> Markdown version of [/jobs/ext/573206-senior-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/573206-senior-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer - **Company:** Amentum Services, Inc. - **Location:** Warrenton, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Word, Microsoft Excel, Microsoft Windows, Active Directory, Microsoft Outlook, Cyber Security, Information Systems, Data as a Services, Linux, Information Security Management, Microsoft Visio, Red Hat Enterprise Linux, Security Software, Microsoft SharePoint, SC Clearance, Forescout, Information Technology, Nessus, Splunk - **Published:** June 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8958714/senior-information-system-security-officer ## About the Role In support of a challenging, critical, and rewarding program that provides integrated voice, video, and data services throughout the Information Technology lifecycle, Amentum is seeking a Senior Information System Security Officer to join our dynamic team of IT professionals dedicated to fostering a positive and collaborative work environment. You must be a critical thinker, have a strong work ethic, and be able to work independently or as a member of a team in a dynamic environment. We value candidates who are detail-oriented while also being able to think and react quickly to emerging and unique problem sets. To be successful, you must be able to rapidly adapt and learn how to operate the front and back end of new products and processes., * Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI * 8 years of relevant experience * In-depth knowledge of Microsoft Windows OS (client and server) and familiarity with Red Hat Enterprise Linux (RHEL). * Experience with security configurations across multiple operating systems in various environments, to include Windows and Linux, utilizing Active Directory/Group Policy * Experience in the development of technical documentation to include artifacts required to support Assessment and Authorization (A&A) under the Risk Management Framework * Experience with XACTA, ACAS/NESSUS, Trellix, and Splunk * Experience with DISA STIGs and DISA Viewer * Experience with risk * 2 years of knowledge and experience with NESSUS/ACAS and Trellix administration * Must be able to work a 40-hour work week, normally Monday through Friday. * Ability to work overtime during critical peaks and be available to meet last minute requests for overtime if needed. * Ability to travel (5-10%) primarily within 75 miles. * Familiarity with MS Office applications such as Excel, Word, Outlook, SharePoint, Project, and Visio. * Exceptional attention to detail; excellent verbal and written communication skills; strong critical thinking, organizational, time-management, and problem-solving skills. * Ability to work both independently and as part of a team in a dynamic environment. Security Clearance Required: * Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI Minimum Education: * Bachelor's degree in IT related field Minimum Years of Experience: * 8 years of relevant experience Required Certifications: Must have or be able to obtain one of the following 8140 IA Technical Level III baseline certifications before start date: * Level III certs include - CASP CE, CCNP, CISA, CISSP (or Associate), * Previous supervision and/or participation with Cybersecurity Assessments and Authorizations * Familiarity and the ability to aid with the cybersecurity tools such as ForeScout, Ivanti, and Trellix ## Description * Generate and maintain the complete security Body of Evidence (BoE) while leading the A&A activities according to the Risk Management Framework (RMF) processes (ICD 503, CNSSI-1253, NIST 800-37, NIST 800-53, etc.) for all multiple information systems. * Lead the development and maintenance of information security policies, standards, and control procedures to enable compliance with RMF. * Complete Security Authorization packages, to include System Security Plans, Security Assessment Reports, POA&M summaries, and a Continuous Monitoring Plan/assessment schedule within XACTA, and present executive briefings to senior management. * Conduct thorough auditing of security information and events utilizing advanced tools like Splunk and NESSUS to detect and mitigate potential threats, ensuring the integrity of the enterprise. * Ensure security risk assessments are conducted as appropriate on any system upgrades, software/hardware changes, etc. * Ensure security authorization boundaries are properly defined and captured in the system security plans, and that all interconnection agreements are in place and current. * Ensure system security controls contain accurate implementation statements and assessment results, and that appropriate artifacts are completed to support findings; provide hands-on assistance as appropriate. * Ensure POA&Ms have appropriate milestones, accurate description of the weaknesses and remediation, estimated cost and realistic due dates providing hands-on assistance to components as necessary. * Maintain day-to-day security posture and continuous monitoring of all Information Systems. * Review system vulnerability scans, verify implementation of DISA STIGs, and ensure other security relevant information system configuration tasks are completed. * Perform test/evaluation of required technical security controls including performing certification tests and periodic inspections of information systems. * Develop and conduct test procedures for verification A&A, RMF safeguards to meet customer requirements based NIST publications. * Assess changes to an IS by performing periodic self-inspections, tests, and reviews of the IS program to ensure that systems are operating as authorized/accredited and that conditions have not changed; ensure corrective actions are taken for identified findings and vulnerabilities. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)