Information System Security Officer - ISSO

General Atomics

Herndon (VA)

On-site

USD 89,180 - 155,825

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

General Atomics in Herndon, VA seeks an Information Systems Security Officer (ISSO) to lead vulnerability assessments, audits, and RMF-based security controls across the organization. The role requires active TS with SAP/SCI eligibility, Security+ certification, and DoD RMF experience.

Responsibilities include implementing security for LAN/WAN, servers, and virtualization, plus monitoring for IoC and guiding remediation efforts using Splunk, Nessus, ACAS, and STIG tools.

Qualifications

  • Bachelor's degree in a related discipline and six or more years of progressive professional experience in information assurance or a related field.
  • Active Top Secret clearance with SAP & SCI eligibility.
  • Must maintain DoD 8570 IAM Level I (Security+) certification as required by customers or contractual obligations.
  • Security+ certification required and experience with RMF.

Responsibilities

  • Conduct ongoing vulnerability assessments and security audits to identify cybersecurity risks in accordance with DoD, DOE, and IC standards.
  • Drive improvements to mitigate risks.
  • Implement cybersecurity requirements for LAN/WAN, routers, firewalls, and related network devices, including Cisco IOS.
  • Build and implement workstations and servers running Windows 11, Windows Server, and Red Hat Linux.
  • Build and implement virtualization infrastructure using VMware or HyperV.
  • Monitor multiple information systems for indicators of compromise to identify insider threats and potential espionage.
  • Perform technical analysis of vulnerabilities and lead in vulnerability corrective action plans.
  • Regularly review security documents and inform management of vulnerabilities and mitigation.
  • Leverage Splunk Enterprise, Nessus, STIGs, and ACAS to enhance security posture.
  • Observe laws and regulations and perform duties safely and ethically.

Skills

Splunk Enterprise
Nessus Vulnerability Assessment
SCAP
STIG Viewer
Network Administration
Windows Backup
Active Directory
RMF Knowledge

Education

Bachelor's degree in a related discipline

Tools

ACAS
DISA STIGs
SCAP Tool

Job description

General Atomics (GA) and its affiliated companies are one of the world’s leading resources for high‑technology systems development ranging from the nuclear fuel cycle to remotely piloted aircraft, airborne sensors, and advanced electric, electronic, wireless, and laser technologies.

We have an exciting opportunity for an Information Systems Security Officer (ISSO) to join our Classified Systems team in Herndon, VA.

Responsibilities
  • Conduct ongoing vulnerability assessments and security audits to identify cybersecurity risks in accordance with Department of Defense (DoD), Department of Energy (DOE), and Intelligence Community (IC) standards, regulations, and cybersecurity policies/procedures.
  • Drive improvements necessary to mitigate those risks.
  • Implement cybersecurity requirements for local area networks (LANs), wide area networks (WANs), routers, firewalls, and related network devices, typically requiring experience with Cisco IOS.
  • Build and implement workstations and servers running multiple operating systems such as Windows 11, Windows Server, and RedHat Linux.
  • Build and implement virtualization infrastructure using tools such as VMware or HyperV.
  • Monitor multiple company information systems for indicators of compromise (IoC) to identify insider threats and potential espionage activity.
  • Perform technical analysis of vulnerabilities and lead in the development of vulnerability corrective action plans.
  • Conduct a regular review of network, application, and operating system security documents and procedures.
  • Review results of vulnerability assessments and code reviews and inform management of vulnerabilities, risk, and mitigation.
  • Proven ability to leverage technical expertise in the following:
    • Splunk Enterprise – installation and management.
    • Nessus Vulnerability Assessment – installation and management.
    • Security Technical Implementation Guide (STIGs) – identify, analyze, and remediate security threats.
    • Network and System Administration.
    • Windows Backup procedures and management.
    • Implementing secure configurations based on NIST (800‑53, 800‑171) with Continuous Monitoring (CONMON) principles.
    • Knowledge of Risk Management Framework (RMF) is a plus.
  • Observe all laws, regulations, and other applicable obligations wherever and whenever business is conducted on behalf of the Company. Expected to work in a safe manner in accordance with established operating procedures and practices.
  • Perform additional duties as assigned.
Technical Skills
  • Splunk Enterprise
  • Nessus Vulnerability Assessment
  • Security Content Automation Protocol (SCAP)
  • Security Technical Implementation Guide (STIG) and STIG Viewer
  • Network and System Administration
  • Active Directory Management
  • Windows Backup
Experiences
  • Implemented Splunk Enterprise for real‑time security monitoring and incident response, leading to a quantifiable improvement to threat detection and response.
  • Utilized Nessus Vulnerability Assessment to identify and prioritize security vulnerabilities within the network infrastructure, resulting in overall security posture.
  • Leveraged Assured Compliance Assessment Solution (ACAS) to automate security data ingestion and processing, streamlining operations and improving efficiency.
  • Ensured system security by adhering to STIGs and utilizing STIG viewer to maintain configuration compliance with industry best practices.
  • Supported network and system administration tasks, including user management, access control, and system maintenance.
  • Performed regular Windows Backups to ensure data availability in the event of a system failure or security incident.
  • Demonstrated understanding of NIST security frameworks (800‑53, 800‑171, other special publication guides).
  • Applied CONMON principles for continuous monitoring and risk mitigation.

