Senior Information Systems Security Officer (ISSO) Category: Cyber Security
Main location: United States, Virginia, Fairfax
Position ID:J0826-1418
Employment Type: Full Time
Position Description: This is an opportunity to join a fast growing team of information security experts as we transform, enhance, and expand the security program for one of the largest IT providers in the world. You will support the Federal Solutions Group, including governance, risk, and compliance consulting services as well as security service delivery across one or more US based industries. The successful candidate will have broad knowledge of current security practices as well as the ability to identify and apply legal, regulatory, and industry specific security requirements. As the threat landscape evolves, this role also requires a forward embracing approach to integrating AI driven security capabilities-leveraging automation, intelligent analytics, and emerging technologies to stay ahead of sophisticated adversaries and strengthen our clients' resilience. You will help our clients define and deploy effective security solutions and strategies while addressing ever changing regulatory and industry compliance challenges. You must be able to collaborate with a variety of technical and management disciplines, including infrastructure and security architecture, security operations, application development, project managers, product owners, and others.
This position is located in our Fairfax, VA, or Lafayette, LA, office; however, a hybrid working model is acceptable.
Your future duties and responsibilities: The responsibilities of the Information Systems Security Officer include, but are not limited to supporting the Information System Security Manager in the following:
. Maintaining operational security posture for an information system or program to ensure information systems security design, implementation, management and review of policies, standards, baselines, procedures, and guidelines are established and followed. Understand business functions to help ensure business is conducted as securely as possible.
. Creating and reviewing documentation to support Systems Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and Client Responsibility Matrices (CRM).
. Identifying, managing, and monitoring POA&Ms, assisting Business Units or clients in improving the quality and effectiveness of their POA&Ms. Provide guidance through remediation as well as develop corrective action plans for each POA&M.
. Using Artificial Intelligence (AI) and applying security concepts around AI.
Required qualifications to be successful in this role: . Bachelor's degree or 8 years of relevant experience
. Experience with Cyber Information Security Analysis
. Experience with FedRAMP and/or NIST compliance
. Experience with cloud security for AWS environments
. Demonstrated understanding of how AI and machine learning technologies impact modern security architectures, including associated risks, threat vectors, and mitigation strategies.
. Familiarity with emerging AI related guidance from NIST (e.g., AI Risk Management Framework) and its application to federal systems.
. Capability to advise stakeholders on responsible adoption of AI in security operations, including automation opportunities and guardrails for safe deployment.
. Experience with web application scanning tools and translating results into actionable tasks
. Experience with network architecture concepts, common ports and protocols, and network monitoring tools
. Experience with writing clear and concise technical documents, specifically policies, processes, and procedural documentation
. Experience with cloud native security tools
. Experience with container security tools
. Experience incorporating AI into existing security
. Organizational skills and the ability to work autonomously with attention to detail and processes
. Experience with NIST 800 53 Rev 5 Agency ATO process and documentation
. Direct experience with Certification and Accreditation techniques and methodologies
Desired qualifications/non essential skills required:
. Security+, CISSP, CISM, or similar level of certification
. Experience working with Google cloud (GCP)
. Experience with Gemini
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $71,700.00 $176,300.00.
CGI Federal's benefits are offered to eligible professionals on their first day of employment to include:
. Competitive compensation
. Comprehensive insurance options
. Matching contributions through the 401(k) plan and the share purchase plan
. Paid time off for vacation, holidays, and sick time
. Paid parental leave
. Learning opportunities and tuition assistance
. Wellness and Well being programs
#CGIFederalJob
#LI JK6
Skills: - Information Security Mngt(ISM)
- IT Security
- Security Analysis
- Security Architecture
- Threat Risk Assessment