Security ISSO
USA VA Home Office (VAHOME), United States
General Dynamics Information Technology
Delivering technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community.Type of Requisition:
RegularClearance Level Must Currently Possess:
SecretClearance Level Must Be Able to Obtain:
SecretPublic Trust/Other Required:
NoneJob Family:
Information SecurityJob Qualifications:
Skills:
Azure Active Directory (AD), ISSO, System Security, System Security PlansCertifications:
NoneExperience:
10 + years of related experienceUS Citizenship Required:
NoJob Description:
Information Security Analyst Sr Advisor
Your Impact
Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the wellbeing of U.S. citizens.
Job Description
We are seeking a qualified, motivated individual to join GDIT as an Information Security Analyst Senior Advisor (Security 1 Lead ISSO). This position will play a dual role as the Security Lead as well as the projects ISSO. Your focus will be on the Systems Security Plan (SSP) and Authorization To Operate (ATO) package documentation, Policy and Controls, and any other duties that fall under the ISSO / Information Assurance role. You will maintain security postures across several development environments, conducting risk assessments, and ensuring all system changes undergo proper security reviews, while keeping abreast of evolving government cybersecurity directives. You will collaborate with GDIT technical leadership, Government customers, and other key stakeholders to assess our existing and new systems infrastructure.
How You’ll Make an Impact:
- Ensure security policies and procedures are implemented
- Authors Standard Operating Procedures, policies, and IA plans of action to ensure systems compliance with Federal/DoD guidance
- Identifying corrective actions/mitigation strategies to achieve/sustain (Risk Management Framework (RMF) compliance
- Review and analyze system implementation plans
- Advising system owners and stakeholders on new deployments and advanced cyber security techniques
Information Security Analyst Senior Advisor Duties and Responsibilities
- Serve as the primary authority on System security
- Oversee the implementation of NIST SP 800-53 controls, Classified National Security Information (CNSI) and FedRAMP requirements across Azure Gov and Azure Secret cloud environments
- Develop and maintain security documentation (System Security Plans, security policies, procedures)
- Manage the ATO process by conducting risk assessments, coordinating with authorizing officials, and tracking Plans of Action & Milestones (POA&Ms) for identified gaps
- Monitor system security posture daily by reviewing audit logs and SIEM alerts (Splunk, Azure Sentinel) for suspicious activity or policy violations
- Ensure timely incident investigation and response with the DevOps team
- Guide DevOps and Engineering teams on secure configuration baselines (applying DISA STIGs or CIS benchmarks to servers, containers, and network devices)
- Verify that all system changes pass security review and change controls
- Coordinate regular vulnerability scanning and penetration testing of cloud infrastructure and applications (using approved tools like Nessus, Fortify)
- Ensure any discovered vulnerabilities are remediated within required timeframes
- Enforce robust access controls and identity management
- Regularly review user accounts and privileges in Azure AD and Azure Gov environments
- Ensure multifactor authentication and PKI usage in accordance with federal security policies
- Provide security training and guidance to engineering teams
- Foster a culture of security awareness, and stay up to date on government cybersecurity directives to adapt security strategies
Information Security Analyst Senior Advisor Requirements and Qualifications
- Bachelor’s degree in computer science or IT related degree; master's degree or equivalent professional experience in information security is preferred
- Ability to create and maintain system BOE documents to include SSPs, architecture diagrams, contingency planning, and continuous monitoring documentation
- Ability to write and modify documents to include SOPs, processes, and other guidance documentation
- Comprehensive knowledge of corporate Systems/Solutions Architecture processes and trends
- Strong leadership, organizational, and communication skills
- Secret Clearance to start
- Knowledge of Agile software development process
- Experience with Azure AD
Required Technical Skills:
- SCAP, STIG, Patching, eMASS, and related RMF tools
- Cybersecurity, Systems Administration, implementation of RMF tools and processes
- Excellent communication skills
- Experience working in Agile software development teams
- Experience with secure development, coding and engineering practices
- Experience with Cybersecurity, Information Security, and Information Technology Security processes, protocols, and procedures.
- Experience with tools such as Splunk, Azure Sentinel, Nessus, Fortify
Experience
- 10 years of relevant experience
- Experience with Cloud Security
- Experience working with leading firewall, network scanning and authentication technologies
- Experience working with internet, web, application and network security techniques
- Experience in Agile methodology
- Experience in Jira to support development team in agile environment
- Experience working in Federal or State government environments
- Ability to work independently and remotely
Certification: CISSP desired, Active DoD 8570 IAT Level II Certification (Security+ CE)
Travel Required: Little to no travel anticipated (may be required upon customer request)
Location: Hybrid
US Citizenship: U.S. Citizenship required
GDIT Is Your Place:
- 401K with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities including paid education and certifications
- Cutting-edge technology you can learn from
- Full-flex work week to own your priorities at work and at home
Scheduled Weekly Hours:
40Travel Required:
Less than 10%Telecommuting Options:
HybridWork Location:
USA DC Home Office (DCHOME)Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events atEqual Opportunity Employer / Individuals with Disabilities / Protected VeteransTags: Active Directory Agile Azure CISSP Clearance Cloud Compliance Computer Science DevOps DISA DoD DoDD 8570 eMASS FedRAMP Firewalls Jira Monitoring Nessus Network security NIST NIST 800-53 Pentesting PKI Risk assessment Risk management RMF SCAP Sentinel SIEM Splunk STIGs System Security Plan Vulnerabilities
Perks/benefits: 401(k) matching Career development Competitive pay Flex hours Health care Home office stipend Insurance Medical leave Parental leave Startup environment Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.