We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.

Qualifications
  • Typically requires a bachelor’s degree in a related discipline and six or more years of progressive professional experience in information assurance or a related field. Equivalent professional experience may be substituted in lieu of education.
  • Must possess an active Top Secret (with SAP & SCI eligibility).
  • Must maintain DoD 8570 IAM Level I (e.g. Security +) professional certification as required by customers or contractual obligations.
  • Security + certification required.
  • Experience with DoD policy such as Risk Management Framework and Joint SAP Implementation Guide.
  • Operational experience with installing, troubleshooting, and auditing Windows desktop & server operating systems.
  • Experience with DISA STIGs, SCAP tool, ACAS.
  • Experience installing and troubleshooting common x86‑based computer hardware.
  • Must demonstrate a general understanding of information assurance principles, theories, concepts and techniques. Must have experience organizing, planning, scheduling, conducting, and coordinating work assignments to meet project milestones or established completion dates.
  • Must possess the ability to understand new concepts quickly and apply them in an evolving environment while contributing to the development of new processes.
  • Must be customer focused and possess:
    • The ability to identify issues, analyze data and develop solutions to a variety of problems.
    • Good analytical, verbal, and written communication skills to accurately document, report, and present findings.
    • Good interpersonal skills enabling an effective interface with other professionals; and good computer skills.
  • Ability to work independently or in a team environment is essential as is the ability to work extended hours as required.
Soft Skills
  • Problem‑Solving
  • Analytical thinking
  • Attention to detail.
  • Adaptability
  • Communication
  • Teamwork

Job Type: Full‑Time Salary

Salary range: 89,180 - 155,825

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer ISSO
Information Systems Security Officer ISSO

General Atomics • Acton (MA)

On-site
USD 89,000 - 156,000
Information System Security Officer - ISSO
Information System Security Officer - ISSO

General Atomics Aeronautical Systems • Poway (CA)

On-site
USD 89,000 - 156,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

The Amatriot Group • Reston (VA)

On-site
USD 170,000 - 201,000
Cybersecurity Engineer - ISSO
Cybersecurity Engineer - ISSO

SAIC • Vienna (VA)

On-site
USD 160,000 - 200,000
Information Systems Security Officer
Information Systems Security Officer

SOSi • United States

On-site
USD 88,000 - 107,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Unity Compass • Alexandria (VA)

Hybrid
USD 90,000 - 175,000
ISSO & Systems Security Engineer: Vulnerability & Risk Lead
ISSO & Systems Security Engineer: Vulnerability & Risk Lead

UIC Arctic Response Services, LLC • Dahlgren (VA)

On-site
USD 130,000 - 150,000
Senior Information Assurance Analyst
Senior Information Assurance Analyst

Qmulos • Arlington (VA)

On-site
USD 90,000 - 120,000
Senior Information System Security Officer
Senior Information System Security Officer

Peraton • Corridor North (MD)

On-site
USD 135,000 - 216,000
ISSO/Systems Security Engineer
ISSO/Systems Security Engineer

UIC Arctic Response Services, LLC • Dahlgren (VA)

On-site
USD 130,000 - 150,000