Information System Security Officer (ISSO) Job at GDIT, McLean, VA

NDM2cVVORjgzcUVXc0NDQndqYWxxLzNQdFE9PQ==
  • GDIT
  • McLean, VA

Job Description

Responsibilities for this Position

Location: USA VA McLean
Full Part/Time: Full time
Job Req: RQ208798

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
Assessment & Authorization (A&A), Continuous Monitoring, Security Audit, Security Compliance Assessment
Certifications:
None
Experience:
9 + years of related experience
US Citizenship Required:
Yes

Job Description:

CYBERSECURITY ARCHITECT SR PRINCIPAL

We are seeking a highly skilled and multi-faceted Information System Security Officer (ISSO) for a critical contract role supporting this commercial Cloud Service Provider's mission-critical systems. The ideal candidate is a proactive and seasoned professional with extensive, hands-on experience navigating the FedRAMP, DOD Impact Level 6 (IL6), and Risk Management Framework (RMF) requirements for classified commercial cloud services and cross domain solutions. This role requires a unique blend of technical engineering prowess, security assessment and auditing skills, deep expertise in continuous monitoring, and the polish to communicate risk to executive leadership. You will be a key contributor to our Governance, Risk, and Compliance (GRC) program, supporting the Information System Security Manager (ISSM) in ensuring the unyielding security and integrity of mission-critical systems.

The ISSO will be directly responsible for the following key areas:
1. RMF & Assessment and Authorization (A&A)
  • Lead A&A Execution: Shepherd complex cloud service offerings, and Cross Domain Solutions (CDS) as needed, through the entire respective FedRAMP/DOD IL6 and RMF lifecycle to obtain and maintain the applicable authorizations. This includes classified accreditations adhering to regulations like Raise the Bar (RTB) for CDS systems.
  • Documentation Mastery: Develop, author, and maintain a comprehensive body of evidence for A&A packages. This includes the FedRAMP/DOD IL6 authorization package and appendices, the DOD CDS authorization package requirements, and the IC joint test team authorization package requirements.
  • Continuous Monitoring & POAM Management: Take full ownership of the monthly and overall FedRAMP/DOD IL6, DOD CDS, and IC Continuous Monitoring requirements.
  • Compliance & Policy Adherence: Act as the primary technical interpreter of security requirements/controls, ensuring all network solutions and system architectures strictly adhere to mandates such as ICD 503, NIST SP 800-53, CNSSI 1253, and all applicable DISA STIGs and SRGs.

2. Security Engineering & System Hardening
  • Technical Security Integration: Review system designs, network architectures, and proposed changes to ensure security principles are integrated from the ground up.
  • System Hardening & Configuration: Work with security engineering to implement and validate security controls, to ensure STIGs applied to operating systems, network devices, and applications.
  • Vulnerability Management: Work with security engineering to proactively identify and assess vulnerabilities using tools like Tenable Nessus. Work with system administrators to prioritize and track remediation efforts, ensuring compliance with established timelines.
  • Network Security & Architecture Review: Conduct in-depth firewall rule reviews, analyze network architecture for security flaws, and manage Ports, Protocols, and Services Management (PPSM) submissions in alignment with Continuous Monitoring activities.

3. Security Control Assessor (SCA) & Auditing
  • Security Audits & Inspections: Conduct comprehensive security control audits, traditional security reviews, and formal inspections, including preparing for and executing FedRAMP/IL6 third-party assessment organization (3PAO) assessments, DOD CDS assessments, and IC assessments. (Potential to support DCSA classified space assessments.)
  • Artifact & Evidence Review: Meticulously review artifacts, logs, and system configurations to ensure they provide sufficient evidence of compliance. Audit the work of ISSEs and system administrators to verify documentation and security posture.
  • Penetration Testing & Validation: Coordinate and/or participate in security testing and penetration testing activities to provide an independent validation of the system's security posture.

4. Continuous Monitoring & GRC
  • Develop & Manage ConMon Strategy: Design, implement, and manage a robust continuous monitoring program that provides near real-time insight into the security posture of all accredited systems.
  • Security Data Analysis: Leverage tools like Splunk, Grafana, eMASS, Xacta, and ServiceNow to aggregate, analyze, and report on security data. Identify trends, anomalies, and potential incidents, providing actionable intelligence to the ISSM and leadership.
  • Risk Management: Perform formal risk assessments and analysis, identifying and documenting potential threats and vulnerabilities and recommending mitigating controls.
  • Incident Response Support: Enable the ISSM and the incident response team with artifacts, providing in-depth system knowledge and security expertise during incident handling and analysis.

