Information System Security Officer
Mantech International Corporation
United States
22 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source
Tech stack
Java (Programming Language)
PHP (Programming Language)
Data Analysis
Software as a Service
Cloud Engineering
Databases
Data Integrity
Data Normalization
Data Security
Federal Information Processing Standards (FIPS)
Infrastructure as a Service (IaaS)
Identity and Access Management
+13 more
Information Security Management
JSON
Python (Programming Language)
Network Architecture
Office Suite
Platform as a Service (PAAS)
Web Platforms
Data Processing
Restful APIs
Api Management
Qualys
Plan of Action and Milestones
Vulnerability Analysis
Job description
- Categorizes systems (FIPS 199) in coordination with system owners, accounting for high-volume PII/NPI data aggregation risks inherent to organizational data.
- Build the control package: apply NIST SP 800-53 controls, develop the SSP, draft implementation statements, and collect evidence validating secure data ingestion and processing.
- Guide system owners on writing and resolving implementation statements.
- Drive controls to secure status and see them through testing, with emphasis on data integrity, encryption-in-transit (TLS), and Identity & Access Management (IAM).
- Partner closely with the Security Assessment Provider/SCA to ensure quality of artifacts and evidence to enable the assessment.
- Advise system owners on control prioritization, ensuring alignment with both NIST frameworks and financial regulatory data protection standards (e.g., FFIEC expectations).
- Support RMF & A&A: Cyber Risk Framework (CRF) input, Change Request Reviews, POA&M tracking, SA&A Project List, and SOPs/A&A artifacts on a best-effort basis.
Requirements
- Hands-on experience with NIST RMF (800-30, 800-37, 800-53, and 800-53A) - practical implementation, not just familiarity.
- Demonstrated experience building control packages and drafting implementation statements.
- Experience in creating or supporting Security Assessment Plans and Security Assessment Reports.
- Experience with Q-Compliance (or the ability to ramp quickly).
- Experience interpreting data from vulnerability scanning tools (e.g., Tenable, Qualys) to identify risks in databases and file-processing pipelines.
- Understanding network architectures, including SaaS, IaaS, or PaaS environments; experience securing modern, cloud-native web platforms preferred.
-
Technical background sufficient to collaborate with system owners on design documentation.
- SME-level knowledge of NIST SP 800-137 (ISCM).
- 1+ years of technical experience with Python, Java, or PHP - sufficient to read, interpret, and understand code to independently verify control implementation and evaluate technical alternate solutions for complex NIST requirements.
- 1+ year of experience with a GRC tool (such as CSAM).
- Experience with Q-Compliance and/or Q-Audit.
- Experience with API testing (REST APIs), JSON payload security, and/or scripting and automation.
-
Relevant industry certifications (e.g., CISA, CAP, CISSP, Security+).
-
Must be a U.S. Citizen with the ability to obtain and maintain a Public Trust clearance prior to starting this position.
- Must be able to remain in a stationary position 50% and constantly operate a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago