Information Systems Security Officer (ISSO)

2026-171568

CAtegory:

Information Technology

Clearance:

Top Secret/SCI

Location:

Chantilly
,
Virginia

Telecommute:

No remote/telework allowed
About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Program Overview
Cybersecurity experts, Scrum and Agile professionals and engineers (systems, software, network, and cloud reliability) design and sustain cloud infrastructure to host spacecraft command and control systems. Infrastructure as a Service (IaaS), Antenna as a Service (AaaS), Data as a Service (DaaS), and an active Admin Wide Area Network (AWAN) team are provided.
About The Role

Peraton is seeking a Mid-Level Information Systems Security Officer (ISSO) in Chantilly, VA to support our Department of Defense customer as part of a highly talented, highly motivated, and high-performing team. As part of the cybersecurity team, you will support Assessment and Authorization (A&A) activities for information systems operating within a DoD Special Access Program (SAP) environment. The position requires extensive knowledge of the Joint Special Access Program Implementation Guide (JSIG) and demonstrated experience implementing the Risk Management Framework (RMF) throughout the system lifecycle.

 

What you'll do:

  • Support the prepare, categorize, select, implement, assess, authorize, and monitor phases of the RMF lifecycle for information systems operating within a DoD SAP environment.
  • Interpret and apply JSIG policy and guidance to system security requirements, security control implementation, assessment activities, authorization packages, and continuous monitoring.
  • Develop, review, and maintain system security plans (SSPs), security control traceability matrices (SCTMs), plans of action and milestones (POA&Ms), risk assessments, continuous monitoring strategies, contingency plans, incident response plans, and supporting authorization artifacts.
  • Develop and maintain security control implementation statements that accurately describe how technical, operational, and management controls are implemented within the system and its operating environment.
  • Collect, review, and validate technical and nontechnical evidence demonstrating security control implementation and effectiveness.
  • Coordinate security control assessments, authorization activities, periodic reviews, annual assessments, and continuous monitoring activities with system owners, engineers, administrators, assessors, and Authorizing Official (AO) representatives.
  • Support authorization package submissions, assessment preparation, evidence reviews, discrepancy resolution, and responses to Security Control Assessor (SCA) and AO questions.
  • Identify cybersecurity risks, document control deficiencies, recommend corrective actions, and track remediation activities through closure.
  • Develop and maintain POA&Ms containing accurate weakness descriptions, risk determinations, remediation strategies, milestones, scheduled completion dates, and closure evidence.
  • Review vulnerability scan results, DISA Security Technical Implementation Guide (STIG) findings, configuration compliance results, audit records, and other cybersecurity data to determine risk and authorization impact.
  • Review system architectures, network diagrams, data flows, authorization boundaries, hardware and software inventories, ports, protocols, services, external connections, and system interconnections for accuracy and compliance.
  • Evaluate proposed hardware, software, architecture, configuration, service, and interconnection changes to determine cybersecurity, A&A, security control, and authorization boundary impacts.
  • Participate in configuration control boards, engineering reviews, security working groups, technical exchange meetings, and cybersecurity risk discussions.
  • Advise system administrators and engineers on security control implementation, STIG hardening, vulnerability remediation, and authorization requirements.
  • Communicate the system security posture, unresolved weaknesses, operational risks, and recommended mitigation actions to the ISSM and appropriate program leadership.
Qualifications

Required Qualifications:

  • This position requires the candidate to possess a minimum of an active Top Secret with eligibility for SCI clearance; must be able to maintain TS/SCI and SAP access.
  • Bachelor's degree and 5+ years of relevant experience; master's degree and 3+ years of relevant experience; associate degree and 7+ years of relevant experience; or high school diploma and 9+ years of relevant experience. Additional 4 years of relevant experience may be considered in lieu of a degree.
  • Knowledge of A&A activities within a DoD SAP environment and demonstrated experience implementing RMF requirements using the JSIG.
  • Working experience with DoDI 8510.01, NIST Special Publication 800-53, CNSSI 1253, ICD 503, applicable DISA guidance, and related DoD cybersecurity policies.
  • Demonstrated experience developing, reviewing, and maintaining RMF authorization packages, including SSPs, SCTMs, POA&Ms, risk assessments, continuous monitoring documentation, and supporting control evidence.
  • Experience documenting security control implementations, evaluating the sufficiency of implementation evidence, and supporting control validation and assessment activities.
  • Experience supporting security control assessments, authorization decisions, continuous monitoring, annual reviews, and system reauthorization activities.
  • Experience reviewing DISA STIG findings, vulnerability scan results, configuration compliance results, and remediation evidence to determine cybersecurity risk and authorization impact.
  • Ability to evaluate technical and procedural findings, document residual risk, recommend mitigation or risk acceptance actions, and clearly communicate operational and authorization impacts.
  • Use of Windows and Linux operating systems, network security, identity and access management, audit logging, vulnerability management, encryption, and secure configuration practices.
  • Must meet DoD Manual 8140.03 for DoD Cyber Workforce Framework Work Role 722 - Information Systems Security Manager, Intermediate Proficiency Level, or Work Role 541 - Vulnerability Assessment Analyst, Intermediate Proficiency Level, as applicable to the duties of an ISSO.
  • Strong technical writing, documentation management, organizational, analytical, and verbal communication skills, with the ability to collaborate effectively with cybersecurity, program security, engineering, system administration, assessment, and program management personnel.

Desired Qualifications:

  • Current or previous approval to support a DoD SAP.
  • Experience working directly with ISSMs, Security Control Assessors, Authorizing Official representatives, Program Security Officers, Government SAP Security Officers, and system owners.
  • Experience preparing systems and authorization packages for formal SAP cybersecurity assessment activities.
  • Experience with eMASS, Xacta, or another approved governance, risk, compliance, or authorization management platform.
  • Experience with ACAS, Tenable Nessus, Tenable Security Center, SCAP tools, Splunk, HBSS/Trellix, or comparable cybersecurity tools.
  • Experience supporting private cloud, hybrid cloud, virtualized, containerized, or classified enterprise environments.
  • Experience evaluating system interconnections, external services, inherited controls, or cross-domain solutions.
  • Current certification such as Security+, SecurityX, CISSP, CGRC, or another certification recognized under the applicable DoD 8140 qualification matrix.
  • Ability to work independently with minimal supervision while recognizing matters requiring ISSM, assessor, or AO involvement.

Benefits:

Peraton offers enhanced benefits to employees working on this critical National Security program, which include heavily subsidized employee benefits coverage for you and your dependents, 25 days of PTO accrued annually up to a generous PTO cap and eligible to participate in an attractive bonus plan

 

#Metroplex

Details

Target Salary Range: $104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at&nbsp;<a href="https://www.careers.peraton.com/benefits?" target="_blank" rel="noopener">https://www.careers.peraton.com/benefits.

Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.&nbsp;By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity.&nbsp;Use of artificial intelligence (AI) tools of any kind during Peraton interviews is strictly prohibited unless the candidate has obtained prior written authorization. All interview responses must be the candidate&rsquo;s own.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

VIEW
SAVED
JOBS