Senior Principal Cyber Information Systems Security Engineer
Description
SAIC is seeking an expert-level Senior Principal Information Systems Security Engineer (ISSE) to support DoD enterprise IT and network modernization programs in one of the following locations and is required to be local: the National Capital Region, San Diego, CA, Norfolk, VA, or Charleston, SC.
This role serves as a senior principal individual contributor and subject matter expert responsible for leading the development, management, and authorization of Risk Management Framework (RMF) packages across both unclassified and classified environments in direct support of DoD enterprise IT and digital transformation missions.
The ideal candidate is a recognized expert in DoD RMF processes with deep hands‑on experience navigating Navy program office authorization workflows, eMASS system management, and ATO package development. This position requires direct engagement with senior government leadership, program offices, engineering teams, and authorizing officials to drive security authorization packages through the full RMF lifecycle from initiation through authorization and continuous monitoring.
This role operates with significant independence, serving as the senior principal ISSE authority and organizational spokesperson on complex cybersecurity authorization matters requiring coordination across multiple program teams, engineering organizations, and government stakeholders. The successful candidate will be a technically fluent self‑starter capable of leading RMF authorization efforts across simultaneous unclassified and classified programs while working collaboratively with a team of engineers to deliver compliant, authorized, and operationally ready systems in support of the warfighter.
Must be able to travel up to 10% to support program site visits and customer engagement
JOB DUTIES:- Serve as Senior Principal ISSE and subject matter expert responsible for leading development, management, and authorization of RMF packages across both unclassified and classified environments supporting DoD enterprise IT and network modernization programs
- Lead end-to-end RMF lifecycle activities following NIST 800-39, 800-37, 800-53, 800-53A, and 800-137 for multiple simultaneous unclassified and classified systems
- Categorize systems and information stored and processed on systems based on FIPS 199 and NIST 800-60; select and tailor initial security control baselines based on FIPS 200 and NIST 800-53
- Implement security controls based on NIST Special Publication guidance documents including 800-34, 800-64, and 800-128; specifically and functionally document all implemented security controls
- Assess security controls based on NIST 800-53A to ensure they are implemented correctly, operating as intended, and producing desired outcomes
- Manage and maintain eMASS records for all assigned systems; ensure accuracy and completeness of all RMF artifacts, POA&Ms, and authorization documentation throughout the system lifecycle
- Drive RMF packages through full authorization workflow in accordance with Navy and DoD RMF processes; coordinate directly with Authorizing Officials (AOs), Information System Owners (ISOs), and Program Managers to achieve and maintain Authority to Operate (ATO)
- Ensure continuous monitoring is achieved based on NIST 800-137, 800-37, 800-53A, and related special publications; maintain ongoing ATO compliance across authorized systems
- Work collaboratively with teams of engineers to identify, document, and implement security controls across complex DoD enterprise IT and network infrastructure environments
- Perform internal auditing functions in support of ISO/IEC standards including 9000, 20000, and 27001; coordinate with external auditors to ensure actions have been performed to industry standards
- Perfo…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).