Information Systems Security Officer ISSE
NVS Limited Company
Lorton, VA, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$160,000.0
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Cloud Computing
Cyber Security
Computer Networks
Wireless Access Point
Virtual Reality
Firewalls (Computer Science)
Information Technology
Data Pipelines
Job description
- Mission Enablement Risk Engineering: Apply a comprehensive risk tradecraft equation-balancing Threat, Vulnerability, Policy, Mitigation, and Residual Risk. Confidently recommend alternative paths to “yes” for senior leadership, including structured Risk Acceptance Memorandums (RAM), Exceptions to Policy (ETP), or transferring risk entirely via reasonable accommodation (e.g., telework routing).
- Architectural & Enterprise CDS Gatekeeping: Serve as the principal technical reviewer for DTRA organizations onboarding onto pre-accredited Enterprise CDS (ECDS) and Raise the Bar (RTB) compliant Cloud CDS providers (e.g., AWS/Azure CDS). Evaluate customer design artifacts to ensure data pipelines “hit the mark” before board submission.
- Dynamic Information Technology Evaluation: Act as the primary advisor for evaluating non-standard, emerging technologies (e.g., virtual reality training platforms, mobile medical devices, standalone scanning configurations) against rigid DoD guidelines. Systematically dissect hardware/software interfaces to isolate threat vectors and design creative compensating controls.
- Board Representation & Intermediary Advocacy: Act as the formal technical advocate and bridge between DTRA development teams, external cloud providers (AWS/DISA), and formal authorizing panels. Represent the CDSE at Cross Domain Technical Advisory Board meetings to defend risk profiles and secure Approvals to Connect (ATC).
- Documentation Quality Assurance: Review, edit, and validate customer-authored Cross Domain packages to guarantee strict compliance with NSA “Raise the Bar” (RTB) standards before formal registry submission into the Sponsor Guidance System (SGS).
Requirements
- Process Knowledge: Minimum of 2 years of active experience navigating formal DoD connection pipelines (e.g., DSAWG via the Sponsor Guidance System, or corresponding Service-level authorizing tracks). Must speak fluent “DISA/Title 10” governance.
- Boundary Analysis Reflexes: Proven conceptual understanding of network traffic enforcement, data-diode behaviors, DMZ architecture, Next-Gen Firewalls (NGFW), or Cloud Access Points (CAP). Ability to read data flow diagrams and spot boundary flaws.
- Risk Management Tradecraft: Proven experience authoring custom waivers, STIG tailoring, or Risk Acceptance Memorandums for complex, non-compliant, or mission-critical hardware/software baselines.
- Communication: Exceptional verbal and written communication skills, with proven experience presenting complex risk profiles, technical trade-offs, and out-of-the-box mitigations directly to senior government leadership (GS-15/O-6 level).
Benefits & conditions
Pulled from the full job description
- Professional development assistance
- Parental leave
- 401(k)
- Health insurance
- Retirement plan
- Vision insurance
- Health savings account, Rather than executing raw system configuration, this role acts as the principal gatekeeper and QA authority-evaluating complex customer requirements, conducting architectural document reviews for automated Cloud/Enterprise data pipelines, and engineering creative, defensible risk mitigation strategies for non-standard, emerging technologies across DTRA’s enclaves.
- Schedule: Full-Time Day Job
- Years of Experience: 10+
- Education: Bachelors Degree
- Potential for Teleworking: No
- Required Certifications (Baseline): Active DoD 8140/8570 IAT Level III (CISSP, CASP+ CE, CISA, or GCED), * 401(k)
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Parental leave
- Professional development assistance
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
25 days ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago