Senior Information System Security Officer

Peraton Inc
Washington, VA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Shift work

Tech stack

CompTIA Security+ Cyber Security Identity and Access Management Information Security Management Software Vulnerability Management

Job description

Experteer Overview In this Senior ISSO role, you lead RMF activities and ATO efforts for complex boundary systems, guiding security operations and engineering to meet authorization goals. You collaborate with cross-functional teams and stakeholders to sustain a robust security posture across development, operations, and modernization. You mentor junior ISSOs, shape playbooks, and translate requirements into actionable, testable guidance. This position offers impact at scale within a mission-focused, government-facing environment. Compensation / Benefits * Lead or co-lead ATO/reauthorization efforts for complex boundary systems * Mentor junior ISSOs and shape security operations playbooks * Perform risk analysis and author formal recommendations to leadership * Drive security engineering outcomes by partnering with internal teams on scalable compliance patterns * Brief senior internal and customer stakeholders on security posture, systemic risk trends, remediation burn-down, and authorization readiness * Act as the Senior ISSO supporting the system security lifecycle across development, operations, and modernization * Execute and maintain RMF activities (control implementation oversight, evidence collection, assessment support, POA&Ms, continuous monitoring) * Maintain security authorization artifacts (SSP, control narratives, diagrams, inheritance/leverage controls, CM plan, incident handling plan, contingency artifacts, user/admin procedures) * Operate continuous monitoring: vulnerability management, config compliance, patching coordination, scan result triage, risk acceptance, and remediation verification * Review and approve security-relevant changes through configuration/change control and validate security configurations after major upgrades * Support incident response and reporting: participate in investigations, coordinate containment actions, preserve evidence, and contribute to post-incident lessons learned * Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, and audit compliance requirements * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible) Tasks * Active Top Secret clearance with SCI eligibility * 10+ years information security/compliance experience (8+ years if MS/MA) including RMF deliverables and ATO events for complex systems * Demonstrated leadership coordinating across security, engineering, and customer stakeholders * Mentorship and direction capability for team members * Proven ability to write risk decisions and packages that withstand assessor scrutiny * Deep understanding of continuous monitoring at scale (evidence, metrics, audit readiness, remediation governance) * Hands-on RMF task execution and authorization artifact maintenance (SSP, POA&Ms, CM evidence) * Strong knowledge of NIST SP 800-53 mapping to technical implementations * Experience with vulnerability and configuration compliance workflows * Effective communication of risk to both technical and non-technical leadership * One or more active certifications (e.g., CISSP, CISM, Security+) Key requirements * discretionary bonus * overtime eligibility * shift differential (where applicable)

Requirements

through oversight, privileged access workflows, periodic access reviews, and audit compliance requirements * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible) Tasks * Active Top Secret clearance with SCI eligibility * 10+ years information security/compliance experience (8+ years if MS/MA) including RMF deliverables and ATO events for complex systems * Demonstrated leadership coordinating across security, engineering, and customer stakeholders * Mentorship and direction capability for team members * Proven ability to write risk decisions and packages that withstand assessor scrutiny * Deep understanding of continuous monitoring at scale (evidence, metrics, audit readiness, remediation governance) * Hands-on RMF task execution and authorization artifact maintenance (SSP, POA&Ms, CM evidence) * Strong knowledge of NIST SP 800-53 mapping to technical implementations * Experience with aaaaaaa across and configuration compliance workflows * Effective communication of risk to both technical and non-technical leadership * One or more active certifications (e.g., CISSP, CISM, Security+) Key requirements * discretionary bonus * overtime eligibility * shift differential (where applicable)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

5:51 min

Transitioning to continuous security operations and automated system hardening

Thomas Fuchs +3 · LIVE

Videos

See all

Related articles

See all