Senior Information System Security Officer Peraton
Overview
Peraton seeks a Senior ISSO to lead IT architecture support in Annapolis Junction MD. You will lead or co-lead ATO/reauthorization efforts mentor junior staff drive security engineering outcomes execute RMF activities maintain security artifacts operate continuous monitoring support incident response ensure least privilege governance translate security requirements provide qualifications required and preferred list.
What You'll Do13
- 1Lead or co-lead ATO/reauthorization efforts for complex boundary systems
- 2Mentor junior ISSOs and shape security operations playbooks
- 3Perform risk analysis and author formal recommendations to leadership
- 4Drive security engineering outcomes by partnering with internal teams on scalable compliance patterns
- 5Brief senior internal and customer stakeholders on security posture systemic risk trends remediation burn-down and authorization readiness
- 6Act as the Senior ISSO supporting the system security lifecycle across development operations and modernization
- 7Execute and maintain RMF activities control implementation oversight evidence collection assessment support POA&M management continuous monitoring
- 8Maintain security authorization artifacts such as SSP control narratives diagrams inheritance/leverage controls CM plan incident handling plan contingency artifacts user/admin procedures
- 9Operate continuous monitoring vulnerability management config compliance patching coordination scan result triage risk acceptance and remediation verification
- 10Review and approve security-relevant changes through configuration change control and validate security configurations after major upgrades
- 11Support incident response and reporting participate in investigations coordinate containment actions preserve evidence and contribute to post-incident lessons learned
- 12Ensure least privilege/access governance account management oversight privileged access workflows periodic access reviews and audit compliance requirements
- 13Translate security requirements into implementation guidance that engineering teams can operationalize clear testable and automatable where possible
Requirements18
- 1Active Top Secret clearance with SCI eligibility
- 2Min 12 years with BS/BA Min 10 years with MS/MA may consider 4 additional years experience in lieu of BS degree
- 38+ years of experience in information security compliance supporting DOD/IC or government systems including ownership of major RMF deliverables and ATO events for complex systems
- 4Demonstrated leadership experience coordinating across security engineering and customer stakeholders
- 5Ability to provide mentorship and direction to team members
- 6Proven ability to write risk decisions and packages that stand up to assessor/AO scrutiny
- 7Deep understanding of continuous monitoring at scale recurring evidence metrics audit readiness remediation governance
- 8Hands-on experience executing RMF tasks and maintaining authorization artifacts SSP POA&Ms continuous monitoring evidence
- 9Strong working knowledge of NIST SP 800-53 controls and how they map to technical implementations and procedures
- 10Experience with vulnerability and configuration compliance workflows
- 11Ability to communicate risk clearly to both technical engineers and non-technical leadership
- 12One or more active/current certifications such as CISSP CISM SecurityX Security+
- 13Preferred Experience with SAP assessments and authorizations
- 14Experience securing or assessing different platforms applications databases operating systems hardware
- 15Experience with SCRUM methodologies
- 16Experience with Splunk and/or other auditing compliance tools
- 17Experience with ACAS Nessus and/or other vulnerability scanners
- 18Experience with data protection requirements relevant to sensitive environments
Salary Insight
$135 - $216k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
1805 KBR Wyle Services, LLC
VerifiedSenior Information System Security Officer (ISSO)
Lead cybersecurity approval and compliance processes while supporting system owners and project managers. Review technical architectures and integrate security requirements throughout the system lifecycle. Ensure cybersecurity compliance and provide guidance to engineers and non-technical partners.
02 CACI, INC.-FEDERAL
VerifiedInformation System Security Manager
Lead and oversee Risk Management Framework lifecycle activities for classified DoD systems supporting SAP SCI NSA missions. Manage system authorizations and cybersecurity compliance while serving as senior cybersecurity authority. Ensure systems remain secure compliant and fully authorized to operate.
Nyla Technology Solutions
VerifiedSenior Information Systems Security Engineer
You will own technical security assessments and engineer IA solutions across multi-enclave environments at TS/SCI polygraph level. You will architect, integrate, and deploy security functionality into networking and computing components, ensuring compliance with RMF and NIST standards. Working with architects and developers, you will embed security throughout the engineering lifecycle. This role stands out for hands-on system building, not just audits, within a top-tier compensation package.
Inadev
VerifiedInformation System Security Officer (ISSO), RMF & NIST
Own the security posture and authorization of a federal system as ISSO at Inadev. Manage the RMF lifecycle, maintain ATO documentation, and ensure continuous compliance with NIST 800-53 and FedRAMP. You will track findings, coordinate with DevSecOps, and report risks to stakeholders. This contract role offers a hybrid schedule in DC and Reston, VA, working with a vibrant team. You bring 5+ years of ISSO experience and a CISSP or equivalent certification.
GD Information Technology, Inc.
VerifiedInformation Systems Security Manager (ISSM) - RMF & XACTA
Information Systems Security Management (ISSM), you will own the RMF workflow and A&A process for a premier cyber security risk management platform supporting DoD and Intelligence Community customers. You will ensure operational IT capabilities deliver timeliness, accuracy, and security of information across multiple fabrics and centers. Your days involve coordinating with stakeholders, managing system vulnerabilities, and maintaining compliance with NIST standards. This role stands out because you'll directly impact national security while working with leading-edge tools like XACTA 360 and STIGs. You will be the go-to expert for all security authorizations, guiding systems from concept to Authority to Operate (ATO).
Xpect Solutions
VerifiedInformation Systems Security Officer - Xpect Solutions
Lead compliance and security operations for government information systems. Navigate the full NIST Risk Management Framework and ensure adherence to NIST 800-53 controls and DHS 4300A requirements. Partner with Government Security Assurance Management teams to protect critical systems and maintain compliance posture.