Information System Security Officer - Senior

Amentum Services, Inc.
Warrenton, VA, United States
24 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$160,000.0 - $190,000.0
Working hours
Shift work

Tech stack

Xacta Microsoft Word Microsoft Excel Microsoft Windows Active Directory Microsoft Outlook Cyber Security Information Systems Data as a Services Linux Information Security Management Microsoft Visio
+9 more
Red Hat Enterprise Linux Security Software Microsoft SharePoint SC Clearance Forescout Information Technology Nessus Splunk Plan of Action and Milestones

Job description

The duties and responsibilities of the Senior Information System Security Officer include, but are not limited to the following:

  • Generate and maintain the complete security Body of Evidence (BoE) while leading the A&A activities according to the Risk Management Framework (RMF) processes (ICD 503, CNSSI-1253, NIST 800-37, NIST 800-53, etc.) for all multiple information systems.
  • Lead the development and maintenance of information security policies, standards, and control procedures to enable compliance with RMF.
  • Complete Security Authorization packages, to include System Security Plans, Security Assessment Reports, POA&M summaries, and a Continuous Monitoring Plan/assessment schedule within XACTA, and present executive briefings to senior management.
  • Conduct thorough auditing of security information and events utilizing advanced tools like Splunk and NESSUS to detect and mitigate potential threats, ensuring the integrity of the enterprise.
  • Ensure security risk assessments are conducted as appropriate on any system upgrades, software/hardware changes, etc.
  • Ensure security authorization boundaries are properly defined and captured in the system security plans, and that all interconnection agreements are in place and current.
  • Ensure system security controls contain accurate implementation statements and assessment results, and that appropriate artifacts are completed to support findings; provide hands-on assistance as appropriate.
  • Ensure POA&Ms have appropriate milestones, accurate description of the weaknesses and remediation, estimated cost and realistic due dates providing hands-on assistance to components as necessary.
  • Maintain day-to-day security posture and continuous monitoring of all Information Systems.
  • Review system vulnerability scans, verify implementation of DISA STIGs, and ensure other security relevant information system configuration tasks are completed.
  • Perform test/evaluation of required technical security controls including performing certification tests and periodic inspections of information systems.
  • Develop and conduct test procedures for verification A&A, RMF safeguards to meet customer requirements based NIST publications.
  • Assess changes to an IS by performing periodic self-inspections, tests, and reviews of the IS program to ensure that systems are operating as authorized/accredited and that conditions have not changed; ensure corrective actions are taken for identified findings and vulnerabilities., Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.

Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.

Requirements

In support of a challenging, critical, and rewarding program that provides integrated voice, video, and data services throughout the Information Technology lifecycle, Amentum is seeking a Senior Information System Security Officer to join our dynamic team of IT professionals dedicated to fostering a positive and collaborative work environment. You must be a critical thinker, have a strong work ethic, and be able to work independently or as a member of a team in a dynamic environment. We value candidates who are detail-oriented while also being able to think and react quickly to emerging and unique problem sets. To be successful, you must be able to rapidly adapt and learn how to operate the front and back end of new products and processes., * Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI

  • 8 years of relevant experience
  • In-depth knowledge of Microsoft Windows OS (client and server) and familiarity with Red Hat Enterprise Linux (RHEL).
  • Experience with security configurations across multiple operating systems in various environments, to include Windows and Linux, utilizing Active Directory/Group Policy
  • Experience in the development of technical documentation to include artifacts required to support Assessment and Authorization (A&A) under the Risk Management Framework
  • Experience with XACTA, ACAS/NESSUS, Trellix, and Splunk
  • Experience with DISA STIGs and DISA Viewer
  • Experience with risk
  • 2 years of knowledge and experience with NESSUS/ACAS and Trellix administration
  • Must be able to work a 40-hour work week, normally Monday through Friday.
  • Ability to work overtime during critical peaks and be available to meet last-minute requests for overtime if needed.
  • Ability to travel (5-10%) primarily within 75 miles.
  • Familiarity with MS Office applications such as Excel, Word, Outlook, SharePoint, Project, and Visio.
  • Exceptional attention to detail; excellent verbal and written communication skills; strong critical thinking, organizational, time-management, and problem-solving skills.
  • Ability to work both independently and as part of a team in a dynamic environment.

Security Clearance Required:

Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI

Minimum Education:

Bachelor’s degree in IT related field

Minimum Years of Experience:

8 years of relevant experience

Required Certifications:

Must possess or be able to obtain one of the following 8140 IAT Level II or III baseline certifications before start date:

  • Level II certs include - CCNA Security, CySA+, CND, Security+ CE
  • Level III certs include - CASP CE, CCNP Security, CISA, CISSP (or Associate), * Previous supervision and/or participation with Cybersecurity Assessments and Authorizations
  • Familiarity and the ability to aid with the cybersecurity tools such as ForeScout, Ivanti, and Trellix

Benefits & conditions

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all