Senior Information Systems Security Officer

SAICNewington, VA
Onsite

About The Position

SAIC is seeking a motivated and skilled Senior Information Systems Security Officer (ISSO) to support cybersecurity and compliance activities for mission-critical IT systems on the MAJESTIC Joint Program Office (JPO) Team. In this role, the ISSO will be responsible for implementing, managing, and assessing system security controls to ensure compliance with government regulations, standards, and best practices, including NIST 800-53, RMF, and other federal security policies. The ideal candidate will work closely with system owners, administrators, and cross-functional security teams to assess risks, maintain security postures, and ensure the confidentiality, integrity, and availability of information systems that support the mission. This role requires on-site support in Springfield, VA.

Requirements

  • Experience with NIST 800-53
  • Experience with Risk Management Framework (RMF)
  • Experience developing, maintaining, and assessing System Security Plans (SSPs), POA&Ms, and applicable policies and procedures.
  • Experience implementing and validating security controls.
  • Experience supporting the Accreditation and Authorization (A&A) process.
  • Experience conducting risk assessments and vulnerability analysis.
  • Experience with system hardening for platforms, applications, and networks in compliance with DISA STIGs.
  • Experience with continuous monitoring of systems using tools such as Splunk, ACAS, or SolarWinds.
  • Experience supporting incident response activities.
  • Experience providing cybersecurity awareness training.
  • Experience preparing and delivering security status updates, risk reports, and briefings.
  • Experience developing and maintaining system documentation.

Responsibilities

  • Ensure compliance with Risk Management Framework (RMF) requirements by developing, maintaining, and assessing system security artifacts, including System Security Plans (SSPs), POA&Ms, and applicable policies and procedures.
  • Implement and validate security controls in alignment with NIST 800-53, associated overlays, and system-specific requirements.
  • Support the Accreditation and Authorization (A&A) process, including preparing documentation and achieving and maintaining system Authority to Operate (ATO) status.
  • Conduct risk assessments and vulnerability analysis, identify potential threats and weaknesses, and provide recommendations for mitigation.
  • Work with IT teams to implement system hardening for platforms, applications, and networks in compliance with DISA STIGs and cybersecurity best practices.
  • Perform continuous monitoring of systems using tools such as Splunk, ACAS, or SolarWinds, ensuring real-time threat detection, event notifications, and security compliance validation.
  • Collaborate with cross-functional teams, including system administrators, developers, and ISSMs, to address security risks, system vulnerabilities, and security incidents.
  • Support incident response activities by conducting forensic analysis, generating reports, and coordinating efforts to remediate and recover from security events.
  • Provide cybersecurity awareness training for users and team members to ensure adherence to organizational security requirements and best practices.
  • Prepare and deliver security status updates, risk reports, and briefings to senior stakeholders and leadership.
  • Develop and maintain system documentation, including security control implementation descriptions, policies, and SOPs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service