Skip to content

Senior Information Systems Security Officer

100k – 150kWashington, DCOnsite3+ YOE
Summary

Manage cybersecurity operations and RMF compliance for classified SAP information systems in a DoD environment. Requires 3-5 years of experience and active 8570/8140 certification.

About the role

What you'll do:

  • Manage day-to-day cybersecurity operations for SAP information systems and networks.
  • Ensure compliance with RMF, JSIG, NIST 800-53, ICD 503, and applicable DoD cybersecurity policies.
  • Support system accreditation activities, including authorization packages, POA&Ms, SSPs, and security control assessments.
  • Maintain continuous monitoring activities, including vulnerability management, patch management, configuration management, and audit log reviews.
  • Conduct periodic security audits, inspections, and self-assessments.
  • Coordinate with ISSMs, system administrators, program managers, and government customers to resolve cybersecurity findings and maintain system authorization status.
  • Review and evaluate hardware/software changes for security impact and compliance.
  • Assist with incident response activities, reporting, and remediation efforts.
  • Support account management processes, media control, system access reviews, and privileged user oversight.
  • Ensure cybersecurity documentation remains accurate and current throughout the system lifecycle.
  • Participate in security testing, vulnerability scanning, and remediation tracking.
  • Provide cybersecurity guidance and training to system users and administrators.

Required qualifications:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field; equivalent experience may be substituted.
  • 3-5 years of cybersecurity or information assurance experience.
  • Experience supporting classified or SAP information systems in a DoD environment.
  • Working knowledge of RMF accreditation processes and cybersecurity compliance frameworks.
  • Familiarity with NIST 800-53, JSIG, STIGs, ACAS, SCAP, and related security tools.
  • Experience managing vulnerability remediation and security compliance activities.
  • Strong understanding of Windows and/or Linux operating systems in secure environments.
  • Ability to work independently and manage multiple priorities in a fast-paced environment.
  • Excellent written and verbal communication skills.
  • Active DoD 8570/8140 compliant certification such as Security+, CISSP, CASP+, or equivalent.
Skills
RMFNIST 800-53JSIGSTIGsACASSCAPWindowsLinuxSecurity+CISSPCASP+
Similar roles at this salary range
All Security Engineering jobs →
Reltio

Senior Cloud Security Engineer

Lead cloud security initiatives across AWS, GCP, and Azure. Design and implement security controls, perform risk assessments, and ensure compliance with SOC2, HITRUST, and ISO frameworks.

95k – 203kUnited StatesSecurity EngineeringRemoteAWSGCP
Imagen Technologies

Security Analyst

Security Analyst responsible for managing endpoint security, DLP, SIEM monitoring, incident response, and compliance for a healthcare AI company. Requires 2+ years in security operations or SOC experience.

80k – 90kUnited StatesSecurity EngineeringRemoteSIEMBash
Huntress

Security Operations Analyst

Triage, investigate, and respond to security alerts in a SOC environment. Requires 2+ years SOC/DFIR experience and strong knowledge of Windows, Linux, macOS, malware analysis, and threat actor TTPs.

100k – 125kUnited StatesSecurity EngineeringRemoteEDRAWS
Trail of Bits

Security Engineer, Application Security

Conduct low-level code security assessments, architecture reviews, and threat modeling for client applications. Build custom security tools bridging vulnerability research and application security. Requires manual code review, binary analysis, and programming proficiency in multiple languages.

100k – 200kUnited StatesSecurity EngineeringRemoteCC++
Trail of Bits

Senior Security Engineer, Agentic AI

Senior Security Engineer specializing in Agentic AI Security to discover and exploit novel vulnerabilities in agentic AI systems, develop prompt injection attacks, and conduct security assessments of AI pipelines and frameworks.

100k – 220kUnited StatesSecurity EngineeringRemoteGoJAX