Acquisition Program Security Officer; APSO/Program Protection Analyst. Stafford Move
Listed on 2026-06-02
-
IT/Tech
Cybersecurity, Information Security, Data Security
Acquisition Program Security Officer (APSO) / Program Protection Analyst - Stafford, VA
Join our team as an Acquisition Program Security Officer (APSO) / Program Protection Analyst in Stafford, VA. We are seeking dedicated professionals with acquisition security, systems engineering, cybersecurity, intelligence, and technology protection experience to support Marine Corps acquisition programs in integrating Program Protection (PP), Critical Program Information (CPI) protection, (Use the "Apply for this Job" box below). Supply Chain Risk Management (SCRM), Operations Security (OPSEC), and acquisition security activities into a comprehensive mission assurance framework focused on preserving U.S. technological advantage and delivering resilient war fighting capability.
This role is instrumental in ensuring sensitive and protected information is not errantly released outside protected boundaries.
- Analyze, develop, and evaluate acquisition, intelligence, and security policies
- Support Program Managers (PMs), Deputy Program Managers, and Integrated Product Teams (IPTs) in identifying, assessing, and protecting CPI, mission‑critical functions, and sensitive acquisition technologies throughout the acquisition lifecycle
- Develop and assess Program Protection Plans (PPPs), CPI assessments, and protection strategies in accordance with DoDI 5000.83 and DoDI 5200.39
- Analyze adversary threat, exposure, vulnerability, and exploitation risk to acquisition programs, systems, software, hardware, interfaces, and supply chains
- Support integration of cybersecurity, OPSEC, SCRM, and system security engineering activities into acquisition protection strategies and program planning
- Assist acquisition programs in translating technical security risks into mission, operational, sustainment, and acquisition impacts for leadership decision‑making
- Provide acquisition security and technology protection recommendations to PMs, IPTs, engineers, and security stakeholders regarding risk mitigation, protection prioritization, and lifecycle protection strategies
- Coordinate cross‑functional acquisition security activities involving engineering, cybersecurity, intelligence, counterintelligence, logistics, contracting, and system security engineering stakeholders
- Recommend risk‑based countermeasures to reduce adversary exploitation opportunities targeting CPI, mission software, embedded systems, sensitive interfaces, technical data, and supply chain exposure points
- Assess protection effectiveness and identify gaps in program protection, acquisition security, OPSEC, and technology protection implementation
- Work with subject‑matter experts (SMEs) from various acquisition competencies, intelligence communities, security, and counterintelligence to ensure delivery of resilient and uncompromised capabilities to the warfighter
- Collaborate with Systems Security Engineers (SSEs), program offices, and intelligence stakeholders in developing and maintaining Security Classification Guides (SCGs), CPI identification and analysis, Criticality Analyses (CAs), PPPs, and technology protection strategies
- Support horizontal protection analysis to ensure consistent protection of equivalent CPI and mission‑critical technologies across related acquisition programs
- Assist in evaluating requirements for exportability considerations, cybersecurity, and system resiliency protections based on consequence of compromise and operational exposure
- Support Supply Chain Risk Management (SCRM) and Trusted Systems and Networks (TSN) activities by assessing supplier, component, software, firmware, and sustainment risks affecting mission‑critical functions and acquisition program integrity
- Coordinate with logistics, engineering, cybersecurity, and sustainment stakeholders regarding counterfeit prevention, trusted supplier concerns, lifecycle exposure points, and supply chain threat mitigation strategies
- Review acquisition documentation for potential security concerns
- Provide guidance regarding classification, Controlled Unclassified Information (CUI), distribution statements, OPSEC‑sensitive information, and acquisition documentation marking…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).