> Markdown version of [/jobs/ext/1975877-senior-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1975877-senior-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer - **Company:** Peraton Inc - **Location:** Annapolis Junction, MD, United States - **Experience:** Expert - **Salary:** $135,000.0 - $216,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Databases, Identity and Access Management, Information Security Management, Scrum Methodology, SAP (Applications), Software Vulnerability Management, IT Architecture, Nessus, Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 7, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9081364/senior-information-system-security-officer ## About the Role * Requires active Top Secret clearance with SCI eligibility * Min 12 years with BS/BA, Min 10 years with MS/MA; may consider 4 additional years experience in lieu of BS degree. * 8+ years of experience in information security/compliance supporting DOD/IC or government systems, including ownership of major RMF deliverables and ATO events for complex systems * Demonstrated leadership experience coordinating across security, engineering, and customer stakeholders * Ability to provide mentorship and direction to team members * Proven ability to write risk decisions and packages that stand up to assessor/AO scrutiny * Deep understanding of continuous monitoring at scale (recurring evidence, metrics, audit readiness, remediation governance) * Hands-on experience executing RMF tasks and maintaining authorization artifacts (SSP, POA&Ms, continuous monitoring evidence) * Strong working knowledge of NIST SP 800-53 controls and how they map to technical implementations and procedures * Experience with vulnerability and configuration compliance workflows * Ability to communicate risk clearly to both technical engineers and non-technical leadership * One or more active/current certifications such as: CISSP, CISM, SecurityX, Security+, and etc., * Experience with SAP assessments and authorizations * Experience securing or assessing different platforms (applications, databases, operating systems, hardware, and etc ) * Experience with SCRUM methodologies * Experience with Splunk and/or other auditing compliance tools. * Experience with ACAS, Nessus, and/or other vulnerability scanners * Experience with data protection requirements relevant to sensitive environments ## Description Engineering, integration, and cybersecurity support to design, build, and test enhanced services for the Department of Navy's IT architecture. Offers a wide range of roles, from cybersecurity experts to engineers specializing in systems, networks, software, and data center services., Peraton is seeking a Senior ISSO to support our customer onsite in Annapolis Junction, MD., * Lead or co-lead ATO/reauthorization efforts for complex boundary systems * Mentor junior ISSOs and shape security operations playbooks * Perform risk analysis and author formal recommendations to leadership * Drive security engineering outcomes by partnering with internal teams on scalable compliance patterns * Brief senior internal and customer stakeholders on security posture, systemic risk trends, remediation burn-down, and authorization readiness * Act as the Senior ISSO supporting the system security lifecycle across development, operations, and modernization * Execute and maintain RMF activities (e.g., control implementation oversight, evidence collection, assessment support, POA&M management, continuous monitoring) * Maintain security authorization artifacts (e.g., SSP, control narratives, diagrams, inheritance/leverage controls, CM plan, incident handling plan, contingency artifacts, user/admin procedures) * Operate continuous monitoring: vulnerability management, config compliance, patching coordination, scan result triage, risk acceptance, and remediation verification * Review and approve security-relevant changes through configuration/change control and validate security configurations after major upgrades * Support incident response and reporting: participate in investigations, coordinate containment actions, preserve evidence, and contribute to post-incident lessons learned * Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, and audit compliance requirements * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible) ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Branch your database like your code: How schema changes and pull requests go hand in hand](https://www.wearedevelopers.com/videos/350-branch-your-database-like-your-code-how-schema-changes-and-pull-requests-go-hand-in-hand) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)