Job Title: Information Systems Security Officer
Job Category: Security
Time Type: Full time
Minimum Clearance Required to Start: Top Secret
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
* * *
Responsibilities:
· Serve as the ISSO for one or more assigned information systems, acting as the liaison between system owners, ISSMs, and the Authorizing Official (AO)
· Support the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
· Prepare, update, and maintain security authorization artifacts, including System Security Plans (SSPs), risk assessments, contingency plans, and Plans of Action and Milestones (POA&Ms)
· Conduct and support periodic security control assessments, vulnerability scans, and audits; track remediation of findings
· Monitor systems for security-relevant events and respond to/report security incidents in accordance with agency policy
· Ensure systems are operated in compliance with NGA, DoD, and IC security policies (e.g., ICD 503, NIST SP 800-53, CNSSI 1253)
· Support configuration management processes, including review of proposed system changes for security impact
· Maintain user access controls, including account management, least privilege, and periodic access reviews
· Support account audits, media protection, and system hardening activities (e.g., STIG compliance)
· Coordinate with the ISSM and government customer to maintain and renew system Authorizations to Operate (ATOs)
· Deliver regular status reports and briefings to program leadership and government stakeholders on the security posture of assigned systems
Qualifications:
Required Qualifications:
· Active Top Secret clearance with the ability to obtain/maintain SCI and polygraph
· DoD 8570/8140 IAM Level II certification (e.g., Security+, CySA+, CAP, or equivalent)
· 3+ years of experience as an ISSO or in a similar cybersecurity role supporting DoD/IC systems
· Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53 controls
· Experience preparing or maintaining security authorization documentation (SSPs, POA&Ms, contingency plans)
· Familiarity with STIGs, ACAS/Nessus scanning, and vulnerability remediation processes
· Strong written and verbal communication skills, with the ability to interface directly with government customers
· Bachelor's degree in a related field or equivalent combination of experience and training
Desired Qualifications:
· Experience supporting NGA or other NGA/IC customer environments specifically
· AWS certification (e.g., AWS Certified Cloud Practitioner or higher) and hands-on experience securing cloud-hosted systems
· Experience with Momentum Financials (Unison/CGI) in a security support or system administration capacity
· CISSP or other DoD 8570 IAM Level III certification
· Experience with Xacta, eMASS, or similar RMF/GRC tools
· Familiarity with container/cloud security practices and continuous ATO (cATO) concepts
· Prior experience supporting a geospatial intelligence, imagery, or mapping-related program
Pay Range:
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
The proposed salary range for this position is:
$75,200-$158,100