Senior Information System Security Officer

Peraton Inc
Annapolis Junction, MD, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$135,000.0 - $216,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Databases Identity and Access Management Information Security Management Scrum Methodology SAP (Applications) Software Vulnerability Management IT Architecture Nessus Splunk Plan of Action and Milestones Vulnerability Analysis

Job description

Engineering, integration, and cybersecurity support to design, build, and test enhanced services for the Department of Navy’s IT architecture. Offers a wide range of roles, from cybersecurity experts to engineers specializing in systems, networks, software, and data center services., Peraton is seeking a Senior ISSO to support our customer onsite in Annapolis Junction, MD., * Lead or co-lead ATO/reauthorization efforts for complex boundary systems

  • Mentor junior ISSOs and shape security operations playbooks
  • Perform risk analysis and author formal recommendations to leadership
  • Drive security engineering outcomes by partnering with internal teams on scalable compliance patterns
  • Brief senior internal and customer stakeholders on security posture, systemic risk trends, remediation burn-down, and authorization readiness
  • Act as the Senior ISSO supporting the system security lifecycle across development, operations, and modernization
  • Execute and maintain RMF activities (e.g., control implementation oversight, evidence collection, assessment support, POA&M management, continuous monitoring)
  • Maintain security authorization artifacts (e.g., SSP, control narratives, diagrams, inheritance/leverage controls, CM plan, incident handling plan, contingency artifacts, user/admin procedures)
  • Operate continuous monitoring: vulnerability management, config compliance, patching coordination, scan result triage, risk acceptance, and remediation verification
  • Review and approve security-relevant changes through configuration/change control and validate security configurations after major upgrades
  • Support incident response and reporting: participate in investigations, coordinate containment actions, preserve evidence, and contribute to post-incident lessons learned
  • Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, and audit compliance requirements
  • Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible)

Requirements

  • Requires active Top Secret clearance with SCI eligibility
  • Min 12 years with BS/BA, Min 10 years with MS/MA; may consider 4 additional years experience in lieu of BS degree.
  • 8+ years of experience in information security/compliance supporting DOD/IC or government systems, including ownership of major RMF deliverables and ATO events for complex systems
  • Demonstrated leadership experience coordinating across security, engineering, and customer stakeholders
  • Ability to provide mentorship and direction to team members
  • Proven ability to write risk decisions and packages that stand up to assessor/AO scrutiny
  • Deep understanding of continuous monitoring at scale (recurring evidence, metrics, audit readiness, remediation governance)
  • Hands-on experience executing RMF tasks and maintaining authorization artifacts (SSP, POA&Ms, continuous monitoring evidence)
  • Strong working knowledge of NIST SP 800-53 controls and how they map to technical implementations and procedures
  • Experience with vulnerability and configuration compliance workflows
  • Ability to communicate risk clearly to both technical engineers and non-technical leadership
  • One or more active/current certifications such as: CISSP, CISM, SecurityX, Security+, and etc., * Experience with SAP assessments and authorizations
  • Experience securing or assessing different platforms (applications, databases, operating systems, hardware, and etc )
  • Experience with SCRUM methodologies
  • Experience with Splunk and/or other auditing compliance tools.
  • Experience with ACAS, Nessus, and/or other vulnerability scanners
  • Experience with data protection requirements relevant to sensitive environments

Benefits & conditions

Target Salary Range: $135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at https://www.careers.peraton.com/benefits.

About the company

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

5:51 min

Transitioning to continuous security operations and automated system hardening

Thomas Fuchs +3 · LIVE

Videos

See all

Related articles

See all