Quick Overview
Job Description
In today's rapidly evolving cyber security landscape, new and more dangerous threats are emerging daily, and vulnerabilities are being exploited almost as fast as they are discovered. The previous mindset of designing solutions, developing software, building environments, and then applying security is totally inadequate in the face of today's realities.
Agencies and programs must focus less on "What do we have to do to get an Authorization to Operate (ATO)?" and more on "What must we do to keep the data, systems, services, and resources within our boundary protected to the fullest extent possible while successfully serving the mission?" Adopting a "Cyber Security First and Continuously; Mission Always" approach will lead naturally to ATOs. The safety of our country, people, warfighters, and vital information depends on it.
As an Information Systems Security Officer (ISSO) and Cyber Security Subject Matter Expert, you will serve as a critical bridge between high-level security policies and their technical implementation, driving the Risk Management Framework (RMF) and Assessment & Authorization (A&A) lifecycle across multiple applications and environments.
Your primary purpose is to ensure that system designs and implementations inherently meet rigorous security objectives by evaluating IT architectures, guiding development teams, and enforcing compliance with NIST SP 800-53 Rev 5 and other enterprise standards from concept to deployment. In this role, your work directly safeguards mission-critical systems and reduces organizational risk. By proactively identifying, tracking, and mitigating vulnerabilities through continuous monitoring, STIG enforcement, and POA&M management, you ensure the resilience of enterprise capabilities.
Your leadership in disaster recovery planning and IAVA compliance empowers engineers and developers to securely deliver operations, ultimately protecting the integrity and availability of our technological infrastructure.
Work Schedule: Work hours are 9am - 5pm, Monday thru Friday, at least four days at customer or Amentum site.
Essential Responsibilities
- Working with Security, Operations, and Development teams to gather information about all the systems, software, components, access permissions, and data flows that are part of the GEODS environments as well as the types of data that are input, manipulated, stored, and output from the authorization boundary.
- Documenting this information to create the Body of Evidence artifacts required as part of our Assessment and Authorization (A&A) packages and to maintain the artifacts as systems evolve.
- Reviewing reports and scan results to identify vulnerabilities and settings not configured in compliance with applicable DISA STIGs and create patching and remediation plans to protect systems in accordance with Agency requirements.
- Documenting clear justifications and exception statements when patching or configuration requirements cannot be met due to adverse functional or performance consequences.
- Building good working relationships within the GEODS teams and with agency A&A personnel to understand expectations and deliver required artifacts within prescribed timelines.
- Updating information in Service+ including CMDB Inventory information and Service Tickets. Work Environment, Physical Demands, and Mental Demands: Most work will be done at a desk or computer.
Minimum Requirements (Knowledge, Skills, and Abilities): Skills & Tasks -
- Extensive knowledge of all applicable compliance requirement documents, such as NIST SP 800-53 REV 5, CNSSI 1253 and Overlays, DISA Security Technical Implementation Guides (STIGs), and Zero Trust.
- Experience with Windows Server, Red Hat Enterprise Linux Server, and Oracle Linux Server Operating Systems, including vulnerability patching methodologies.
- Experience with Amazon Web Services (AWS) and Oracle Cloud environments and administration interfaces (e.g., CAP Tool).
- Experience with XACTA 360, manually entering as well as importing/exporting information including Security Control Implementation responses, test plans, self-assessments, and other required Body of Evidence documentation.
- Analyzing large amounts of data, such as Cloud Inventory reports and Nessus ACAS Security Center IAVM and STIG scan results across multiple instances and environments.
- Producing clear, consistent documentation describing the status of all systems, software, and other components within the authorization boundary, as well communicating the procedures used to develop custom code, perform regular operational support of the system, and recover systems/services from disasters.
- Essential skills needed:
- Attention to detail
- Critical thinking
- Creative problem solving
- Flexibility and ability to pivot quickly between multiple tasks
- Strong work ethic Job Duties
- Gathering situational awareness information of all data and components within the authorization boundary and creating Body of Evidence documentation, such as Concepts of Operations (CONOPs), Control Implementation Plans, Test Plans, Operational Procedures, and Data Flow Diagrams.
