×
Register Here to Apply for Jobs or Post Jobs. X

Information Systems Security Officer Security Clearance

Job in Lorton, Fairfax County, Virginia, 22079, USA
Listing for: SPA
Full Time position
Listed on 2026-07-25
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Information Security & Data Protection
Job Description & How to Apply Below
Position: Information Systems Security Officer with Security Clearance
Overview Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter . Come work with the best!

We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA:
Objective. Responsive. Trusted. The Sea, Land, Air Analysis Group's mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, US Air Force, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.

SPA has an immediate need for an IT Modernization Information Systems Security Engineer. Responsibilities The Senior Cloud Information Systems Security Engineer (SCISSE) will support the Government Program Manager by integrating cybersecurity requirements into system architecture, design, and engineering activities from concept through deployment. Working across the system lifecycle, the SCISSE will develop and maintain security artifacts, including Security Plans, Security Controls Traceability Matrices, architectural diagrams, and engineering documentation.

Responsibilities include performing security engineering analyses such as threat modeling, vulnerability assessments, and security impact analyses for proposed system changes. The SCISSE will select, tailor, and implement security controls in accordance with NIST SP 800-53, CNSSI 1253, the Joint SAP Implementation Guide, and other applicable cybersecurity frameworks. To support informed decision-making, the SCISSE will communicate engineering risk assessments, including mitigation strategies, residual risks, and risk-benefit recommendations.

The role also encompasses requirements analysis, system design, and integration for complex software applications and collaboration infrastructures. As part of the configuration management process, the SCISSE will submit and review Change Requests while assessing the security implications of proposed modifications. Additional responsibilities include creating and maintaining information system security documentation, developing Standard Operating Procedures, and providing guidance on active Plans of Action and Milestones (POA&Ms).

The SCISSE will conduct continuous and periodic monitoring of systems, documentation, and operational procedures to ensure ongoing compliance with authorization requirements. Close collaboration with ISSOs, system administrators, and development teams will be essential to remediate vulnerabilities, maintain secure system configurations, and support secure engineering practices. Working with multiple system owners, the SCISSE will address security-related design and integration requirements for hybrid environments while evaluating cloud technologies in areas such as encryption, identity and access management, boundary protection, logging, and monitoring.

The position also supports incident response and forensic activities in coordination with cybersecurity teams and contributes to the development and execution of governance frameworks for managing and authorizing national security systems. Qualifications

Required Qualifications:

* Ability to support onsite in Lorton Virginia, up to full-time, based upon the needs of the client
* Master's degree in engineering, computer science, cybersecurity, networking, or programming
* Requires experience working with Special Access Programs (SAPs), along with strong proficiency in cloud architecture and associated security elements
* Must possess excellent analytical skills with the ability to quantify risk to enterprise systems and assess compliance with security policy, backed by 12+ years of technical experience in cybersecurity, information technology, or systems engineering
* TS/SCI with CI Polygraph, and the ability to maintain this throughout employment Advanced knowledge in one or more of the following areas:
* Secure systems engineering practices, including threat modeling, security architecture design, and/or system hardening
* Software Development in Java, Python, Ruby and/or C++
* Linux Expertise
* Dynamic & Static Application Security Scanning (e.g., OPSWAT, OWASP ZAP, Burp Suite, Fortify
* Experience with vulnerability management tools (e.g., Tenable, Defender), SIEM technologies, and secure configuration baselines
* Infrastructure Security Scanning, Vulnerability Scanning (NMAP, Azure Defender, AWS Inspector, ACAS/Nessus) Certification Requirements in one or more of the following:
*…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary