Senior Information System Security Officer (ISSO)
Laurel, MD$135k–$216kPosted May 11, 2026
Welcome page
Returning candidate?
Log back in!
Senior Information System Security Officer (ISSO)
Job Locations
US-MD-Laurel
Requisition ID
2026-166615
Position Category
Information Technology
Clearance
Top Secret/SCI w/Poly
Responsibilities
Peraton Labs is seeking a poly cleared Senior Information System Security Officer for a mission-critical, highly complex HPC environment enabling research across multiple security domains. You will own day-to-day security operations aligned to RMF, drive continuous monitoring, maintain ATO posture, and partner closely with subcontractor and customer personnel. This position requires full-time on-site work in Laurel, or a customer site near College Park, MD. Key responsibilities may includeLead or co-lead ATO/reauthorization efforts for complex boundary systemsMentor junior ISSOs and shape security operations playbooksPerform risk analysis and author formal recommendations to leadershipDrive security engineering outcomes by partnering with internal teams on scalable compliance patternsBrief senior internal and customer stakeholders on security posture, systemic risk trends, remediation burn-down, and authorization readinessAct as the Senior ISSO supporting the system security lifecycle across development, operations, and modernizationExecute and maintain RMF activities (e.g., control implementation oversight, evidence collection, assessment support, POA&M management, continuous monitoring)Maintain security authorization artifacts (e.g., SSP, control narratives, diagrams, inheritance/leverage controls, CM plan, incident handling plan, contingency artifacts, user/admin procedures)Operate continuous monitoring: vulnerability management, config compliance, patching coordination, scan result triage, risk acceptance, and remediation verification.Review and approve security-relevant changes through configuration/change control and validate security configurations after major upgradesSupport incident response and reporting: participate in investigations, coordinate containment actions, preserve evidence, and contribute to post-incident lessons learnedEnsure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, and audit compliance requirementsTranslate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible) *This position may be eligible for an increased sign-on bonus. Eligibility, bonus amount, and applicable terms and conditions will be discussed during the recruiting process* #MDFSP#PLABS26
Qualifications
Required qualifications12+ years of experience and a BS in Computer Science, Cybersecurity, or related technical discipline, MS and 10+ years of experience, or a PhD and 8+ years of experience. Four years of additional experience is required in lieu of a Bachelors’ degree for a total of 16 years of experience8+ years of experience in information security/compliance supporting DOD/IC or government systems, including ownership of major RMF deliverables and ATO events for complex systemsDemonstrated leadership experience coordinating across security, engineering, and customer stakeholdersAbility to provide mentorship and direction to team membersProven ability to write risk decisions and packages that stand up to assessor/AO scrutinyDeep understanding of continuous monitoring at scale (recurring evidence, metrics, audit readiness, remediation governance)Hands-on experience executing RMF tasks and maintaining authorization artifacts (SSP, POA&Ms, continuous monitoring evidence)Strong working knowledge of NIST SP 800-53 controls and how they map to technical implementations and proceduresExperience with vulnerability and configuration compliance workflowsFamiliarity with Linux-based enterprise environments and common hardening conceptsAbility to communicate risk clearly to both technical engineers and non-technical leadershipOne or...