SAIC

Senior Information System Security Officer

SAIC$160K — $200K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security or related field, or equivalent experience
  • 14+ years of experience in cybersecurity, information assurance, or related areas
  • Expertise in DoD vulnerability assessment tools like eMASS, Nessus, and Splunk
  • Strong understanding of NIST frameworks (e.g., RMF, SP 800-53) and A&A processes
  • Possession of DoD 8140 IAT Level II certification(s) such as CompTIA Security+ or CISSP
  • Willingness to undergo a Polygraph examination and process for Sensitive Compartmented Information access

Responsibilities

  • Conduct continuous monitoring and compliance inspections of security systems
  • Review and communicate findings from security vulnerability scans to stakeholders
  • Report security status to management and provide recommendations
  • Support audits for information systems as required
  • Develop and update key security documentation like System Security Plans and Risk Assessments
  • Review and approve system Change Requests and ensure compliance with security guidelines
  • Execute system audit log reviews using SIEM tools

Benefits

  • Professional mentorship and growth opportunities
  • Dynamic work environment with customer-centric focus
  • Access to advanced tools and technologies for cybersecurity
  • Potential for involvement in high-stakes national security projects
  • Exposure to specialized security practices in the aerospace domain
Full Job Description
Job Description

Description

SAIC is seeking a technical Senior Information System Security Officer (ISSO) to support the company's secure operating facilities in Colorado Springs, CO. The Horizon 2 contract supports the US Space Force. The primary Government customer is Space Systems Command and its Program Offices that oversee the Space Domain Awareness and Combat Power Branches & the Battle Management Command, Control and Communications portfolios.

You will support all facets of SAIC's Information Protection Program at our Colorado Springs location. You will assist the Information Systems Security Manager and provide oversight, guidance, and technical support, on IT and information system security issues affecting the mission of the customer, by implementing common information system security practices, policies, and standards. You will have access to information systems to perform advanced vulnerability and compliance scanning and your background in applying sound and effective Information Assurance security practices, in both Windows and Linux environments, will be the driving force behind the success of our customer missions.

This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the ongoing compliance of systems. Join us in safeguarding the nation's space assets and explore the limitless opportunities that await in this dynamic role. You'll have the invaluable opportunity to be mentored in this role, ensuring not only your professional growth, but also the continued excellence of our operations. You will get to use your strong communication (verbal and written) skills and interpersonal skills in a dynamic customer centric environment, which may require sporadic off-hours support. If this is what you are looking for, keep reading.

Fun stuff you will do on the job:
  • Conduct continuous monitoring and self-inspections of computer systems to ensure security compliance with official guidance and policy directives, and proactively report progress to management, make recommendations for security posture improvements, and ensure systems are ready for audits.
  • Review and interpret security vulnerability scans, communicate their contents to management and technical stakeholders, and push them to remediation.
  • Proactively report security status and concerns to management and make recommendations as appropriate.
  • Participate in and support directorate responses for ongoing information system audits.
  • Develop and update standard government security documentation such as System Security Plans, Contingency Plans, Interconnection Security Agreements, Risk Acceptances/Waivers, Privacy Threshold Analyses, Privacy Impact Assessments, and other ad-hoc documentation as needed.
  • Review and approve/deny relevant system Change Requests as needed.
    Ensure configuration management is appropriate for all Information Systems (IS) software and hardware, in accordance with DoD STIGs (Security Technical Implementation Guides) and industry best practices.
  • Execute system audit log reviews in accordance with established policy requirements using Security Information and Event Management (SIEM) tools such as Splunk, Kibana, etc.
  • Assist creation of new policies/procedures as needed for directorate systems.
  • Support ad-hoc data call and reporting requirements initiated by DHS CIO, CISA and other headquarters offices.

Qualifications

This is You:
  • Bachelor's degree (preferable Information Security related), 14+ years experience (4 years of experience may be used in lieu of degree) with:
    • Cybersecurity, cyber engineering, information assurance, system administration, or equivalent combination to reflect knowledge and experience.
    • The Risk Management Framework, National Institute of Standards and Technology, Committee on National Security Systems cyber security requirements and guidance, and cyber security related risk management methodologies.
    • Expert knowledge and experience using DoD tools and capabilities for vulnerability assessments and compliance reporting (eMASS, XACTA, ACAS, STIGs, Nessus, SCAP, Splunk, etc.).
    • Mastery understanding of the JSIG, ICD 503, NIST Risk Management Framework (RMF), NIST SP 800-53/53A, and CNSSI 1253, and the Assessment & Authorization (A&A) process.
    • Successful participation Information Assurance self-inspections, ATO renewals, and Cybersecurity compliance inspections.
    • Working in a SAP and/or SCI environment.
    • Controlling, labeling, virus scanning, and appropriately transferring data (upload/download) between information systems at varying classification levels.
    • Experience conducting security audits/system assessments of information systems.
    • Possess certification(s) that meet or exceed DoD 8140 IAT Level II requirements (ex. CompTIA Security+, CISSP).
  • Must be willing to be nominated for access to Sensitive Compartment Information and Special Access Programs and willing to consent to a Polygraph examination.
  • Must have an in-scope security background investigation (T5 or SSBI), adjudicated for SCI eligibility and enrolled in the Continuous Evaluation program (if applicable).

You will wow us even more if you have these skills:
  • A masters degree (preferably in cyber security, Information Security or related security studies).
  • Experience with Incident Response and Disaster Recovery Procedures.
  • Experience creating/updating plans, processes, and procedures, in support of system and data security requirements, as well as establishing artifacts required for system certification.
  • Familiarity with virtualized hosting, such as VMware.
  • Extensive training or experience with Windows-based Information Systems with a working knowledge of LINUX operating systems.
  • Understanding of Contractor SAP Security Officer (CSSO) functions, responsibilities, and disciplines (i.e., PERSEC, PHYSEC, facility alarm operations, Security Training and Education, visitor access requests).
  • Program Security responsibilities to include, but not limited to: OPSEC, Program Protection, Personnel Security clearances, Security Training and Education, and Classification management.
  • Working knowledge of COMSEC responsibilities.
  • Have an understanding of DD254s to support government contracts.

Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

About SAIC

Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.
Learn more about SAIC
Size
26,000 employees
Market Cap
$6 billion
Industry
Net Income
$206 million
Founded
1969
5 Year Trend
+10.7%
Revenue
$6.8 billion
NASDAQ

Similar Jobs

More Jobs at SAIC

More Aerospace & Defense Jobs

Find similar Senior Information System Security Officer jobs: