to achieve exceptional results. We offer competitive salary and an opportunity to participate in incentive plans as well other employee financial benefits including 401k match, life insurance and opportunities to purchase SkyWater stock at a discounted rate.
Additionally, SkyWater offers a comprehensive benefits package which promotes a healthy life. This includes benefit eligibility day one, medical, dental, mental health benefits, vision, legal planning, short- and long-term disability, paid time off, paid holidays, an on-site fitness facility, and an on-site self-serve market.
SkyWater complies with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities unless doing so would cause an undue hardship. Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. To request reasonable accommodations, to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Human Resources at 952-851-5200 or Recruiting@SkyWatertechnology.com.
EOE, including disability/vets
We will never ask applicants to pay fees, purchase equipment or gift cards, or provide financial information before a formal offer of employment has been accepted. If you receive a suspicious communication claiming to represent our company, please verify its authenticity by contacting our recruitment team at recruiting@skywatertechnology.com before responding.
|