Information Systems Security Officer (ISSO)

Peraton

Chantilly (VA)

On-site

USD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Peraton in Chantilly, VA is seeking a Mid-Level Information Systems Security Officer to support a DoD customer on RMF/JSIG programs across SAP environments.

You will develop SSPs, assess control implementations, coordinate A&A activities, and guide system owners through authorization processes. This role requires TS/SCI eligibility and strong RMF/JSIG experience, with collaboration across engineers and assessors.

Qualifications

  • Active Top Secret with eligibility for SCI clearance required.
  • Bachelor's degree with 5+ years of relevant experience; master's degree with 3+ years; associate with 9+ years.
  • Knowledge of A&A activities within a DoD SAP environment and RMF with JSIG.
  • Experience with DoDI 8510.01, NIST SP 800-53, CNSSI 1253, ICD 503, DISA guidance.
  • Experience developing RMF packages (SSPs, SCTMs, POA&Ms) and supporting control evidence.
  • Experience reviewing DISA STIG findings, vulnerability scans, and remediation evidence.

Responsibilities

  • Support the RMF lifecycle phases for DoD SAP environments.
  • Interpret and apply JSIG policy to security requirements and authorization packages.
  • Develop, review, and maintain SSPs, SCTMs, POA&Ms, risk assessments, and monitoring plans.
  • Coordinate security control assessments and authorization activities with stakeholders.
  • Identify cybersecurity risks and track remediation through closure.
  • Advise system administrators on security control implementation and STIG hardening.
  • Communicate system security posture and mitigation actions to leadership.

Skills

RMF knowledge
JSIG experience
DoD policy understanding

Education

Bachelor's degree
Master's degree
Associate degree

Job description

Responsibilities

Peraton is seeking a Mid-Level Information Systems Security Officer (ISSO) in Chantilly, VA to support our Department of Defense customer as part of a highly talented, highly motivated, and high-performing team. As part of the cybersecurity team, you will support Assessment and Authorization (A&A) activities for information systems operating within a DoD Special Access Program (SAP) environment. The position requires extensive knowledge of the Joint Special Access Program Implementation Guide (JSIG) and demonstrated experience implementing the Risk Management Framework (RMF) throughout the system lifecycle.

What you'll do:
  • Support the prepare, categorize, select, implement, assess, authorize, and monitor phases of the RMF lifecycle for information systems operating within a DoD SAP environment.
  • Interpret and apply JSIG policy and guidance to system security requirements, security control implementation, assessment activities, authorization packages, and continuous monitoring.
  • Develop, review, and maintain system security plans (SSPs), security control traceability matrices (SCTMs), plans of action and milestones (POA&Ms), risk assessments, continuous monitoring strategies, contingency plans, incident response plans, and supporting authorization artifacts.
  • Develop and maintain security control implementation statements that accurately describe how technical, operational, and management controls are implemented within the system and its operating environment.
  • Collect, review, and validate technical and nontechnical evidence demonstrating security control implementation and effectiveness.
  • Coordinate security control assessments, authorization activities, periodic reviews, annual assessments, and continuous monitoring activities with system owners, engineers, administrators, assessors, and Authorizing Official (AO) representatives.
  • Support authorization package submissions, assessment preparation, evidence reviews, discrepancy resolution, and responses to Security Control Assessor (SCA) and AO questions.
  • Identify cybersecurity risks, document control deficiencies, recommend corrective actions, and track remediation activities through closure.
  • Develop and maintain POA&Ms containing accurate weakness descriptions, risk determinations, remediation strategies, milestones, scheduled completion dates, and closure evidence.
  • Review vulnerability scan results, DISA Security Technical Implementation Guide (STIG) findings, configuration compliance results, audit records, and other cybersecurity data to determine risk and authorization impact.
  • Review system architectures, network diagrams, data flows, authorization boundaries, hardware and software inventories, ports, protocols, services, external connections, and system interconnections for accuracy and compliance.
  • Evaluate proposed hardware, software, architecture, configuration, service, and interconnection changes to determine cybersecurity, A&A, security control, and authorization boundary impacts.
  • Participate in configuration control boards, engineering reviews, security working groups, technical exchange meetings, and cybersecurity risk discussions.
  • Advise system administrators and engineers on security control implementation, STIG hardening, vulnerability remediation, and authorization requirements.
  • Communicate the system security posture, unresolved weaknesses, operational risks, and recommended mitigation actions to the ISSM and appropriate program leadership.
Qualifications
  • Required Qualifications: This position requires the candidate to possess a minimum of an active Top Secret with eligibility for SCI clearance; must be able to maintain TS/SCI and SAP access.
  • Bachelor's degree and 5+ years of relevant experience; master's degree and 3+ years of relevant experience; associate degree and 7+ years of relevant experience; or high school diploma and 9+ years of relevant experience. Additional 4 years of relevant experience may be considered in lieu of a degree.
  • Knowledge of A&A activities within a DoD SAP environment and demonstrated experience implementing RMF requirements using the JSIG.
  • Working experience with DoDI 8510.01, NIST Special Publication 800-53, CNSSI 1253, ICD 503, applicable DISA guidance, and related DoD cybersecurity policies.
  • Demonstrated experience developing, reviewing, and maintaining RMF authorization packages, including SSPs, SCTMs, POA&Ms, risk assessments, continuous monitoring documentation, and supporting control evidence.
  • Experience documenting security control implementations, evaluating the sufficiency of implementation evidence, and supporting control validation and assessment activities.
  • Experience supporting security control assessments, authorization decisions, continuous monitoring, annual reviews, and system reauthorization activities.
  • Experience reviewing DISA STIG findings, vulnerability scan results, configuration compliance results, and remediation evidence to determine cybersecuri
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Peraton • Chantilly (VA)

On-site
USD 120,000 - 150,000
Subsidized benefits for employees and
25 days PTO per year
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JAAW™ Group • Hill Air Force Base (UT)

On-site
USD 90,000 - 130,000
ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering, Inc • Annapolis (MD)

Hybrid
USD 120,000 - 165,000
11 paid holidays
3 weeks PTO
Group medical plan
+2
ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering, Inc. • Maryland

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Group medical plan
+4
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 120,000 - 135,000
Medical insurance
Dental insurance
Vision insurance
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JFL Consulting LLC • Omaha (NE)

On-site
USD 120,000 - 140,000
Full medical coverage (incl. depend.)
FSAs
Life and disability insurance
+3
DoD ISSO: RMF/A&A Specialist for SAP
DoD ISSO: RMF/A&A Specialist for SAP

Peraton • Chantilly (VA)

On-site
USD 120,000 - 150,000
Subsidized benefits for employees and
25 days PTO per year
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

8 Consulting LLC • Washington

Hybrid
USD 110,000 - 170,000
Information Systems Security Officer (ISSO) - Mid
Information Systems Security Officer (ISSO) - Mid

ECS • Winchester (VA)

On-site
USD 90,000 - 135,000