user avatar

Information System Security Officer

MANTECH

Posted today

Job Requirements

Remote
Public Trust Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

seeks a career and customer-oriented Information to join our team supporting a federal agency's Safeguards and Risk Management (SRM) mission. This is a fully position and only expected to be in the office in case of emergency or if requested/required by government.


  • Categorizes systems (FIPS 199) in coordination with system owners, accounting for high-volume PII/NPI data aggregation risks inherent to organizational data.
  • Build the control package: apply NIST SP 800-53 controls, develop the SSP, draft implementation statements, and collect evidence validating secure data ingestion and processing.
  • Guide system owners on writing and resolving implementation statements.
  • Drive controls to secure status and see them through testing, with emphasis on data integrity, encryption-in-transit (TLS), and Identity & Access Management (IAM).
  • Partner closely with the Security Assessment Provider/SCA to ensure quality of artifacts and evidence to enable the assessment.
  • Advise system owners on control prioritization, ensuring alignment with both NIST frameworks and financial regulatory data protection standards (e.g., FFIEC expectations).
  • Support RMF & A&A: Cyber Risk Framework (CRF) input, Change Request Reviews, POA&M tracking, SA&A Project List, and SOPs/A&A artifacts on a best-effort basis.



  • Hands-on experience with NIST RMF (800-30, 800-37, 800-53, and 800-53A) - practical implementation, not just familiarity.
  • Demonstrated experience building control packages and drafting implementation statements.
  • Experience in creating or supporting Security Assessment Plans and Security Assessment Reports.
  • Experience with Q-Compliance (or the ability to ramp quickly).
  • Experience interpreting data from vulnerability scanning tools (e.g., Tenable, Qualys) to identify risks in databases and file-processing pipelines.
  • Understanding network architectures, including SaaS, IaaS, or PaaS environments; experience securing modern, cloud-native web platforms preferred.
  • Technical background sufficient to collaborate with system owners on design documentation.



  • SME-level knowledge of NIST SP 800-137 (ISCM).
  • 1+ years of technical experience with Python, Java, or PHP - sufficient to read, interpret, and understand code to independently verify control implementation and evaluate technical alternate solutions for complex NIST requirements.
  • 1+ year of experience with a GRC tool (such as CSAM).
  • Experience with Q-Compliance and/or Q-Audit.
  • Experience with API testing (REST APIs), JSON payload security, and/or scripting and automation.
  • Relevant industry certifications (e.g., CISA, CAP, CISSP, Security+).



  • Must be a U.S. Citizen with the ability to obtain and maintain a Public Trust clearance prior to starting this position.



  • Must be able to remain in a stationary position 50% and constantly operate a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
group id: RTX14564a
job ad image
Find MANTECH on Social Media
Recruiters
user avatar
About Us
For over half a century, we have been where our clients are: land, sea, air, space and cyberspace. We collaborate across sectors and capabilities to deliver next-generation technology, tools, training and seasoned personnel.
job ad2 image

MANTECH Jobs


Job Category
IT - Security
Clearance Level
Public Trust
Employer
MANTECH