Information Systems Security Officer (ISSO)

Peraton

Chantilly (VA)

On-site

USD 120,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Subsidized benefits for employees and
25 days PTO per year

Job summary

Peraton is seeking a Mid-Level Information Systems Security Officer (ISSO) in Chantilly, VA to support a DoD SAP program. You will lead RMF activities, prepare and review SSPs, SCTMs, POA&Ms, and risk assessments, ensuring security controls align with JSIG and DISA requirements.

The role requires TS/SCI clearance, DoD policy knowledge, and collaboration with ISSMs, assessors, and program leadership to maintain authorization and monitor system risk across the lifecycle.

Qualifications

  • Active TS/SCI with the ability to maintain clearances.
  • Bachelor's degree plus 5+ years of relevant experience, or advanced degrees with fewer years.
  • Experience in RMF authorization packages (SSPs, SCTMs, POA&Ms, risk assessments).
  • Knowledge of DoD cybersecurity policies (JSIG, DISA STIGs).
  • Experience with RMF lifecycle activities: categorization, control selection, authorization, monitoring.

Responsibilities

  • Support RMF lifecycle phases for DoD SAP environments.
  • Interpret JSIG policy for security requirements and control implementations.
  • Develop and maintain SSPs, SCTMs, POA&Ms, risk assessments, and contingency plans.
  • Coordinate security control assessments and authorization activities with stakeholders.
  • Review vulnerability scans and DISA STIG findings to assess risk and authorization impact.
  • Advise on security control implementation, remediation, and authorization requirements.

Skills

Top Secret with SCI clearance
RMF/JSIG
Windows/Linux security
Security documentation
Technical writing
Cybersecurity policy

Education

Bachelor's degree
Master's degree
Associate degree
High school diploma

Tools

eMASS
Xacta
ACAS/Nessus
SCAP tools

Job description

Required Qualifications:
  • This position requires the candidate to possess a minimum of an active Top Secret with eligibility for SCI clearance; must be able to maintain TS/SCI and SAP access.
  • Bachelor's degree and 5+ years of relevant experience; master's degree and 3+ years of relevant experience; associate degree and 7+ years of relevant experience; or high school diploma and 9+ years of relevant experience. Additional 4 years of relevant experience may be considered in lieu of a degree.
  • Knowledge of A&A activities within a DoD SAP environment and demonstrated experience implementing RMF requirements using the JSIG.
  • Working experience with DoDI 8510.01, NIST Special Publication 800-53, CNSSI 1253, ICD 503, applicable DISA guidance, and related DoD cybersecurity policies.
  • Demonstrated experience developing, reviewing, and maintaining RMF authorization packages, including SSPs, SCTMs, POA&Ms, risk assessments, continuous monitoring documentation, and supporting control evidence.
  • Experience documenting security control implementations, evaluating the sufficiency of implementation evidence, and supporting control validation and assessment activities.
  • Experience supporting security control assessments, authorization decisions, continuous monitoring, annual reviews, and system reauthorization activities.
  • Experience reviewing DISA STIG findings, vulnerability scan results, configuration compliance results, and remediation evidence to determine cybersecurity risk and authorization impact.
  • Ability to evaluate technical and procedural findings, document residual risk, recommend mitigation or risk acceptance actions, and clearly communicate operational and authorization impacts.
  • Use of Windows and Linux operating systems, network security, identity and access management, audit logging, vulnerability management, encryption, and secure configuration practices.
  • Must meet DoD Manual 8140.03 for DoD Cyber Workforce Framework Work Role 722 - Information Systems Security Manager, Intermediate Proficiency Level, or Work Role 541 - Vulnerability Assessment Analyst, Intermediate Proficiency Level, as applicable to the duties of an ISSO.
  • Strong technical writing, documentation management, organizational, analytical, and verbal communication skills, with the ability to collaborate effectively with cybersecurity, program security, engineering, system administration, assessment, and program management personnel.
Desired Qualifications:
  • Current or previous approval to support a DoD SAP.
  • Experience working directly with ISSMs, Security Control Assessors, Authorizing Official representatives, Program Security Officers, Government SAP Security Officers, and system owners.
  • Experience preparing systems and authorization packages for formal SAP cybersecurity assessment activities.
  • Experience with eMASS, Xacta, or another approved governance, risk, compliance, or authorization management platform.
  • Experience with ACAS, Tenable Nessus, Tenable Security Center, SCAP tools, Splunk, HBSS/Trellix, or comparable cybersecurity tools.
  • Experience supporting private cloud, hybrid cloud, virtualized, containerized, or classified enterprise environments.
  • Experience evaluating system interconnections, external services, inherited controls, or cross-domain solutions.
  • Current certification such as Security+, SecurityX, CISSP, CGRC, or another certification recognized under the applicable DoD 8140 qualification matrix.
  • Ability to work independently with minimal supervision while recognizing matters requiring ISSM, assessor, or AO involvement.
Benefits:

