Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
As the Senior Information System Security Officer, you will provide strategic cybersecurity leadership, ensuring the security, compliance and operational integrity of mission-critical DoD systems., * Lead the development, implementation, and enforcement of cybersecurity policies, standards, and methodologies.
- Direct vulnerability management activities using ACAS, DISA STIGs, and SCAP Compliance Checker.
- Oversee secure configuration of operating systems and network devices in accordance with DISA STIG requirements.
- Manage continuous monitoring efforts, conduct security audits, and drive risk mitigation strategies.
- Provide subject matter expertise on NIAP/Common Criteria certifications and DISA Approved Products List (APL) compliance.
- Prepare and review authorization documentation, certification letters, and MOAs for system interconnections.
- Advise program leadership, system owners, and engineers on RMF compliance and cybersecurity best practices.
This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.
Requirements
- Candidates must meet DoD 8140-M Advanced level qualification requirements: Masters degree in Information Technology, Cybersecurity, Computer Science, or related area of study, required. If an advanced degree is not held, qualified candidates must have a CISM, CISSP, FITSP-M, or other 8140-M Advanced-level certification. Please upload copies of any relevant IT certifications you hold.
- 10 years of engineering experience, including at least 5 years in Information Assurance/Cybersecurity (IA/CS).
- Demonstrated experience implementing the Risk Management Framework (RMF) in accordance with DoDI 8510.01.
- Extensive experience applying security controls outlined in CNSSI 1253, NIST SP 800-53, and JSIG.
- Able to conduct vulnerability assessments using ACAS, DISA STIGs, and SCAP Compliance Checker with automated benchmarks.
- Proven experience implementing DISA STIG configurations across operating systems and network devices.
- In-depth knowledge of continuous monitoring, security audits, risk assessments, and mitigation planning for DoD systems.
- Experience evaluating NIAP/Common Criteria technologies and the DISA Approved Products List (APL).
- Background preparing certification letters, MOAs, and authorization documentation for system interconnections.
- Experience developing IA-related acquisition documentation.
- Familiarity with Intelligence Community Directive (ICD) 705, DoDD 5205.07, and DOD 5205.07-M Volumes 1-4.
- Comfortable mentoring and guiding more junior teammates.
Equally Important:
- Ability to build positive, collaborative relationships across teams and with external partners.
- Effective communicator with strong verbal and written skills.
- Proactive, self-directed work style with the ability to operate independently.
- Analytical thinker with proven problem-solving capabilities.
- Highly organized, with the ability to balance competing priorities in a fast-paced environment.
Benefits & conditions
- The anticipated annual salary range for this position is $135,000 - $165,000, commensurate with an individual’s experience, qualifications, and skill set. ASEC is committed to providing fair and equitable compensation. The low end of this salary range is accounting for a candidate that meets or exceeds all of the listed requirements., * 100% employee-owned company. Learn more about our Employee Stock Ownership Plan (ESOP) here !
- Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
- 401(k) with company match
- Tuition assistance for undergraduate and graduate education
- Veteran-friendly employer
- Thriving employee culture
About the company
ASEC is committed to providing access and reasonable accommodation in its services, activities, programs, and employment opportunities in accordance with the Americans with Disabilities Act and other applicable laws., ASEC offers meaningful, mission-driven work within a culture that supports your professional and personal growth. We partner with our government customers to deliver innovative solutions across engineering, information technology, training, and logistics. Above all, we are committed to doing what’s right for the Warfighter-plain and simple. Explore what makes ASEC different by visiting our website.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Is Software Engineering Over-Saturated?
Dev Digest 134 - Where pixels sing?