Senior Information System Security Officer

Core One
McLean, VA, United States
about 2 months ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Cyber Security Information Systems Computer Engineering Information Security Management SARS Software Products Information Technology Nessus Vulnerability Analysis

Job description

The Senior Information System Security Officer is responsible for implementing and maintaining cybersecurity controls, ensuring compliance with federal regulations, and guiding information systems through the Customer’s A&A process. This role requires a deep understanding of federal cybersecurity standards, proactive engagement with stakeholders, and the ability to operate independently in a fast-paced environment., * Lead and execute activities across all RMF phases (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor).

  • Develop, review, and maintain accreditation artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessments, and POA&Ms.
  • Monitor compliance with NIST 800-53, 800-171, ICD 503, FedRAMP, FISMA, and agency-specific policies. Prepare for and support audits, inspections, and assessments.
  • Conduct vulnerability scanning, compliance checks, risk assessments, and remediation tracking using tools such as Nessus or Tenable.sc.
  • Create and maintain security documentation, continuous monitoring strategies, incident response plans, and compliance reports. Provide briefings and status updates to leadership and Authorizing Officials.
  • Collaborate with system owners, engineers, and developers to ensure security is integrated into design, development, and operations.
  • Support investigation, response, and remediation of security incidents.
  • Manage account recertifications, access reviews, and deliver security awareness training at the system level.
  • Serve as the primary cybersecurity point of contact for assigned systems, ensuring clear communication with internal and external stakeholders.

Requirements

  • Bachelor’s Degree, or more advanced degree, in Information Technology, Computer Science, Cybersecurity, Computer Engineering, or Information Systems or related field
  • 5+ years of cumulative experience spanning IT systems administration, cybersecurity compliance, IT system troubleshooting, and incident
  • 6+ years of experience in a role such as Information Systems Security Engineer (ISSE), accrediting Sponsor programs
  • Experience with completing new system(s) authorization and accreditation through the Sponsor’s Authorization and Accreditation (A&A) processes, procedures, security requirements, and systems ( e.g. Greenlight)
  • Experience using the Sponsor’s A&A process to accredit systems built on C2E or C2S Amazon Web Services
  • Experience in security policy, counterintelligence, and security controls
  • TS/SCI w/ Poly Clearance, * Certified in AWS or equivalent cloud technology
  • Security+, Certified Information System Security
  • Professional (CISSP), Certified Information Security
  • Manager (CISM), or equivalent

About the company

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation’s most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all