WHAT YOU'LL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The Cybersecurity Architect Sr Principal must have:

Education: BA/BS Degree or equivalent experience in lieu of degree
Experience: 10+ years of related experience

Technical skills: Progressive experience in information assurance and cybersecurity roles. A minimum of 5 years of direct, hands-on experience as an ISSO or ISSM, with a proven track record of successfully achieving and maintaining ATO for multiple classified systems under IL6, DoD RMF, and/or ICD 503 policies.

Security clearance level: Must be a U.S. Citizen. Must possess a current and active Top Secret (Sensitive Compartmented Information [SCI] eligibility). Additionally, personnel agree to be submitted for Full-Scope Polygraph (FSP) for potential hands-on, independent activities. However, requirement is Top Secret, and if FSP cannot be adjudicated, personnel will not be impacted and will continue to work on activities where the FSP was never required.

Location: Onsite at the classified operations center in McLean, VA.

Role requirements: Expert-level knowledge of the complete NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles.

Certifications: Must be DoD 8140 / 8570.01-M compliant. A CISSP (Certified Information Systems Security Professional) is strongly preferred and considered the baseline.

Desired:
  • Hands-on experience with security and GRC tools such as ACAS (Tenable.sc/Nessus), Splunk, Grafana, ServiceNow, eMASS, and Xacta.
  • Deep understanding of network architecture, firewall configurations, and the PPSM process.
  • Understanding of Microsoft Active Directory and implementing controls via Group Policy.
  • CDS authorization processes and policies of the Intelligence Community (IC), Department of Defense (DoD), and SLED entities.

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

The likely salary range for this position is $157,250 - $212,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
None

Telecommuting Options:
Onsite

Work Location:
USA VA McLean

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans



PI278929301




CYBERSECURITY ARCHITECT SR PRINCIPAL


We are seeking a highly skilled and multi-faceted Information System Security Officer (ISSO) for a critical contract role supporting this commercial Cloud Service Provider's mission-critical systems. The ideal candidate is a proactive and seasoned professional with extensive, hands-on experience navigating the FedRAMP, DOD Impact Level 6 (IL6), and Risk Management Framework (RMF) requirements for classified commercial cloud services and cross domain solutions. This role requires a unique blend of technical engineering prowess, security assessment and auditing skills, deep expertise in continuous monitoring, and the polish to communicate risk to executive leadership. You will be a key contributor to our Governance, Risk, and Compliance (GRC) program, supporting the Information System Security Manager (ISSM) in ensuring the unyielding security and integrity of mission-critical systems.


The ISSO will be directly responsible for the following key areas:
1. RMF & Assessment and Authorization (A&A)

  • Lead A&A Execution: Shepherd complex cloud service offerings, and Cross Domain Solutions (CDS) as needed, through the entire respective FedRAMP/DOD IL6 and RMF lifecycle to obtain and maintain the applicable authorizations. This includes classified accreditations adhering to regulations like Raise the Bar (RTB) for CDS systems.
  • Documentation Mastery: Develop, author, and maintain a comprehensive body of evidence for A&A packages. This includes the FedRAMP/DOD IL6 authorization package and appendices, the DOD CDS authorization package requirements, and the IC joint test team authorization package requirements.
  • Continuous Monitoring & POAM Management: Take full ownership of the monthly and overall FedRAMP/DOD IL6, DOD CDS, and IC Continuous Monitoring requirements.
  • Compliance & Policy Adherence: Act as the primary technical interpreter of security requirements/controls, ensuring all network solutions and system architectures strictly adhere to mandates such as ICD 503, NIST SP 800-53, CNSSI 1253, and all applicable DISA STIGs and SRGs.



2. Security Engineering & System Hardening

  • Technical Security Integration: Review system designs, network architectures, and proposed changes to ensure security principles are integrated from the ground up.
  • System Hardening & Configuration: Work with security engineering to implement and validate security controls, to ensure STIGs applied to operating systems, network devices, and applications.
  • Vulnerability Management: Work with security engineering to proactively identify and assess vulnerabilities using tools like Tenable Nessus. Work with system administrators to prioritize and track remediation efforts, ensuring compliance with established timelines.
  • Network Security & Architecture Review: Conduct in-depth firewall rule reviews, analyze network architecture for security flaws, and manage Ports, Protocols, and Services Management (PPSM) submissions in alignment with Continuous Monitoring activities.



3. Security Control Assessor (SCA) & Auditing

  • Security Audits & Inspections: Conduct comprehensive security control audits, traditional security reviews, and formal inspections, including preparing for and executing FedRAMP/IL6 third-party assessment organization (3PAO) assessments, DOD CDS assessments, and IC assessments. (Potential to support DCSA classified space assessments.)
  • Artifact & Evidence Review: Meticulously review artifacts, logs, and system configurations to ensure they provide sufficient evidence of compliance. Audit the work of ISSEs and system administrators to verify documentation and security posture.
  • Penetration Testing & Validation: Coordinate and/or participate in security testing and penetration testing activities to provide an independent validation of the system's security posture.



