> Markdown version of [/jobs/ext/2025781-senior-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2025781-senior-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer - **Company:** CACI International Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Security Management, Systems Development Life Cycle, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/senior-information-system-security-officer-washington-dc-usa-58899227 ## About the Role aaaaaw_ Plans (SSPs) and control baselines * Create and maintain Configuration Management, Contingency, and Incident Response Plans * Conduct risk assessments, annual security assessments, and vulnerability assessments * Manage security documentation handling and classification-aware communications * Maintain incident and threat assessment programs for classified systems Tasks * U.S. Citizenship required * Active TS/SCI Clearance * BS/BA + 15 years of information security experience * One of CISSP, CISM, or CASP+ (IAT Level III qualifications) * 10+ years in information security * Experience with classified information systems and SCIFs * Expertise in RMF, FISMA, NIST, DHS 4300 Series, and classified system security requirements * Complete Standard Form 4414 Non-Disclosure Agreement before accessing TS/SCI information Key requirements * flexible time off * robust learning resources * healthcare benefits * retirement benefits * continuing education * time off benefits ## Description Experteer Overview In this role you will lead security and compliance for FEMA's most sensitive systems, ensuring robust controls across classified and unclassified environments. You will act as the single point of contact for classified system matters within the Cybersecurity Division, collaborating with system owners and cyber professionals to secure mission-critical data. You will drive RMF activities, ATO decisions, and SDLC-related security work in TS/SCI contexts, contributing to national security objectives. This opportunity offers impactful work at the intersection of defense-grade security and public service, with opportunities to shape security programs and incident response across complex systems. Compensation / Benefits * Complete RMF activities for Authority to Operate (ATO) decisions * Support classified and unclassified systems through the SDLC * Participate in classified network and facility meetings related to Supply Chain Risk Management * Develop and maintain System Security Plans (SSPs) and control baselines * Create and maintain Configuration Management, Contingency, and Incident Response Plans * Conduct risk assessments, annual security assessments, and vulnerability assessments * Manage security documentation handling and classification-aware communications * Maintain incident and threat assessment programs for classified systems Tasks * U.S. Citizenship required * Active TS/SCI Clearance * BS/BA + 15 years of information security experience * One of CISSP, CISM, or CASP+ (IAT Level III qualifications) * 10+ years in information security * Experience with classified information systems and SCIFs * Expertise in RMF, FISMA, NIST, DHS 4300 Series, and classified system security requirements * Complete Standard Form 4414 Non-Disclosure Agreement before accessing TS/SCI information Key requirements * flexible time off * robust learning resources * healthcare benefits * retirement benefits * continuing education * time off benefits ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)