Information Systems Security Officer (Technical ISSO / RMF Assessor)

Posted Yesterday
Be an Early Applicant
3 Locations
In-Office
112K-179K Annually
Senior level
Aerospace • Information Technology • Security • Cybersecurity • Defense
Do the can't be done.
The Role
Develop and validate security controls in DoD RMF environments; author STPs, SCTMs, implementation statements, and ATO documentation. Analyze STIG, ACAS/Nessus, and Splunk findings, manage remediation, maintain RMF artifacts in Xacta or eMASS, and support continuous monitoring, audits, risk assessments, and ATO activities. Collaborate with system owners, engineers, and government stakeholders while providing cybersecurity guidance and incident response support.
Summary Generated by Built In
Responsibilities

Job Summary

We are seeking a highly skilled and technically proficient Information Systems Security Officer (ISSO) with hands-on experience developing, implementing, and validating security controls within DoD RMF environments. This role requires deep technical understanding of NIST SP 800-53 controls, STIG implementation, vulnerability analysis, and the ability to produce assessable, audit-ready security documentation.

The ideal candidate will be confident writing Security Test Procedures (STPs), building Security Controls Traceability Matrices (SCTMs), interpreting ACAS/Nessus scan results, and using Splunk to verify control effectiveness. This ISSO will work closely with system owners, engineers, and government stakeholders to support ATO efforts and continuous monitoring activities.


Duties & Responsibilities:


Core Technical Responsibilities

  • Develop, write, and maintain Security Test Procedures (STPs) for NIST SP 800-53 controls.
  • Create and update Security Controls Traceability Matrices (SCTMs).
  • Draft, review, and refine control implementation statements for all control families.
  • Interpret and remediate STIG/SCAP findings across operating systems, applications, and infrastructure.
  • Conduct and analyze ACAS/Nessus vulnerability scan results; validate findings with engineering teams; track remediation to closure.
  • Perform Splunk log analysis to validate control operation and investigate anomalies.
  • Prepare and update core ATO documentation including SSPs, SARs, POA&Ms, Contingency Plans, Continuous Monitoring artifacts, and other related Body of Evidence (BoE) components.

RMF & Security Lifecycle

  • Lead and support RMF Steps 1–6 for assigned systems.
  • Manage, validate, and maintain control evidence in alignment with NIST SP 800-53 and DoD requirements.
  • Support continuous monitoring activities, including log review, vulnerability assessments, and control re-validation.
  • Coordinate directly with system owners and engineering teams to address security gaps.
  • Ensure system documentation is maintained accurately and entered in tools such as Xacta or eMASS.
  • Provide security guidance for system changes, risk assessments, and configuration updates.

Collaboration & Stakeholder Support

  • Communicate technical risks, findings, and required actions to system owners, government counterparts, and internal leadership.
  • Participate in security meetings, assessments, and audits.
  • Assist with incident response activities as needed, including log review and security control validation.
Qualifications

Required Qualifications

  • Active TS clearance with SCI eligibility OR TS/SCI clearance adjudication with current polygraph OR the ability to pass a polygraph.
  • Bachelor's degree in a relevant technical field with 8+ years of relevant experience, or 12+ years of experience in lieu of a degree.
  • 8+ years of hands-on experience as an ISSO, ISSE, Assessor, Security Engineer, or closely related DoD cybersecurity role.
  • Demonstrated experience writing STPs, creating SCTMs, and developing implementation statements.
  • Hands-on experience performing STIG interpretation and remediation.
  • Experience reviewing and validating ACAS/Nessus vulnerability scan results.
  • Ability to use Splunk (or similar SIEM) to validate security controls and investigate anomalies.
  • Direct experience authoring ATO documentation (SSP, SAR, POA&M, etc.).
  • Strong working knowledge of NIST SP 800-53, RMF, and DoD cybersecurity requirements.
  • Experience using Xacta or eMASS to manage RMF artifacts.
  • DoD 8570 IAM-II compliant certification (e.g., Security+, CISSP, CISM).
  • Strong written and verbal communication skills with the ability to explain technical topics clearly.

Desired Qualifications

  • Experience as a Security Control Assessor (SCA) or assessor support.
  • Familiarity with FISMA, FISCAM, and federal audit requirements.
  • Experience supporting cloud environments (AWS GovCloud preferred).
  • Experience with automation or scripting to support security tasks.
  • Strong understanding of Zero Trust principles.
  • Experience supporting SAP/SAR or other high-side environments.

Peraton offers enhanced benefits to employees working on this critical National Security program, which include heavily subsidized employee benefits coverage for you and your dependents, 25 days of PTO accrued annually up to a generous PTO cap and eligible to participate in an attractive bonus plan


Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range$112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Skills Required

  • Active TS clearance with SCI eligibility, TS/SCI clearance adjudication with current polygraph, or ability to pass a polygraph
  • Bachelor's degree in a relevant technical field with 8+ years of relevant experience, or 12+ years of experience in lieu of a degree
  • 8+ years of hands-on experience as an ISSO, ISSE, assessor, security engineer, or closely related DoD cybersecurity professional
  • Experience writing Security Test Procedures, creating Security Controls Traceability Matrices, and developing control implementation statements
  • Hands-on experience interpreting and remediating STIG findings
  • Experience reviewing and validating ACAS or Nessus vulnerability scan results
  • Ability to use Splunk or a similar SIEM to validate security controls and investigate anomalies
  • Direct experience authoring ATO documentation, including SSPs, SARs, and POA&Ms
  • Strong working knowledge of NIST SP 800-53, RMF, and DoD cybersecurity requirements
  • Experience using Xacta or eMASS to manage RMF artifacts
  • DoD 8570 IAM-II compliant certification, such as Security+, CISSP, or CISM
  • Strong written and verbal communication skills
  • Experience as a Security Control Assessor or assessor support
  • Familiarity with FISMA, FISCAM, and federal audit requirements
  • Experience supporting cloud environments, preferably AWS GovCloud
  • Experience with automation or scripting for security tasks
  • Strong understanding of Zero Trust principles
  • Experience supporting SAP, SAR, or other high-side environments

Peraton Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Peraton and has not been reviewed or approved by Peraton.

  • Healthcare Strength Healthcare offerings are described as broad, including medical, dental, vision, mental health support, and specialty programs like virtual physical therapy and surgical/cancer care navigation. Medical coverage is also characterized as a standout part of the overall package in terms of perceived quality.
  • Retirement Support Retirement support includes a 401(k) with employer matching and is repeatedly positioned as a strong component of total rewards. The 401(k) benefit is frequently singled out as one of the most valued parts of the package.
  • Leave & Time Off Breadth Time-off benefits are positioned as robust, including PTO, holidays, paid sick days, and floating holidays, with some roles offering notably generous accrual. Leave breadth is reinforced by related programs such as short/long-term disability and bereavement leave.

Peraton Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
18,000 Employees
Year Founded: 2017

What We Do

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Why Work With Us

We are fearlessly solving the world’s most complex challenges to keep people safe and secure. You can be a part of protecting and promoting that freedom around the world.

Gallery

Gallery

Similar Jobs

Citizens Logo Citizens

Wealth Advisor - Sewickley, PA

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees
105K-250K Annually

PwC Logo PwC

Signature Events & Experiences Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
69 Locations
370000 Employees
91K-322K Annually

PwC Logo PwC

SAP Technology and D&A Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
56 Locations
370000 Employees
124K-280K Annually

PwC Logo PwC

Business Integrity Trade Compliance Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
69 Locations
370000 Employees
91K-322K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account