4. Continuous Monitoring & GRC

  • Develop & Manage ConMon Strategy: Design, implement, and manage a robust continuous monitoring program that provides near real-time insight into the security posture of all accredited systems.
  • Security Data Analysis: Leverage tools like Splunk, Grafana, eMASS, Xacta, and ServiceNow to aggregate, analyze, and report on security data. Identify trends, anomalies, and potential incidents, providing actionable intelligence to the ISSM and leadership.
  • Risk Management: Perform formal risk assessments and analysis, identifying and documenting potential threats and vulnerabilities and recommending mitigating controls.
  • Incident Response Support: Enable the ISSM and the incident response team with artifacts, providing in-depth system knowledge and security expertise during incident handling and analysis.



WHAT YOU'LL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The Cybersecurity Architect Sr Principal must have:


Education: BA/BS Degree or equivalent experience in lieu of degree
Experience: 10+ years of related experience


Technical skills: Progressive experience in information assurance and cybersecurity roles. A minimum of 5 years of direct, hands-on experience as an ISSO or ISSM, with a proven track record of successfully achieving and maintaining ATO for multiple classified systems under IL6, DoD RMF, and/or ICD 503 policies.


Security clearance level: Must be a U.S. Citizen. Must possess a current and active Top Secret (Sensitive Compartmented Information [SCI] eligibility). Additionally, personnel agree to be submitted for Full-Scope Polygraph (FSP) for potential hands-on, independent activities. However, requirement is Top Secret, and if FSP cannot be adjudicated, personnel will not be impacted and will continue to work on activities where the FSP was never required.


Location: Onsite at the classified operations center in McLean, VA.


Role requirements: Expert-level knowledge of the complete NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles.


Certifications: Must be DoD 8140 / 8570.01-M compliant. A CISSP (Certified Information Systems Security Professional) is strongly preferred and considered the baseline.


Desired:

  • Hands-on experience with security and GRC tools such as ACAS (Tenable.sc/Nessus), Splunk, Grafana, ServiceNow, eMASS, and Xacta.
  • Deep understanding of network architecture, firewall configurations, and the PPSM process.
  • Understanding of Microsoft Active Directory and implementing controls via Group Policy.
  • CDS authorization processes and policies of the Intelligence Community (IC), Department of Defense (DoD), and SLED entities.



GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace


OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.


The likely salary range for this position is $157,250 - $212,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.



Scheduled Weekly Hours:
40



Travel Required:
None



Telecommuting Options:
Onsite



Work Location:
USA VA McLean



Additional Work Locations:



Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.


We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.


Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc .


Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans







PI278929301

Job Tags

Full time, Contract work, Temporary work, Part time, Immediate start, Remote work, Worldwide, Flexible hours,

Similar Jobs

Pearl Smile Dental

Dental Receptionist Job at Pearl Smile Dental

 ...and clean on a daily basis. What Must You Have to Be Part Of The Team?~ High School Diploma or equivalent. ~6 + months of dental front office experience. ~ Digital practice software experience (Dentrix). ~ Familiarity with general dental terminology. ~ Flexibility... 

Petco

Groomer Job at Petco

 ...Location Belton, MO : Create a healthier, brighter future for pets, pet parents and people! If you want to make a real difference,...  ...Position Purpose: Responsible to deliver pet parent service and grooming services to our pet parents and the pets in our care that align... 

HaHa App

Social Media Manager Job at HaHa App

 .... As one of the first marketing hires, you will be responsible for our company's growth and ultimate success. About the Social Media Manager Position Our organization is in need of a talented Social Media Manager to manage our accounts. The Social Media Manager... 

New York State Center for Recruitment & Public Service

Office Assistant 1 Keyboarding (NY HELPS) Job at New York State Center for Recruitment & Public Service

 ...following minimum qualifications: Minimum qualifications for taking the open-competitive Beginning Office Assistant examination: There are no minimum education or experience requirements. For the duration of the NY HELPS Program, this title may be filled via a non-... 

Bednark Studio Inc.

Tool Room Assistant Job at Bednark Studio Inc.

 ...Bednark Studio is seeking a reliable Tool Room Assistant to support our Tool Room Coordinator at our Brooklyn warehouse. This role is ideal...  .... Assist with pickups, deliveries, and loading trucks. Operate company vehicles for material runs. Support teams with...