> Markdown version of [/jobs/ext/2960025-senior-cyber-security-information-system-security-officer-iss](https://www.wearedevelopers.com/jobs/ext/2960025-senior-cyber-security-information-system-security-officer-iss). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security / Information System Security Officer (ISS - **Company:** Cgi Inc. - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Authentication Protocols, Automation of Tests, Cloud Computing, CompTIA Security+, Cyber Security, System Configuration, Continuous Integration, Data Migration, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Data Streaming, Data Logging, Cloud Platform System, Data Management, Devsecops, Vulnerability Analysis - **Published:** September 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9171001/senior-cyber-security-information-system-security-officer-iss ## About the Role * Must have an Active Top Secret Security Clearance * U.S. Citizenship * Bachelor's degree and 8+ years of experience in cybersecurity, ISSO support, or security engineering * Strong understanding of federal security frameworks and compliance requirements * Experience performing vulnerability scanning, interpreting findings, and driving remediation * Proficiency with identity/access management, system hardening, logging, and auditing * Strong communication skills for partnering with technical teams and leadership Preferred Qualifications * Experience supporting federal modernization or national-security programs * Familiarity with cloud environments (AWS strongly preferred) * Experience with DevSecOps practices, CI/CD pipeline security, and automated scanning * Security certifications such as CISSP, CISM, Security+, or similar Due to the nature of this government contract, US Citizenship is required. ## Description CGI Federal is seeking a Senior Cyber Security / Information System Security Officer (ISSO) to provide advanced security oversight, compliance monitoring, and protection of mission-critical systems within a major federal modernization program. The Senior ISSO ensures all systems, applications, data flows, and development environments adhere to federal security policies, controls, accreditation requirements, and continuous monitoring standards. This role partners with engineering, cloud, DevSecOps, QA, and operations teams to ensure security is embedded across all phases of delivery. Your future duties and responsibilities: Security Governance & Compliance * Implement and enforce federal security policies, controls, standards, and procedures * Maintain security documentation including SSPs, POA&Ms, security checklists, and control evidence * Support continuous monitoring activities, vulnerability scanning, and remediation tracking * Ensure systems, applications, and cloud environments remain compliant with applicable frameworks System Security Oversight * Guide teams on secure architectures, data-handling requirements, and system hardening * Validate security controls across development, testing, migration, and operational environments * Monitor audit logs, access controls, authentication mechanisms, and system configurations * Support accreditation processes, assessments, and readiness activities Collaboration & Advisory Support * Work closely with engineers, cloud teams, DevSecOps, QA automation, data migration, and product leads * Provide security requirements, design guidance, and risk advisories during planning and development * Participate in sprint ceremonies, technical reviews, and release readiness cycles * Communicate risks, incidents, and mitigation strategies to leadership Risk Management & Incident Support * Identify security risks and coordinate mitigation strategies across teams * Support incident response activities, root-cause analysis, and corrective action tracking * Lead remediation efforts for findings from scans, audits, or assessments Documentation & Reporting * Maintain accurate and current security documentation for audits, accreditation, and compliance * Generate reports summarizing vulnerabilities, remediation status, and security posture * Support program leadership with security metrics, dashboards, and risk summaries ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)