- Ensuring all program systems, software, and services comply with all applicable:
- Cyber Security Controls and Overlays
- Best practices and Development frameworks
- STIG configurations/Vendor Security Guides
- Enterprise Security Services (e.g., CRIBL, Trellix, Carbon Black, etc.)
- Performing regular analysis and self-assessments, such as:
- Reviewing and analyzing vulnerability scans (e.g., ACAS IAVM scans, Static and Dynamic Code Scans)
- Performing manual test plan checks
- Documenting non-compliance
- POA&Ms
- Justifications
- Disaster Recovery/Incident Response
- Supporting Assessment and Authorization activities:
- Completing all required XACTA 360 sections and tasks
- Verifying all Body of Evidence deliverables
- Providing support with demonstrating A&A Test Plans
- Continuous Monitoring:
- Working with OPS Team to develop patching strategies
- Participating in Development Sprint planning to help support Configuration/Change Management and identify potential Security Relevant Changes
- Evaluating proposed security architectures and designs and providing input to ensure they meet required security compliance objectives
- Suggesting strategies to improve cyber security posture throughout the development lifecycle and to gain efficiencies Security Clearance Required: TS/SCI CI Poly Minimum Education: Bachelor's degree plus 10 years' experience, associate's degree plus 12 years' experience, or a minimum of 14 years' experience in a related field Required Certifications: CompTIA Security+ (at a minimum)
Preferred Qualifications: AI if applicable to your program
- Prior experience with NGA cyber security A&A processes and procedures highly preferred
- Certified Information Systems Security Professional (CISSP), CompTIA SecurityX (CASP+), CompTIA Security Pro, or other IAT II Certification
- Extensive experience with Cyber Security Framework regulations and best practices, including NIST SP 800-53 Rev 5, ICD 503, CNSSI 1253, Risk Management Framework (RMF)
- NIST SP 800-37 Rev 2, DISA Security Technical Implementation Guides (STIGs)
- Extensive experience with Plans of Action and Milestones (POA&Ms) and knowledge of appropriate corrective actions for unacceptable risks
- Experience with A&A Activities involving Cloud environments, Containers, and Microservices
- Experience with Nessus ACAS Security Center and IAVM/STIG reports
- Experience with XACTA 360
- Applicable software/hardware/management training and certification (e.g., specialties like Amazon Web Service architect/engineering, ServiceNow/Service+) Other Responsibilities: Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams. Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities. Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. #javelin Compensation Details:
Benefits Overview: Our health and welfare benefits are designed to support you and your priorities. Offerings include:
- Health, dental, and vision insurance
- Paid time off and holidays
- Retirement benefits (including 401(k) matching)
- Educational reimbursement
- Parental leave
- Employee stock purchase plan
- Tax-saving options
- Disability and life insurance
- Pet insurance Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (
Similar jobs
- FH
M730-Senior Network Security Engineer (807471)
NewFHR
Farnham, Virginia🇺🇸On-site5 minutes agoMFASplunkActive Directory+3Technology - CR
Network Security Engineer
NewCredence
Mc Lean, Virginia🇺🇸$130k - $155k/yrHybrid35 minutes agoGCPAWSSOC 2+4Technology - TH
FRCS Network Security Engineer
NewTlingit Haida Tribal Business Corporation
Falls Church, Virginia🇺🇸$130k - $140k/yrHybrid35 minutes agoTCP/IPVMwareTechnology - FH
M730-Senior Network Security Engineer
NewFocused HR Solutions
Mechanicsville, Virginia🇺🇸On-site35 minutes agoMFASplunkActive Directory+3Technology - GS
Network Security Engineer
NewGeorgia System Operations Corporation
Tucker, Georgia🇺🇸On-site35 minutes agoLoad BalancingMFAAnsible+5Technology - 2P
Senior Network Security Engineer
New2Bridge Partners
Addison, Texas🇺🇸$150k - $180k/yrRemote35 minutes agoLoad BalancingNginxDNS+3Technology