Amentum

Information System Security Officer Senior (ISSO)

Amentum$150K — $165K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years as an Information Systems Security Officer or similar role in complex organizations.
  • In-depth knowledge of information security principles and best practices.
  • Familiarity with ISO 27001, NIST, HIPAA regulations.
  • Experience with risk assessments and security controls implementation.
  • Proficiency in using security tools like SIEM and intrusion detection systems.
  • Strong problem-solving skills for identifying and addressing security gaps.
  • Knowledge of incident response procedures.

Responsibilities

  • Advise the Information System Owner and CISO/ISSM on security matters.
  • Implement and maintain security controls for information systems.
  • Direct necessary controls to protect information system assets.
  • Guide physical protection of information systems to functional units.
  • Report on data security effectiveness and recommend improvements.
  • Assist with ATO accreditation documentation process.
  • Develop and manage POAMS based on vulnerability data.

Benefits

  • Health, dental, and vision insurance.
  • Paid time off and holidays.
  • Retirement benefits including 401(k) matching.
  • Educational reimbursement.
  • Parental leave.
  • Employee stock purchase plan.
  • Tax-saving options.
  • Disability and life insurance.
  • Pet insurance.
Full Job Description
Purpose and Impact:

Amentum is searching for a Top-Secret cleared ISSO to join our team in Washington, DC. You will be working in an organization that's mission is to accelerate operations through data and new analytical insights. The entire section leverages agile and works to provide enhanced reporting and global searching capabilities to facilitate task management, cross-utilization, and address national intelligence priorities while protecting confidential data and sources.

You will be responsible for technical information assurance engineering efforts with network/server scanning, patching, mitigation, and compliance cross-checking of target network assets. Experience in ST&E process and POAM generation. You will need a strong understanding of approved COTS security analyst tools and government mitigation/compliance checkers. You will need a strong comprehension of FISMA, DIACAP, NIST-800 SPs and DCID 6/3 standards and policy control grouping. You will need experience determining products to meet client needs and presenting results.

Work Schedule: Typically, Monday through Friday 8-hour days onsite. Flexibility within a 2-week pay period to reach 80 hours.

Essential Responsibilities:

Serves as the principal advisor to the Information System Owner (SO), Business Process Owner, and the Chief Information Security Officer (CISO) / Information System Security Manager (ISSM) on all matters, technical and otherwise, involving the security of an information system. ISSOs are responsible for ensuring the implementation and maintenance of security controls. Directs and implements the necessary controls and procedures to cost-effectively protect information systems assets from intentional or inadvertent modification, disclosure, or destruction. Provides guidance and direction for the physical protection of information systems assets to other functional units. Provides reports to superiors regarding effectiveness of data security and makes recommendations for the adoption of new procedures. Assist with reviewing, developing, and navigating the system, team, and customer through the Authority to Operate (ATO) accreditation/certification documentation process. Perform network self-inspections. Create new and edit existing documentation that forms the Authority to Operate (ATO) package to include the System Security Plan and IS contingency plan. Develop Plan of Action and Milestone (POAMS) from vulnerability data and enter into the system of record.

Possesses and applies a comprehensive knowledge across key tasks and high impact assignments. Plans and leads major technology assignments. Evaluates performance results and recommends major changes affecting short-term project growth and success. Functions as a technical expert across multiple project assignments. May supervise others. Minimum of 8 years' experience recommended. In absence of years of experience, certifications or past work may be used to show the level of experience needed to perform at this level.

Minimum Requirements (Knowledge, Skills, and Abilities):
  • Minimum of 7 years of experience collectively with the following:
    • Proven work experience as an Information Systems Security Officer or a similar role, preferably in a complex organizational setting.
    • In-depth knowledge of information security principles, methodologies, and best practices.
    • Familiarity with industry standards and regulations (e.g., ISO 27001, NIST, HIPAA, etc.).
    • Experience in conducting risk assessments and implementing security controls.
    • Experience with Risk Management Framework (RMF), ICD 503, NIST SP800-53 or DCID 6/3
    • Proficiency in using security tools and technologies, such as firewalls, intrusion detection systems, SIEM, and vulnerability management tools.
    • Strong analytical and problem-solving skills to identify security gaps and develop effective mitigation strategies.
    • Knowledge of incident response procedures
    • Documented and demonstrated experience with troubleshooting and problem solving
    • Documented and demonstrated experience as an individual consultant or a team lead
    • Familiarity with the ATO process


Security Clearance Required:
  • Active Top-Secret clearance with SCI eligibility


Minimum Education:
  • Bachelor's degree in Information Systems Engineering, Computer Science, Engineering, Business or other related field.
  • In absence of degree, additional years of experience may be substituted for educational requirements


Minimum Years of Experience:
  • Minimum of 8 years of experience


Required Certifications:
  • Cloud Practitioner Certification (or similar)


Preferred Qualifications:
  • Development Tools:
    • Git source version control
    • Google DevOps project management
    • Static Application Security Testing (SAST, e.g. SonarQube, Gitlab SAST)
    • Unit and integration testing (e.g., xunit, nunit)
    • Automated testing
    • End-to-end testing (e.g., Selenium, Cucumber)
  • Platforms:
    • Attribute and role-based access control paradigms (ABAC/RBAC)
    • Windows Service Fabric
    • Splunk administration
    • Windows and Linux server administration
  • Business Analysis and Project Management:
    • Agile Principles
    • DevOps
  • Splunk, JIRA, Confluence, Nessus
  • Strong Excel experience
  • Experience with major Cloud Services
  • Experience implementing, reviewing, and providing recommendations on Cloud Security configurations
  • Experience with Microsoft Windows Server and Linux
  • Cloud Associate Level or above Certification(s)


#javelin

This position is not designated as a safety sensitive position.

Other Responsibilities:

Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.

Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.

Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job.

Compensation Details:
US:$150,000 - $165,000

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.

Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:
  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance


Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Original Posting:
08/12/2026 - Until Filled
Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

About Amentum

Amentum is a leading provider of engineering and technical services to the U.S. government and commercial customers worldwide. The company offers a wide range of services, including environmental remediation, facilities management, and logistics and supply chain management, among others. Amentum has a global presence, with operations in over 20 countries, and serves a diverse range of customers, including the Department of Defense, the Department of Energy, and the Department of State. The company is committed to providing high-quality services and has a strong reputation for technical expertise, innovation, and customer satisfaction.
Learn more about Amentum
Size
20,000 employees
Industry
Net Income
$200 million
Founded
2014
Revenue
$5 billion

Similar Jobs

More Jobs at Amentum

More Education, Government & Non-Profit Jobs

Find similar Information System Security Officer Senior (ISSO) jobs: