Information Security Systems Officer (ISSO) - Senior Consultant

Guidehouse Inc.
Springfield, VA, United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Agile Methodology Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Security Cloud Engineering Cyber Security Information Systems Computer Engineering Continuous Integration Identity and Access Management
+15 more
Information Systems Security Architecture Professional Python (Programming Language) Network Security Windows PowerShell Scaled Agile Framework Security Content Automation Protocol Security Information and Event Management Data Logging Scripting HybridCloud Nessus CIS Benchmarks Splunk Devsecops Vulnerability Analysis

Job description

We are seeking a highly experienced Information Security Systems Officer (ISSO)- to support a major federal initiative. The ISSO serves as a technical and compliance lead, guiding system owners, engineers, and security teams through RMF, ATO, and continuous monitoring activities. This role is responsible for interpreting policy, providing authoritative security guidance, leading audits, and evaluating complex systems across hybrid cloud and on-premises environments. The ISSO will mentor junior staff and ensure that systems maintain full compliance with federal requirements, NIST security controls, and agency-specific governance., * Lead design and engineering of secure cloud architectures across AWS, Azure, and hybrid environments.

  • Implement and validate NIST 800-53 security controls and cloud-native security services (IAM, encryption, segmentation, logging).
  • Conduct cloud threat modeling, risk assessments, and architecture reviews.
  • Oversee cloud configuration baselines using STIGs, CIS Benchmarks, and SCAP.
  • Drive cloud vulnerability and compliance efforts using ACAS/Nessus and cloud-security posture tools.
  • Support RMF engineering activities including boundary definition, inheritance documentation, and authorization packages.
  • Integrate cloud-security capabilities such as Sentinel, Splunk, and SIEM logging pipelines.
  • Guide DevSecOps teams on secure CI/CD, container security, and infrastructure-as-code validation.
  • Produce cloud architecture diagrams, design documentation, and engineering artifacts.
  • Mentor junior and mid-level ISSEs and act as a technical escalation point for cloud engineering issues.

Requirements

  • Bachelor’s degree from an accredited university.
  • Minimum of FIVE (5) years of work experience in cybersecurity or secure systems engineering experience, including cloud architecture.
  • An ACTIVE and MAINTAINED TS/SCI Poly Federal or DoD security clearance with a (COUNTERINTELLIGENCE (CI) polygraph - OR - FULL SCOPE (FS/FSP) polygraph).
  • US Citizenship is contractually required.
  • Strong understanding of security frameworks and compliance standards (e.g., NIST, RMF SP 800-53 Rev 5, DoD 8570).

  • Proven experience in designing and implementing enterprise security tools such as SIEM (e.g., Splunk), vulnerability scanners (e.g., Nessus), and endpoint protection platforms (e.g., Crowdstrike).
  • Demonstrated ability to lead cross-functional teams and complex technical projects.
  • Strong analytical and problem-solving skills.
  • Excellent communication skills with the ability to convey technical concepts to non-technical stakeholders.

What Would Be Nice To Have:

  • Bachelor’s degree from an accredited university in Cybersecurity, Information Systems, Computer Engineering, or related technical field.
  • Master’s Degree in relevant cybersecurity or IT field.
  • One or more of the following certifications:
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Controls (CRISC)
  • Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC)
  • Certified Information Systems Auditor (CISA)
  • Familiarity with scripting or automation (PowerShell, Python, Bash) is a plus
  • Hands-on experience with network security, cryptography, and/or identity management.
  • Project Management Professional (PMP) or Scaled Agile Framework (SAFe) certification for managing cybersecurity projects in Agile environments.

Benefits & conditions

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all