Guidehouse logo
GuidehousePosted 2 weeks ago

Information Security Systems Officer (ISSO) - Senior Consultant

On-siteSpringfield, Virginia, United States

Full TimeSenior LevelBachelors DegreeLarge

Job Summary

Lead design and engineering of secure cloud architectures across AWS, Azure, and hybrid environments while implementing and validating NIST 800-53 security controls. Conduct cloud threat modeling, risk assessments, and architecture reviews to oversee configuration baselines using STIGs, CIS Benchmarks, and SCAP. Drive vulnerability and compliance efforts using ACAS/Nessus and cloud-security posture tools, supporting RMF engineering activities including boundary definition and authorization packages. Integrate cloud-security capabilities such as Sentinel, Splunk, and SIEM logging pipelines, and guide DevSecOps teams on secure CI/CD and infrastructure-as-code validation. Mentor junior staff and act as a technical escalation point for complex cloud engineering issues. Requires an active TS/SCI poly clearance and five years of cybersecurity experience.

Required Qualifications

  • Active Top Secret SCI with Polygraph
  • US Citizenship
  • Bachelor's degree from an accredited university
  • Minimum of FIVE (5) years of work experience in cybersecurity or secure systems engineering experience, including cloud architecture
  • An ACTIVE and MAINTAINED TS/SCI Poly Federal or DoD security clearance with a (COUNTERINTELLIGENCE (CI) polygraph - OR - FULL SCOPE (FS/FSP) polygraph)
  • Strong understanding of security frameworks and compliance standards (e.g., NIST, RMF SP 800-53 Rev 5, DoD 8570)
  • Proven experience in designing and implementing enterprise security tools such as SIEM (e.g., Splunk), vulnerability scanners (e.g., Nessus), and endpoint protection platforms (e.g., Crowdstrike)
  • Demonstrated ability to lead cross-functional teams and complex technical projects
  • Strong analytical and problem-solving skills
  • Excellent communication skills with the ability to convey technical concepts to non-technical stakeholders

Desired Qualifications

  • Bachelor's degree from an accredited university in Cybersecurity, Information Systems, Computer Engineering, or related technical field
  • Master's Degree in relevant cybersecurity or IT field
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Controls (CRISC)
  • Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC)
  • Certified Information Systems Auditor (CISA)
  • Familiarity with scripting or automation (PowerShell, Python, Bash)
  • Hands-on experience with network security, cryptography, and/or identity management
  • Project Management Professional (PMP) or Scaled Agile Framework (SAFe) certification for managing cybersecurity projects in Agile environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce