Information System Security Officer

Core One
McLean, VA, United States
2 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$150,000.0 - $250,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing CompTIA Security+ Cyber Security Information Systems Computer Engineering Data Security Information Security Management Internet Security Information Systems Security Architecture Professional Server Administration Software Engineering
+4 more
SARS Software Products Information Technology Nessus Vulnerability Analysis

Job description

The Senior Information System Security Officer is responsible for implementing and maintaining cybersecurity controls, ensuring compliance with federal regulations, and guiding information systems through the Customer’s A&A process. This role requires a deep understanding of federal cybersecurity standards, proactive engagement with stakeholders, and the ability to operate independently in a fast-paced environment., * Lead and execute activities across all RMF phases (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor).

  • Develop, review, and maintain accreditation artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessments, and POA&Ms.
  • Monitor compliance with NIST 800-53, 800-171, ICD 503, FedRAMP, FISMA, and agency-specific policies. Prepare for and support audits, inspections, and assessments.
  • Conduct vulnerability scanning, compliance checks, risk assessments, and remediation tracking using tools such as Nessus or Tenable.sc.
  • Create and maintain security documentation, continuous monitoring strategies, incident response plans, and compliance reports. Provide briefings and status updates to leadership and Authorizing Officials.
  • Collaborate with system owners, engineers, and developers to ensure security is integrated into design, development, and operations.
  • Support investigation, response, and remediation of security incidents.
  • Manage account recertifications, access reviews, and deliver security awareness training at the system level.
  • Serve as the primary cybersecurity point of contact for assigned systems, ensuring clear communication with internal and external stakeholders.

Requirements

  • Bachelor’s Degree, or more advanced degree, in Information Technology, Computer Science, Cybersecurity, Computer Engineering, or Information Systems or related field
  • 5+ years of cumulative experience spanning IT systems administration, cybersecurity compliance, IT system troubleshooting, and incident
  • 6+ years of experience in a role such as Information Systems Security Engineer (ISSE), accrediting Sponsor programs
  • Experience with completing new system(s) authorization and accreditation through the Sponsor’s Authorization and Accreditation (A&A) processes, procedures, security requirements, and systems (e.g. Greenlight)
  • Experience using the Sponsor’s A&A process to accredit systems built on C2E or C2S Amazon Web Services
  • Experience in security policy, counterintelligence, and security controls
  • TS/SCI w/ Poly Clearance

Desired Qualifications:

  • Certified in AWS or equivalent cloud technology
  • Security+, Certified Information System Security
  • Professional (CISSP), Certified Information Security
  • Manager (CISM), or equivalent

Salary Range: $150,000 - $250,000

The pay range reflected above is a general guideline for this position and labor category and is not a guarantee of a specific salary or offer. Final compensation is determined based on factors including, but not limited to, relevant experience, education, certifications, security clearance level, contract requirements, geographic location, and internal pay equity, and may reflect market data specific to the awarded contract., Amazon Web Services (AWS), CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, CompTIA Security+, Compensation Management, Computer Engineering, Computer Science, Computer Security, Documentation, FISMA - Federal Information Security Management Act, Federal Compliance Regulations, Incident Response, Information Systems Security Engineering (ISSE), Information Systems/Technology IS/IT Administration, Information Technology & Information Systems, Information/Data Security (InfoSec), Integrated Circuits (ICs), International Classification of Diseases (ICD), Internet Security, Leadership, Maintain Compliance, Nessus, Operational Audit, Regulatory Compliance, Risk Analysis, Security Analysis, Security Policy, Sensitive Compartmented Information (SCI), Software Administration, Software Development, Systems Administration/Management, Team Player, Top Secret Clearance, Training/Teaching, U.S.

About the company

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation’s most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all