Information Systems Security Officer

Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Master’s degree in engineering, computer science, cybersecurity, networking, or programming.
  • 12+ years of technical experience in cybersecurity, information technology, or systems engineering.
  • Proficiency in cloud architecture and security elements, especially with Special Access Programs (SAPs).
  • TS/SCI with CI Polygraph clearance, maintainable throughout employment.
  • Advanced knowledge in secure systems engineering, threat modeling, and system hardening.

Responsibilities

  • Integrate cybersecurity requirements into system architecture and engineering from concept to deployment.
  • Develop and maintain security artifacts, including Security Plans and compliance documentation.
  • Perform security analyses such as threat modeling and vulnerability assessments for system changes.
  • Select and implement security controls following NIST SP 800-53 and other cybersecurity frameworks.
  • Communicate engineering risk assessments and propose mitigation strategies to stakeholders.
  • Manage change requests and assess security implications of proposed modifications.
  • Collaborate with teams to ensure ongoing compliance and remediate vulnerabilities.

Benefits

  • Health insurance and flexible spending accounts.
  • Retirement savings plans with employer contributions.
  • Paid and unpaid time off options.
  • Life and disability insurance programs.
Full Job Description
Overview

The Sea, Land, Air Analysis Group’s mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, US Air Force, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.

 

SPA has an immediate need for an IT Modernization Information Systems Security Engineer.

Responsibilities

 

The Senior Cloud Information Systems Security Engineer (SCISSE) will support the Government Program Manager by integrating cybersecurity requirements into system architecture, design, and engineering activities from concept through deployment. Working across the system lifecycle, the SCISSE will develop and maintain security artifacts, including Security Plans, Security Controls Traceability Matrices, architectural diagrams, and engineering documentation.

Responsibilities include performing security engineering analyses such as threat modeling, vulnerability assessments, and security impact analyses for proposed system changes. The SCISSE will select, tailor, and implement security controls in accordance with NIST SP 800-53, CNSSI 1253, the Joint SAP Implementation Guide, and other applicable cybersecurity frameworks.

To support informed decision-making, the SCISSE will communicate engineering risk assessments, including mitigation strategies, residual risks, and risk-benefit recommendations. The role also encompasses requirements analysis, system design, and integration for complex software applications and collaboration infrastructures.

As part of the configuration management process, the SCISSE will submit and review Change Requests while assessing the security implications of proposed modifications. Additional responsibilities include creating and maintaining information system security documentation, developing Standard Operating Procedures, and providing guidance on active Plans of Action and Milestones (POA&Ms).

The SCISSE will conduct continuous and periodic monitoring of systems, documentation, and operational procedures to ensure ongoing compliance with authorization requirements. Close collaboration with ISSOs, system administrators, and development teams will be essential to remediate vulnerabilities, maintain secure system configurations, and support secure engineering practices.

Working with multiple system owners, the SCISSE will address security-related design and integration requirements for hybrid environments while evaluating cloud technologies in areas such as encryption, identity and access management, boundary protection, logging, and monitoring. The position also supports incident response and forensic activities in coordination with cybersecurity teams and contributes to the development and execution of governance frameworks for managing and authorizing national security systems.

Qualifications

Required Qualifications:

  • Ability to support onsite in Lorton Virginia, up to full-time, based upon the needs of the client
  • Master’s degree in engineering, computer science, cybersecurity, networking, or programming
  • Requires experience working with Special Access Programs (SAPs), along with strong proficiency in cloud architecture and associated security elements
  • Must possess excellent analytical skills with the ability to quantify risk to enterprise systems and assess compliance with security policy, backed by 12+ years of technical experience in cybersecurity, information technology, or systems engineering
  • TS/SCI with CI Polygraph, and the ability to maintain this throughout employment
Advanced knowledge in one or more of the following areas:
  • Secure systems engineering practices, including threat modeling, security architecture design, and/or system hardening
  • Software Development in Java, Python, Ruby and/or C++
  • Linux Expertise
  • Dynamic & Static Application Security Scanning (e.g., OPSWAT, OWASP ZAP, BurpSuite, Fortify
  • Experience with vulnerability management tools (e.g., Tenable, Defender), SIEM technologies, and secure configuration baselines
  • Infrastructure Security Scanning, Vulnerability Scanning (NMAP, Azure Defender, AWS Inspector, ACAS/Nessus)

Certification Requirements in one or more of the following:

  • Information Systems Security Engineering Professional (ISSEP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Advanced Security Practitioner (CASP)
  • GIAC Cloud Security Essentials Certification (GCLD)

Desired Qualifications:

  • Strong oral and written communication Skills.
Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $210,000.00/Yr.

About Systems Planning And Analysis, Inc.

Systems Planning And Analysis, Inc. Careers

Joining Systems Planning And Analysis, Inc. presents an unparalleled opportunity to advance a career in a leading-edge professional environment that is committed to innovation and leadership. This company is renowned for its strategic role in providing integral analysis and planning solutions across various sectors.

Explore Job Opportunities

Systems Planning And Analysis, Inc. offers a variety of job opportunities that cater to a range of skills and experiences. Whether one is a seasoned professional or a recent graduate, there is a position that can fit one's career aspirations and expertise. The company values diversity and strives to create an inclusive culture where every team member can thrive.

Internship Programs

For those starting their career journey, Systems Planning And Analysis, Inc. provides robust internship programs designed to foster growth, enhance skills, and offer real-world experience in a supportive and dynamic environment. Internships are a stepping stone to full-time employment and offer invaluable networking opportunities within the company.

Professional Growth and Development

Commitment to professional growth is a cornerstone of Systems Planning And Analysis, Inc. Employees are encouraged to pursue continuous improvement through various training programs, including leadership development and diversity training. The company supports career advancement with resources and tools that help individuals expand their knowledge and take on new challenges.

Benefits and Culture

Systems Planning And Analysis, Inc. is dedicated to supporting its employees with comprehensive benefits designed to promote a healthy work-life balance. The benefits package includes health, dental, and vision insurance, as well as competitive retirement plans. The company culture is built on a foundation of respect and integrity, fostering an environment where innovation and collaboration are paramount.

Hiring Process

The hiring process at Systems Planning And Analysis, Inc. is designed to be transparent and efficient. Candidates can expect a thorough interview process where they can showcase their skills and learn more about the company's operations and values. Interested candidates are encouraged to submit a detailed resume and cover letter through the Systems Planning And Analysis, Inc. careers page.

Networking and Career Opportunities

Systems Planning And Analysis, Inc. actively encourages its employees to engage in networking within the industry to enhance their career prospects. Regular company events and professional meet-ups provide platforms for employees to connect with industry leaders and peers.

Join the Team

Systems Planning And Analysis, Inc. is continuously searching for passionate, curious, and innovative team players who are ready to make a significant impact. Explore the open positions that match your skills and interests on the Systems Planning And Analysis, Inc. jobs portal.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights that can be put to use today—all from the people who work at Systems Planning And Analysis, Inc.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at Systems Planning And Analysis, Inc.
Learn more about Systems Planning And Analysis, Inc.

Similar Jobs

More Jobs at Systems Planning And Analysis, Inc.

More Information Technology Jobs

Find similar Information Systems Security Officer jobs: