Senior Information Systems Security Officer

Summary

Senior ISSO supporting system accreditation (BOE documentation, controls, POAMs), conducting vulnerability scans, and maintaining security configurations on-site in Washington, D.C., using tools like Tenable Nessus, IBM Guardium, HP WebInspect, and NMAP.

MANTECH seeks a motivated, career and customer-oriented Senior Information Systems Security Officer (ISSO) to join our team in Washington, D.C. This is an on-site position.


The Senior ISSO will leverage their strong technical background and knowledge to support accreditation efforts, to include creating Body of Evidence (BOE) documentation, responding to/implementing/documenting required controls, and completing required tasks and actions.


Responsibilities Include but are not limited to:

  • Create, update, maintain, and interpret required Body of Evidence (BOE) documentation to navigate system accreditation processes.

  • Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of system security configurations and practices.

  • Conduct required vulnerability scans, review reports to identify vulnerabilities, and perform comprehensive vulnerability analysis.

  • Develop, oversee, and track Plans of Action and Milestones (POAMs) to effectively mitigate discovered security risks.

  • Coordinate with system owners, ISSMs, and team resources to diagnose operational issues and implement necessary technology solutions.

  • Document and implement plans detailing security postures, proper configurations, and secure remote access capabilities for applications.

Minimum Qualifications:

  • 10 + years of related information systems security experience, or a Master's degree with 7 + years of experience.

  • Bachelor's Degree or equivalent (6 additional years of experience).

  • Must possess one or more relevant industry certifications: Certified Information Systems Security Professional (CISSP), Certified Information Systems Security Manager - Informatin System Security Management Professional (CISSP-ISSMP), Certified Information Security Manager (CISM), Federal IT Security Professional - Manager (FITSP-M), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), Global Industrial Cyber Security Professional (GICSP), or GIAC Security Leadership (GSLC).

  • Significant experience navigating technical accreditation processes, meeting strict security requirements, and creating A&A Body of Evidence (BOE) documentation.

  • Familiarity operating standard security and discovery tools including Tenable Nessus, Security Center, IBM Guardium, HP WebInspect, and Network Mapper (NMAP).

  • Proven experience managing complex network documentation, inventorying networks, and working across large technical teams to drive a standardized security agenda.

Preferred Qualifications:

  • Cloud Certification.

  • Hands-on experience utilizing cyber risk and compliance automation tools.

Clearance Requirements:

  • Current/Active TS/SCI Required.

  • Ability to obtain and maintain a polygraph.

Physical Requirements:

  • Must be able to remain in a stationary position 50% of the time.

  • Needs to occasionally move about inside the office to access file cabinets, office machinery, and other equipment.

  • Frequently communicates with co-workers, management, and customers, which may involve delivering presentations.

  • Must be able to exchange accurate information in these situations.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available