Information Systems Security Officer (ISSO)
Peraton
Get more Software Engineering openings
A short daily email when similar roles appear in Chantilly. No account needed.
Responsibilities
Peraton is seeking a Mid-Level Information Systems Security Officer (ISSO) in Chantilly, VA to support our Department of Defense customer as part of a highly talented, highly motivated, and high-performing team. As part of the cybersecurity team, you will support Assessment and Authorization (A&A) activities for information systems operating within a DoD Special Access Program (SAP) environment. The position requires extensive knowledge of the Joint Special Access Program Implementation Guide (JSIG) and demonstrated experience implementing the Risk Management Framework (RMF) throughout the system lifecycle.
What you'll do:
- Support the prepare, categorize, select, implement, assess, authorize, and monitor phases of the RMF lifecycle for information systems operating within a DoD SAP environment.
- Interpret and apply JSIG policy and guidance to system security requirements, security control implementation, assessment activities, authorization packages, and continuous monitoring.
- Develop, review, and maintain system security plans (SSPs), security control traceability matrices (SCTMs), plans of action and milestones (POA&Ms), risk assessments, continuous monitoring strategies, contingency plans, incident response plans, and supporting authorization artifacts.
- Develop and maintain security control implementation statements that accurately describe how technical, operational, and management controls are implemented within the system and its operating environment.
- Collect, review, and validate technical and nontechnical evidence demonstrating security control implementation and effectiveness.
- Coordinate security control assessments, authorization activities, periodic reviews, annual assessments, and continuous monitoring activities with system owners, engineers, administrators, assessors, and Authorizing Official (AO) representatives.
- Support authorization package submissions, assessment preparation, evidence reviews, discrepancy resolution, and responses to Security Control Assessor (SCA) and AO questions.
- Identify cybersecurity risks, document control deficiencies, recommend corrective actions, and track remediation activities through closure.
- Develop and maintain POA&Ms containing accurate weakness descriptions, risk determinations, remediation strategies, milestones, scheduled completion dates, and closure evidence.
- Review vulnerability scan results, DISA Security Technical Implementation Guide (STIG) findings, configuration compliance results, audit records, and other cybersecurity data to determine risk and authorization impact.
- Review system architectures, network diagrams, data flows, authorization boundaries, hardware and software inventories, ports, protocols, services, external connections, and system interconnections for accuracy and compliance.
- Evaluate proposed hardware, software, architecture, configuration, service, and interconnection changes to determine cybersecurity, A&A, security control, and authorization boundary impacts.
- Participate in configuration control boards, engineering reviews, security working groups, technical exchange meetings, and cybersecurity risk discussions.
- Advise system administrators and engineers on security control implementation, STIG hardening, vulnerability remediation, and authorization requirements.
- Communicate the system security posture, unresolved weaknesses, operational risks, and recommended mitigation actions to the ISSM and appropriate program leadership.
Qualifications
Required Qualifications:
- This position requires the candidate to possess a minimum of an active Top Secret with eligibility for SCI clearance; must be able to maintain TS/SCI and SAP access.
- Bachelor's degree and 5+ years of relevant experience; master's degree and 3+ years of relevant experience; associate degree and 7+ years of relevant experience; or high school diploma and 9+ years of relevant experience. Additional 4 years of relevant experience may be considered in lieu of a degree.
- Knowledge of A&A activities within a DoD SAP environment and demonstrated experience implementing RMF requirements using the JSIG.
- Working experience with DoDI 8510.01, NIST Special Publication 800-53, CNSSI 1253, ICD 503, applicable DISA guidance, and related DoD cybersecurity policies.
- Demonstrated experience developing, reviewing, and maintaining RMF authorization packages, including SSPs, SCTMs, POA&Ms, risk assessments, continuous monitoring documentation, and supporting control evidence.
- Experience documenting security control implementations, evaluating the sufficiency of implementation evidence, and supporting control validation and assessment activities.
- Experience supporting security control assessments, authorization decisions, continuous monitoring, annual reviews, and system reauthorization activities.
- Experience reviewing DISA STIG findings, vulnerability scan results, configuration compliance results, and remediation evidence to determine cybersecurity risk and authorization impact.
- Ability to evaluate technical and procedural findings, document residual risk, recommend mitigation or risk acceptance actions, and clearly communicate operational and authorization impacts.
- Use of Windows and Linux operating systems, network security, identity and access management, audit logging, vulnerability management, encryption, and secure configuration practices.
- Must meet DoD Manual 8140.03 for DoD Cyber Workforce Framework Work Role 722 - Information Systems Security Manager, Intermediate Proficiency Level, or Work Role 541 - Vulnerability Assessment Analyst, Intermediate Proficiency Level, as applicable to the duties of an ISSO.
- Strong technical writing, documentation management, organizational, analytical, and verbal communication skills, with the ability to collaborate effectively with cybersecurity, program security, engineering, system administration, assessment, and program management personnel.
Desired Qualifications:
- Current or previous approval to support a DoD SAP.
- Experience working directly with ISSMs, Security Control Assessors, Authorizing Official representatives, Program Security Officers, Government SAP Security Officers, and system owners.
- Experience preparing systems and authorization packages for formal SAP cybersecurity assessment activities.
- Experience with eMASS, Xacta, or another approved governance, risk, compliance, or authorization management platform.
- Experience with ACAS, Tenable Nessus, Tenable Security Center, SCAP tools, Splunk, HBSS/Trellix, or comparable cybersecurity tools.
- Experience supporting private cloud, hybrid cloud, virtualized, containerized, or classified enterprise environments.
- Experience evaluating system interconnections, external services, inherited controls, or cross-domain solutions.
- Current certification such as Security+, SecurityX, CISSP, CGRC, or another certification recognized under the applicable DoD 8140 qualification matrix.
- Ability to work independently with minimal supervision while recognizing matters requiring ISSM, assessor, or AO involvement.
Benefits:
Peraton offers enhanced benefits to employees working on this critical National Security program, which include heavily subsidized employee benefits coverage for you and your dependents, 25 days of PTO accrued annually up to a generous PTO cap and eligible to participate in an attractive bonus plan
#Metroplex
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Target Salary Range
$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
The average job posting receives 250 applications.
Stand out by tailoring your resume to this specific role. Our AI resume builder highlights the skills and experience that matter most to this employer.