Senior Information Systems Security Officer (ISSO)
About the role
This position is part of our Cyber and Intelligence division, which plays a critical role in supporting Enterprise-Level Security and Modernization efforts across IT infrastructure, cybersecurity, physical facilities, and personnel operations. The selected candidate will contribute to a high-impact government program focused on enhancing and securing mission-critical systems and environments.
Responsibilities
Designs and implements information assurance and security engineering systems with requirements of business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter-espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management). Assesses and mitigates system security threats and risks throughout the program life cycle. Validates system security requirements definition and analysis. Establishes system security designs. Implements security designs in hardware, software, data, and procedures. Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities. Supports secure systems operations and maintenance.
Requirements
- 6+ years of information security experience (ISSO, cyber analyst, cyber auditor, etc) with at least 2 years as an ISSO
- Demonstrated mastery of the Risk Management Framework (RMF) and experience leading information systems through the RMF lifecycle
- Demonstrated experience authoring, reviewing, and maintaining body-of-evidence (BoE) documentation (e.g., SSP, SAR, RAR, CP, and POA&Ms)
- Must meet DoD 8140/CSWF for 451-Intermediate or be willing to obtain the appropriate credential within 6 months
- Active TS/SCI Government Security Clearance Required To Start
Qualifications
- Engineer Info Assurance 2: High School Diploma or equivalent and 6 years relevant experience
- Engineer Info Assurance 3: 6 years relevant experience with Bachelors in related field; or High School Diploma or equivalent and 9 years relevant experience
- Engineer Info Assurance 4: 9 years relevant experience with Bachelors in related field; 7 years relevant experience with Masters in related field; or High School Diploma or equivalent and 13 years relevant experience
Skills
- Preferred Experience with GRC tools (xActa, eMASS, Archer, ServiceNow GRC)
- Experience with discovery tools (e.g., ACAS) and experience managing vulnerabilities from discovery, through risk-based prioritization, remediation tracking, and formal risk assessments
- Incident response/responder experience
Pay
The listed salary range for this role is $102,831.00 - $154,000.00. The salary range for specific levels are: Engineer Info Assurance 2: $92,185 - $112,693, Engineer Info Assurance 3: $106,620 - $128,620, Engineer Info Assurance 4: $128,887 - $158,124