Staff Information Systems Security Officer
The Staff Information Systems Security Officer will secure and accredit classified information systems by implementing RMF and NIST controls, managing vulnerabilities, supporting audits and incident response, and overseeing Cross Domain Solutions. The role requires 8 years of classified-environment cybersecurity experience and expertise in DoD and IC requirements.
About the job
Responsibilities
- Implement and monitor cybersecurity controls in accordance with the Risk Management Framework (RMF) and NIST 800-53.
- Ensure compliance with Department of Defense and Intelligence Community security requirements.
- Review system configurations, audit logs, and security controls.
- Support RMF lifecycle activities and system accreditation.
- Maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and related documentation.
- Coordinate with the Information System Security Manager (ISSM), Authorizing Official (AO), and other stakeholders.
- Perform vulnerability management and patch tracking.
- Analyze ACAS/Nessus scan results and report system risk posture.
- Support incident response activities, audits, and inspections.
- Maintain audit-ready security documentation.
- Support Cross Domain Solutions (CDS) accreditation and compliance.
- Validate CDS configurations and data flows and coordinate with CDS administrators.
- Ensure Security Technical Implementation Guide (STIG) compliance.
- Maintain secure system baselines and review configuration changes.
- Collaborate with engineers and administrators on secure system design.
- Provide security guidance for multilevel security (MLS) environments.
Required Qualifications
- 8 years of cybersecurity or ISSO experience in classified environments.
- Experience with RMF and NIST 800-53.
- Familiarity with STIGs and vulnerability-management tools.
Preferred Qualifications
- Experience in Intelligence Community or Special Access Program (SAP) environments.
- Familiarity with eMASS.
- Scripting experience with Python, PowerShell, or Bash.
- Bachelor's degree or equivalent experience.
Skills
Rmf, Nist 800-53, Stigs, Acas, Nessus, Emass, Python, PowerShell, Bash, Cross Domain Solutions, Vulnerability Management, Incident Response
Similar jobs
Security Engineering jobsLeads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.