Information System Security Officer

Posted 5 days ago
$119K - $161K / year

Are you applying to the internship?

Job Description

IT and Cyber Risk Auditor Principal | General Dynamics Information Technology

The Tone:
This is a full-time role at General Dynamics Information Technology, located in La Plata, MD. General Dynamics Information Technology delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. This role is essential for monitoring and enforcing security controls, ensuring system compliance, and maintaining the integrity of information systems. The work directly supports critical government missions by protecting against vulnerabilities and cyber risks.

The TL;DR
• Role: Full Time
• Type: Regular
• Location: In-person, La Plata, MD
• Pay: $119000–$161000 yearly
• Mission: Identify, track, and remediate system vulnerabilities and ensure compliance with security controls for critical government systems.
• Tech Stack: Splunk, Security Center, Telos XACTA, MacAfee EPO, XACTA data base applications

What You’ll Actually Do
• Monitor: Monitor and enforce security controls for technical, operational, and management support.
• Develop: Develop and document critical security materials including system security plans, contingency plans, and other security-related documents.
• Remediate: Identify, track, and remediate system vulnerabilities, implementing corrective actions through Plans of Action and Milestones (POA&M) management.
• Certify: Prepare system artifacts for annual system audits and complete Authority to Operate (ATO) security packages.
• Review: Review system configurations, monthly vulnerability scan reports, and proposed change requests to ensure compliance and perform security impact analysis.

The Must-Haves
• Background: Bachelor’s degree or equivalent in Cyber and IT Risk Management or a related field, operating at a Principal career level, and possessing a current Top Secret SCI + Polygraph clearance.
• Experience: 8+ years of experience in IT and Cyber Risk Management, with a minimum of 3-5 years specifically applying ICD 503 and NIST 800-53 policies, and senior-level experience in engineering IT systems. Requires maintaining certification in accordance with DoW Directive 8140.01 Cyberspace Workforce Management requirements.
• Skills: Cyber Risks, Cybersecurity Controls, NIST 800-53, System Security Plan documentation, Plans of Action and Milestones (POA&M) Management, Authority to Operate (ATO) Security Packages, Incident Response.
• Bonus: 2-3 years as an Information System Security Engineer (ISSE), 2-3 years in a Windows and/or Unix administrator role, experience using XACTA database applications and ICD 503, NIST 800-83 rev4 policy, and familiarity with Splunk, Security Center, Telos XACTA, and MacAfee EPO.

Related Jobs