Information Security Systems Officer (ISSO) - Senior Consultant
On-siteSpringfield, Virginia, United States
Job Summary
Lead design and engineering of secure cloud architectures across AWS, Azure, and hybrid environments while implementing and validating NIST 800-53 security controls. Conduct cloud threat modeling, risk assessments, and architecture reviews to oversee configuration baselines using STIGs, CIS Benchmarks, and SCAP. Drive vulnerability and compliance efforts using ACAS/Nessus and cloud-security posture tools, supporting RMF engineering activities including boundary definition and authorization packages. Integrate cloud-security capabilities such as Sentinel, Splunk, and SIEM logging pipelines, and guide DevSecOps teams on secure CI/CD and infrastructure-as-code validation. Mentor junior staff and act as a technical escalation point for complex cloud engineering issues. Requires an active TS/SCI poly clearance and five years of cybersecurity experience.
Required Qualifications
- Active Top Secret SCI with Polygraph
- US Citizenship
- Bachelor's degree from an accredited university
- Minimum of FIVE (5) years of work experience in cybersecurity or secure systems engineering experience, including cloud architecture
- An ACTIVE and MAINTAINED TS/SCI Poly Federal or DoD security clearance with a (COUNTERINTELLIGENCE (CI) polygraph - OR - FULL SCOPE (FS/FSP) polygraph)
- Strong understanding of security frameworks and compliance standards (e.g., NIST, RMF SP 800-53 Rev 5, DoD 8570)
- Proven experience in designing and implementing enterprise security tools such as SIEM (e.g., Splunk), vulnerability scanners (e.g., Nessus), and endpoint protection platforms (e.g., Crowdstrike)
- Demonstrated ability to lead cross-functional teams and complex technical projects
- Strong analytical and problem-solving skills
- Excellent communication skills with the ability to convey technical concepts to non-technical stakeholders
Desired Qualifications
- Bachelor's degree from an accredited university in Cybersecurity, Information Systems, Computer Engineering, or related technical field
- Master's Degree in relevant cybersecurity or IT field
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Controls (CRISC)
- Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC)
- Certified Information Systems Auditor (CISA)
- Familiarity with scripting or automation (PowerShell, Python, Bash)
- Hands-on experience with network security, cryptography, and/or identity management
- Project Management Professional (PMP) or Scaled Agile Framework (SAFe) certification for managing cybersecurity projects in Agile environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.