> Markdown version of [/jobs/ext/2106140-principal-cybersecurity-systems-security-officer-90307947-null](https://www.wearedevelopers.com/jobs/ext/2106140-principal-cybersecurity-systems-security-officer-90307947-null). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cybersecurity Systems Security Officer - 90307947 - null - **Company:** Amtrak - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $113,200.0 - $146,664.0 - **Contract:** Contract - **Skills:** Agile Methodology, Software as a Service, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Information Systems Security Architecture Professional, Software Vulnerability Management, Information Security Management System, Cloud Platform System, CIS Benchmarks, Devsecops - **Published:** August 18, 2026 - **Apply:** https://careers.amtrak.com/talentcommunity/apply/1420529200/?locale=en_US ## About the Role * Bachelor's Degree or equivalent combination of education, training and/or relevant experience. * 7 years of relevant work experience or 11 plus years in lieu of degree * ISC2 CISSP (Certified Information Systems Security Professional), * Bachelor's Degree in Cybersecurity, Information Systems or equivalent combination of education, training and/or relevant experience. Plus 9 years of relevant work experience. * Desired industry standard cybersecurity certifications: CISM, CISA, CRISC, GCIH, GPEN, CEH, CHFI, Security+, CASP, OSCP, etc. Knowledge, Skills & Abilities: * Ability to build cross-functional alignment and lead complex cross functional programs. * Strong written and verbal communication skills * Ability to translate technical findings and regulatory requirements. * Demonstrated experience performing security architecture reviews, risk assessments, threat modeling, vulnerability management, and security control evaluations across applications, infrastructure, networks, and cloud environments. * Demonstrated success building or scaling an ISSO/ISSM operating model across multiple products, platforms, or business units. * Expert knowledge of cybersecurity governance, risk management, and control frameworks, including mapping requirements to implemented controls and measurable evidence. * Skill in designing and operating continuous monitoring programs (security telemetry, vulnerability management, configuration baselines, exception handling, and metrics). * Skill in leading audit/assurance activities, including preparing control narratives, evidence packages, and stakeholder responses under tight deadlines. * Experience implementing or operating an ISO/IEC 27001-aligned information security management system (ISMS) and supporting external audits/attestations. * Strong knowledge of cybersecurity frameworks and standards, including NIST RMF, NIST CSF, CIS Controls, UCF, and other applicable industry and regulatory frameworks. * Knowledge of OT/ICS cybersecurity principles, including cyber-to-physical risk, safety impacts, and operational constraints that affect control selection and implementation. * Experience with GRC tooling (controls library management, evidence workflows, risk registers) and security KPI/KRI design. * Experience coordinating third-party risk and contract security requirements, including cloud/SaaS and managed service providers. ## Description The Principal Cybersecurity Systems Security Officer leads the cybersecurity governance and risk management program for assigned systems and services, ensuring they operate at an acceptable level of risk and remain assessment- and audit-ready. This role establishes security governance, drives control effectiveness, and integrates security requirements into system design, engineering, operations, and sustainment activities. Oversees continuous monitoring, assessment readiness, and remediation execution, translating control gaps into clear risk decisions and prioritized actions. The role manages and develops cybersecurity staff and partners closely with engineering, operations, compliance, and business leadership to deliver measurable risk reduction while supporting availability, reliability, and operational objectives., * Develop and maintain security documentation, including System Security Plans (SSPs), Security Design Reviews, Secure Design Directives (SDDs), risk assessments, exception requests, and remediation plans. * Serve as the primary cybersecurity advisor for Agile Release Trains (ARTs), partnering with business, portfolio, product, architecture, and engineering stakeholders to integrate security-by-design principles, DevSecOps practices, and risk management activities into Program Increment (PI) Planning and solution delivery processes. * Perform security architecture and design reviews to identify security gaps, evaluate risks, and design appropriate mitigating and compensating controls. * Lead assessment, audit, and assurance readiness activities by establishing evidence strategies, maintaining high-quality security documentation, coordinating reviews, and ensuring timely closure of findings and gaps. * Drive security assessment and authorization or attestation activities by ensuring security plans, control implementations, and decision artifacts are current, traceable, and defensible. * Drive continuous monitoring programs by defining required security telemetry, reviewing control health, overseeing vulnerability and configuration management activities, and monitoring residual risk trends. * Lead risk decision-making by prioritizing remediation activities, adjudicating exceptions and compensating controls, and escalating material risks with clear impact statements and recommended actions. * Partner with engineering, architecture, and operations stakeholders to integrate security requirements into system design, change management, release readiness, and lifecycle sustainment processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)