Information Systems Security Officer Senior

Saic

Ashburn (VA)

Hybrid

USD 120,000 - 160,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

SAIC is seeking a senior-level Information System Security Officer (ISSO) and/or Alternate ISSO for federal IT systems. The role applies RMF, NIST controls, and continuous monitoring to maximize security and FISMA compliance.

The position is hybrid-remote with one mandatory on-site day per week in Ashburn, VA, and involves audits, risk assessments, and documentation updates. Candidates should have 8+ years of IT security, CISSP/CCSP, and cloud/SIEM experience.

Qualifications

  • B.S. in Information Assurance / Cybersecurity or equivalent.
  • 8+ years IT security experience with focus on compliance.
  • 8+ years as primary ISSO or security lead on IT systems.
  • CISSP or CCSP certification required.

Responsibilities

  • Continuous monitoring and self-inspections for security compliance.
  • Review vulnerability scans and drive remediation.
  • Report security status to management and stakeholders.
  • Support audits and prepare security documentation.
  • Manage DoD STIGs compliant configurations.
  • Execute SIEM log reviews and audit readiness.

Skills

Senior ISSO/AISSO experience
8+ years IT security
CISSP or CCSP
POA&M management
Vulnerability management
Auditing & NIST RMF
Linux and AWS security
DoD STIGs knowledge
Communication with auditors

Education

B.S. in Information Assurance / Cybersecurity

Tools

Splunk
Kibana
AWS
SIEM

Job description

Description

SAIC is seeking a senior-level Information System Security Officer (ISSO) and/or Alternate Information System Security Officer (AISSO) for one or more major federal IT information systems as a member of the customer directorate’s Security Team.Overall, the candidate will be responsible for utilizing the NIST Risk Management Framework (RMF), NIST Security and Privacy Controls for Information Systems and Organizations, and related Continuous Monitoring activities to maximize the security of their assigned system(s) and ensure compliance with Federal Information Security Management Act (FISMA) requirements and DHS/CBP policies and processes.

This position is hybrid-remote and requires 1 day per-week on-site per week in Ashburn, VA.