Peraton offers enhanced benefits to employees working on this critical National Security program, which include heavily subsidized employee benefits coverage for you and your dependents, 25 days of PTO accrued annually up to a generous PTO cap and eligible to participatein an attractive bonus plan

#Metroplex

Peraton is seeking a Mid-Level Information Systems Security Officer (ISSO) in Chantilly, VA to support our Department of Defense customer as part of a highly talented, highly motivated, and high-performing team. As part of the cybersecurity team, you will support Assessment and Authorization (A&A) activities for information systems operating within a DoD Special Access Program (SAP) environment. The position requires extensive knowledge of the Joint Special Access Program Implementation Guide (JSIG) and demonstrated experience implementing the Risk Management Framework (RMF) throughout the system lifecycle.

What you'll do:
  • Support the prepare, categorize, select, implement, assess, authorize, and monitor phases of the RMF lifecycle for information systems operating within a DoD SAP environment.
  • Interpret and apply JSIG policy and guidance to system security requirements, security control implementation, assessment activities, authorization packages, and continuous monitoring.
  • Develop, review, and maintain system security plans (SSPs), security control traceability matrices (SCTMs), plans of action and milestones (POA&Ms), risk assessments, continuous monitoring strategies, contingency plans, incident response plans, and supporting authorization artifacts.
  • Develop and maintain security control implementation statements that accurately describe how technical, operational, and management controls are implemented within the system and its operating environment.
  • Collect, review, and validate technical and nontechnical evidence demonstrating security control implementation and effectiveness.
  • Coordinate security control assessments, authorization activities, periodic reviews, annual assessments, and continuous monitoring activities with system owners, engineers, administrators, assessors, and Authorizing Official (AO) representatives.
  • Support authorization package submissions, assessment preparation, evidence reviews, discrepancy resolution, and responses to Security Control Assessor (SCA) and AO questions.
  • Identify cybersecurity risks, document control deficiencies, recommend corrective actions, and track remediation activities through closure.
  • Develop and maintain POA&Ms containing accurate weakness descriptions, risk determinations, remediation strategies, milestones, scheduled completion dates, and closure evidence.
  • Review vulnerability scan results, DISA Security Technical Implementation Guide (STIG) findings, configuration compliance results, audit records, and other cybersecurity data to determine risk and authorization impact.
  • Review system architectures, network diagrams, data flows, authorization boundaries, hardware and software inventories, ports, protocols, services, external connections, and system interconnections for accuracy and compliance.
  • Evaluate proposed hardware, software, architecture, configuration, service, and interconnection changes to determine cybersecurity, A&A, security control, and authorization boundary impacts.
  • Participate in configuration control boards, engineering reviews, security working groups, technical exchange meetings, and cybersecurity risk discussions.
  • Advise system administrators and engineers on security control implementation, STIG hardening, vulnerability remediation, and authorization requirements.
  • Communicate the system security posture, unresolved weaknesses, operational risks, and recommended mitigation actions to the ISSM and appropriate program leadership.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Peraton • Chantilly (VA)

On-site
USD 110,000 - 170,000
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
ME00620-ISSO 1
ME00620-ISSO 1

Rippling, Inc. • Annapolis (MD)

Hybrid
USD 120,000 - 165,000
11 paid holidays
3 weeks PTO
Group medical plan
+2
ME00620-ISSO 1
ME00620-ISSO 1

Rippling, Inc. • Maryland

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Group medical plan
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JFL Consulting LLC • Omaha (NE)

On-site
USD 120,000 - 140,000
Full medical coverage (incl. depend.)
FSAs
Life and disability insurance
+3
DoD ISSO: RMF/A&A Specialist for SAP
DoD ISSO: RMF/A&A Specialist for SAP

Peraton • Chantilly (VA)

On-site
USD 120,000 - 150,000
Subsidized benefits for employees and
25 days PTO per year
Information Systems Security Officer (ISSO) III
Information Systems Security Officer (ISSO) III

The Amatriot Group • San Antonio (TX)

On-site
USD 118,500 - 122,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 120,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Peraton • Laurel (MD)

On-site
USD 120,000 - 190,000
Sign-on bonus (may apply)
Information System Security Officer II
Information System Security Officer II

Targeted Solutions, LLC • Albuquerque (NM)

On-site
USD 90,000 - 140,000
PTO and Flexible holidays
Tax-free healthcare reimbursement
401K with 4% match