Information System Security Officer

Mantech International Corporation
United States
22 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) PHP (Programming Language) Data Analysis Software as a Service Cloud Engineering Databases Data Integrity Data Normalization Data Security Federal Information Processing Standards (FIPS) Infrastructure as a Service (IaaS) Identity and Access Management
+13 more
Information Security Management JSON Python (Programming Language) Network Architecture Office Suite Platform as a Service (PAAS) Web Platforms Data Processing Restful APIs Api Management Qualys Plan of Action and Milestones Vulnerability Analysis

Job description

  • Categorizes systems (FIPS 199) in coordination with system owners, accounting for high-volume PII/NPI data aggregation risks inherent to organizational data.
  • Build the control package: apply NIST SP 800-53 controls, develop the SSP, draft implementation statements, and collect evidence validating secure data ingestion and processing.
  • Guide system owners on writing and resolving implementation statements.
  • Drive controls to secure status and see them through testing, with emphasis on data integrity, encryption-in-transit (TLS), and Identity & Access Management (IAM).
  • Partner closely with the Security Assessment Provider/SCA to ensure quality of artifacts and evidence to enable the assessment.
  • Advise system owners on control prioritization, ensuring alignment with both NIST frameworks and financial regulatory data protection standards (e.g., FFIEC expectations).
  • Support RMF & A&A: Cyber Risk Framework (CRF) input, Change Request Reviews, POA&M tracking, SA&A Project List, and SOPs/A&A artifacts on a best-effort basis.

Requirements

  • Hands-on experience with NIST RMF (800-30, 800-37, 800-53, and 800-53A) - practical implementation, not just familiarity.
  • Demonstrated experience building control packages and drafting implementation statements.
  • Experience in creating or supporting Security Assessment Plans and Security Assessment Reports.
  • Experience with Q-Compliance (or the ability to ramp quickly).
  • Experience interpreting data from vulnerability scanning tools (e.g., Tenable, Qualys) to identify risks in databases and file-processing pipelines.
  • Understanding network architectures, including SaaS, IaaS, or PaaS environments; experience securing modern, cloud-native web platforms preferred.
  • Technical background sufficient to collaborate with system owners on design documentation.

  • SME-level knowledge of NIST SP 800-137 (ISCM).
  • 1+ years of technical experience with Python, Java, or PHP - sufficient to read, interpret, and understand code to independently verify control implementation and evaluate technical alternate solutions for complex NIST requirements.
  • 1+ year of experience with a GRC tool (such as CSAM).
  • Experience with Q-Compliance and/or Q-Audit.
  • Experience with API testing (REST APIs), JSON payload security, and/or scripting and automation.
  • Relevant industry certifications (e.g., CISA, CAP, CISSP, Security+).

  • Must be a U.S. Citizen with the ability to obtain and maintain a Public Trust clearance prior to starting this position.

  • Must be able to remain in a stationary position 50% and constantly operate a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

5:51 min

Transitioning to continuous security operations and automated system hardening

Thomas Fuchs +3 · LIVE

Videos

See all

Related articles

See all