Job Responsibilities
  • Conduct continuous monitoring and self-inspections of computer systems to ensure security compliance with the a forementioned guidance and DHS/CBP policy directives, and proactively report progress to management, make recommendations for security posture improvements, and ensure systems are ready for audits.
  • Review and interpret security vulnerability scans, communicate their contents to management and technical stakeholders, and push them to remediation.
  • Proactively report security status and concerns to management and make recommendations as appropriate.
  • Participate in and support directorate responses for ongoing information system audits.
  • Develop and update standard government security documentation such as System Security Plans, Contingency Plans, Interconnection Security Agreements, Risk Acceptances/Waivers, Privacy Threshold Analyses, Privacy Impact Assessments, and other ad-hoc documentation as needed.
  • Review and approve/deny relevant system Change Requests as needed.
  • Ensure configuration management is appropriate for all Information Systems (IS) software and hardware, in accordance with DoD STIGs (Security Technical Implementation Guides) and industry best practices.
  • Execute system audit log reviews in accordance with established policy requirements using Security Information and Event Management (SIEM) tools such as Splunk, Kibana, etc.
  • Assist creation of new policies/procedures as needed for directorate systems.
  • Support ad-hoc data call and reporting requirements initiated by DHS CIO, CISA and other headquarters offices.
Qualifications
Job Responsibilities
  • Conduct continuous monitoring and self-inspections of computer systems to ensure security compliance with the a forementioned guidance and DHS/CBP policy directives, and proactively report progress to management, make recommendations for security posture improvements, and ensure systems are ready for audits.
  • Review and interpret security vulnerability scans, communicate their contents to management and technical stakeholders, and push them to remediation.
  • Proactively report security status and concerns to management and make recommendations as appropriate.
  • Participate in and support directorate responses for ongoing information system audits.
  • Develop and update standard government security documentation such as System Security Plans, Contingency Plans, Interconnection Security Agreements, Risk Acceptances/Waivers, Privacy Threshold Analyses, Privacy Impact Assessments, and other ad-hoc documentation as needed.
  • Review and approve/deny relevant system Change Requests as needed.
  • Ensure configuration management is appropriate for all Information Systems (IS) software and hardware, in accordance with DoD STIGs (Security Technical Implementation Guides) and industry best practices.
  • Execute system audit log reviews in accordance with established policy requirements using Security Information and Event Management (SIEM) tools such as Splunk, Kibana, etc.
  • Assist creation of new policies/procedures as needed for directorate systems.
  • Support ad-hoc data call and reporting requirements initiated by DHS CIO, CISA and other headquarters offices.
Required Skills and Experience
  • B.S. in the Information Assurance / Cybersecurity field.
  • 8+ years of overall IT security experience.
  • 6+ years of experience as a primary ISSO or security compliance lead for an IT system.
  • Possesses one of the following professional security certifications: CISSP or CCSP certification.
  • Creating, tracking, and driving to completion Plans of Action and Milestones (POA&Ms) for resolving security control deficiencies.
  • Providing system-level security auditing support, including interacting directly with auditors and providing artifacts as requested.
  • Executing the completion of a new or renewed system Certification and Accreditation (C&A) package from start to finish.
  • Effectively communicating security vulnerabilities with technical POCs and management.
  • Possesses significant security experience with systems primarily supported by Linux OS (on premises) or Amazon Web Services (AWS).
  • Possesses significant experience and knowledge of how to interpret details of vulnerability scans and effectively communicate results.
  • Understands the differences between types of vulnerability scans.
  • Demonstrates a knowledge of cloud systems/types and related security issues.
  • Possesses significant experience writing or updating system Security Plans.
  • Demonstrates the ability to communicate effectively verbally and in writing.
Desired Skills and Experience
  • Utilizes Splunk of other SIEM tools.
  • Creating, tracking, and updating security policies and/or procedures.
  • Creating, tracking, and updating Interconnection Security Agreements (ISAs), risk acceptance memorandums, and policy waiver requests.
  • Demonstrates the ability to lead annual Contingency Plan Tests in either tabletop form or as actual fail-over tests.
  • Supporting the federal government in an IT environment.
  • Security experience with cloud systems hosted by Amazon Web Services (AWS).
  • Possesses the ability to lead an IT security team.
  • Experience with DoD STIG system configuration standards.
  • Experience with OIG, GAO, Financial and FISMA audits.
Customer Requirements
  • Clearance – Ability to obtain and hold a public trust position and favorable suitability based on a CBP Background Investigation
  • Citizenship – Must be a US Citizen
  • Location – Hybrid with on-site (Ashburn, VA) 1 day per week (Mondays) with some additional on-site visits for mission needs. All candidates must be within the GWA/commutable area.

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Federal Staffing Solutions Inc. • Ashburn (VA)

On-site
USD 150,000 - 180,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Akima • Ashburn (VA)

On-site
USD 90,000 - 120,000
Information Systems Security Officer II
Information Systems Security Officer II

Saic • Washington

Hybrid
USD 80,000 - 120,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Saic • Washington

Hybrid
USD 120,000 - 160,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Steampunk, Inc. • McLean (VA)

On-site
USD 90,000 - 140,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

APTNEXUS • Virginia (MN)

On-site
USD 135,000 - 165,000
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -

RedTrace Technologies • Washington

On-site
USD 80,000 - 100,000
Competitive salary
401(k) plan
Annual performance bonus
+5
Information System Security Officer
Information System Security Officer

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 90,000 - 130,000
Information Systems Security Officer
Information Systems Security Officer

Future Technologies Inc. • King George (VA)

On-site
USD 105,000 - 140,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

ECS Corporate Services • Washington

On-site
USD 120,000 - 145,000