Senior Information Systems Security Officer

Saic

Washington (District of Columbia)

Hybrid

USD 120,000 - 160,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SAIC seeks a Senior ISSO to support a federal agency in the National Capital Region. This hybrid role requires at least three on-site days per week in Washington, DC, and focuses on security authorization, continuous monitoring, and risk management across on-prem and cloud environments.

The successful candidate will validate security controls, prepare artifacts (SSPs, SARs, POA&Ms, SIAs), coordinate assessments, and engage with engineers and system owners to ensure compliant, well-evidenced

Qualifications

  • Bachelor’s degree with 5+ years in cybersecurity or related fields.
  • Public trust clearance or ability to obtain one.
  • Hands-on technical background in systems admin, cloud, network, or security engineering.
  • Experience supporting federal authorization activities (SSPs, POA&Ms, SIAs, RMF, etc.).
  • Knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with AWS, Azure, M365, Entra ID, AD, VMware, Cisco, Oracle.
  • Strong written/spoken English; ability to produce polished documentation.
  • Proficiency with MS Word, Excel, PowerPoint, and SharePoint.

Responsibilities

  • Support the security authorization lifecycle and continuous monitoring.
  • Develop and maintain SSPs, SARs, POA&Ms, SIAs, and related docs per NIST RMF/FISMA.
  • Coordinate for Security Control Assessments and ensure defensible evidence.
  • Conduct SIAs for changes to hardware, software, cloud, connectivity, or architecture.
  • Review architecture and evidence to validate controls and resolve discrepancies.
  • Support change management, POA&Ms, risk acceptance, audits, and remediation.
  • Coordinate with owners, engineers, and governance to support compliance reporting.
  • Develop dashboards and risk briefings; assist Lead ISSO in execution.

Skills

Analytical
Technical writing
Communication
MS Word
Excel
PowerPoint
SharePoint
CISSP
CISM
CCSP
Security+
CGRC
AWS
Azure
Microsoft 365
Entra ID
Active Directory
VMware
Cisco
Oracle
Archer
eMASS
Xacta
JCAM/CSAM

Education

Bachelor’s degree
Master’s degree

Tools

AWS
Azure
Microsoft 365
Entra ID
Active Directory
VMware
Cisco
Oracle
Archer
eMASS
Xacta
JCAM/CSAM

Job description

Description

SAIC is seeking a technical Senior Information System Security Officer (ISSO) to support a critical U.S. government agency in the National Capital Region. This role reports to the Security Program Management Office (SPMO) Manager and works directly with team members and Federal ISSOs to support authorization, compliance, continuous monitoring, and risk management activities across assigned systems.

This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the secure authorization and ongoing compliance of systems across on-premises and cloud environments. This is not a hands‑on engineering position. Instead, the Senior ISSO leverages prior experience as a Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, Security Engineer, or similar technical role to independently validate security implementations, assess technical risk, and ensure authorization decisions are supported by accurate technical evidence. The successful candidate must be comfortable engaging engineers, architects, and system owners to validate security controls, identify inconsistencies, and challenge unsupported technical assumptions.

This hybrid role requires a minimum of three on-site days per week in Washington, DC.

Responsibilities:

  • Support the security authorization lifecycle and ongoing continuous monitoring activities for assigned systems.
  • Develop, review, and maintain security documentation and authorization artifacts, including SSPs, SARs, POA&Ms, SIAs, and related documentation, in accordance with NIST SP 800-53, RMF, FISMA, and agency policies.
  • Coordinate and prepare systems for Security Control Assessments (SCAs), ensuring documentation and evidence are complete, accurate, and technically defensible.
  • Conduct Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, connectivity, or system architecture.
  • Review system architecture, technical documentation, and supporting evidence to validate security controls, independently assess technical implementations, identify inconsistencies, and collaborate with engineers, architects, administrators, and system owners to resolve discrepancies.
  • Support change management, continuous monitoring, POA&M management, risk acceptance, audit responses, and remediation activities to maintain ongoing authorization and compliance.
  • Coordinate with system owners, engineers, architects, and governance stakeholders to support standards reviews, exception requests, policy implementation, compliance reporting, and risk management activities.
  • Develop dashboards, executive risk briefings, status reports, and other stakeholder communications while supporting the Lead ISSO in operational execution and coordination activities.

Qualifications

Requirements:

  • Bachelor’s degree and 5+ years of relevant experience, or a master’s degree and 3+ years of experience, in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card.
  • Prior hands-on experience in a technical role such as Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, or Security Engineer, with the ability to evaluate technical implementations, validate controls, assess evidence, and challenge unsupported assumptions.
  • Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments.
  • Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms.
  • Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring.
  • Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms.
  • Strong analytical, technical writing, organizational, and communication skills, including demonstrated professional proficiency in written and spoken English. Ability to independently produce polished, technically accurate documentation; communicate clearly and effectively with technical and non-technical stakeholders; work independently; and manage competing priorities in a fast-paced environment.
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.

Preferred Qualifications:

  • Security+, CGRC (formerly CAP), CISSP, CISM, CCSP, or similar cybersecurity certification.
  • Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs.
  • Knowledge of modern cybersecurity practices including OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK.
  • Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts.
  • Experience operating in fast-paced, high-visibility environments with competing priorities.

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Skysoft Inc. • Maryland

Hybrid
USD 120,000 - 170,000
Information Systems Security Officer
Information Systems Security Officer

Demand Drive Solutions LLC • Washington

On-site
USD 110,000 - 120,000
Senior Information System Security Officers (ISSO)
Senior Information System Security Officers (ISSO)

Global Solutions Consulting LLC. • Baltimore (MD)

Hybrid
USD 80,000 - 110,000
Competitive salary and benefits package
Flexible work arrangements
Professional development opportunities
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Information Systems Security Officer
Information Systems Security Officer

Peraton • Maryland

On-site
USD 100,000 - 130,000
Senior ISSO
Senior ISSO

Agile Defense, LLC • Washington

On-site
USD 120,000 - 180,000
Lead Information System Security Officer (ISSO)
Lead Information System Security Officer (ISSO)

Development InfoStructure • Washington

On-site
USD 137,000 - 147,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

The Amatriot Group • Washington

On-site
USD 150,000 - 210,000
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

Hybrid
USD 110,000 - 170,000