Job Closed
This listing is no longer active.
SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives. We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com . For ongoing news, please visit our newsroom .
Cybersecurity Information System Security Officer
Location
United States
Posted
100 days ago
Salary
0
No structured requirement data.
Job Description
Cybersecurity Information System Security Officer
SAIC
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description SAIC is seeking a hands-on Cybersecurity Information System Security Officer (ISSO) to support a program part-time (25%) within the Department of War. This position focuses on leveraging Risk Management Framework (RMF), continuous monitoring, and cybersecurity best practices to ensure the security posture of the system and operations. The successful candidate will collaborate with cross-functional teams, execute vulnerability management, and provide guidance on security compliance using tools and methodologies aligned with contract requirements. This is a remote / work from home position approximately 10 hours per week. - Review audit logs and security alerts to detect and assess potential anomalies. - Conduct continuous monitoring tasks, including Configuration Control Board (CCB) impact reviews, patching recommendations, and ATO delta documentation. - Support vulnerability scanning efforts by reviewing scan reports, tracking mitigations, and documenting residual risks. - Assist in maintaining RMF documentation—such as System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and archiving security artifacts in eMASS. - Review and assess access logs and user activity reports to identify and report potential inconsistencies or anomalies. - Use Jira for tracking cybersecurity and engineering activities facilitating continuous monitoring of security measures. - Serve as a bridge between Information System Security Manager (ISSM) and engineers. Qualifications - Bachelor’s degree in related discipline and eight (8) years or more experience. Four (4) additional years of related experience will be considered in lieu of a bachelor’s degree. - Experience performing security monitoring, risk assessments, and compliance checks. - Hands-on experience maintaining RMF packages and security documentation within tools like eMASS. - Demonstrated experience in vulnerability management, including analyzing scan results and overseeing remediations. - Familiarity with incident response coordination and audit log review processes. - Experience collaborating with CCBs and providing risk assessments related to system changes. - Experience working closely with ISSM and Systems Integration teams. Requirements - Must be CompTIA Security+ certified, prior to start date. - Active Secret Clearance.
Job Requirements
- Bachelor’s degree in related discipline and eight (8) years or more experience. Four (4) additional years of related experience will be considered in lieu of a bachelor’s degree.
- Experience performing security monitoring, risk assessments, and compliance checks.
- Hands-on experience maintaining RMF packages and security documentation within tools like eMASS.
- Demonstrated experience in vulnerability management, including analyzing scan results and overseeing remediations.
- Familiarity with incident response coordination and audit log review processes.
- Experience collaborating with CCBs and providing risk assessments related to system changes.
- Experience working closely with ISSM and Systems Integration teams.
- Must be CompTIA Security+ certified, prior to start date.
- Active Secret Clearance.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
ICR Information Request Specialist
RevecoreRevecore has been at the forefront of specialized claims management, helping healthcare providers recover meaningful revenue to enhance quality patient care in their communities. We’re powered by people, driven by technology, and dedicated to our clients and employees. If you’re looking for a collaborative and diverse culture with a great work/life balance, look no further.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Provides a high level of service to meet company commitments and objectives to facilitate timely resolution of client accounts for assigned clients, while acting as a liaison between our claims representatives and our providers. - Updates patient accounts with information received from hospitals and follow-up with Contact Specialist. - Accesses client connections/computer system to obtain information required to update accounts. - Monitors requests to ensure they do not age beyond day. - Performs special projects or tasks as assigned. - Assist IT in resolving access issues. Qualifications - High school diploma or equivalent required. - Eagerness to learn new technologies and develop proficiency in internal applications. - Strong computer navigation skills and experience using multiple software programs simultaneously to complete work. Requirements - Ability to communicate effectively and professionally both verbally and in writing. - Demonstrated skill in providing a high level of customer service to external customers (clients) and internal customers (company departments). - Demonstrated ability to work independently and follow-through on assignments with minimal direction. - Knowledge of or ability to learn client and Operations processes and how they interact. - Ability to produce accurate work while maintaining attention to detail. - Skilled in organizing and setting priorities according to situational demands. - Ability to work effectively under minimal supervision. - Working knowledge of Excel and Word. - Ability to gain proficiency in working with varied hospital databases. - High level of attention to detail and be skilled in organizing and prioritizing work. Benefits - Paid training and incentive plans. - Medical, dental, vision, and life insurance benefits available from the first day of employment. - Excellent work/life balance. - Employee Resource Groups build community and foster a culture of belonging and inclusion. - 401(k) contributions matched. - Career growth opportunities. - 12 paid holidays and generous paid time off. Work at Home Requirements - A quiet, distraction-free environment to work from in your home. - A secure internet connection is required. - Home internet with speeds >20 Mbps for downloads and >10 Mbps for uploads. - The workspace area accommodates all workstation equipment and related materials and provides adequate surface area to be productive. - Must reside in the United States within one of the specified states.
Director of Information Security
ECPClinical and operations software solutions for assisted living providers
ECP is a market-leading SaaS software solution that enables senior living communities to better care for their residents. ECP is used in over 8,000 communities. We're looking to further expand by increasing the number of customers that use our software and increasing the scope of how we serve our customers by developing and releasing new products. ECP is seeking a Director of Information Security to lead and execute our cybersecurity and compliance strategy. This is a hands-on role responsible for ensuring the confidentiality, integrity, and availability of our systems and customer data within the context of healthcare regulations (HIPAA) and SOC 2 Type II compliance. The ideal candidate brings a blend of technical expertise, regulatory understanding, and practical execution, partnering closely with our Infrastructure and IT teams to strengthen our security posture across the company. You’ll manage annual audits, harden systems, guide best practices, and foster a culture of security awareness. This position reports to the VP of Engineering and collaborates cross-functionally with DevOps, Infrastructure, Compliance, and IT. Note: We are open to remote candidates located in the U.S. Cybersecurity: - Develop and execute ECP’s information security strategy, aligned with business goals and risk tolerance. - Maintain and evolve SOC 2 Type II compliance, including evidence gathering, documentation, and audit coordination. - Ensure compliance with HIPAA and other healthcare data protection standards. - Establish, implement, and maintain security policies, procedures, and standards consistent with regulatory and customer expectations. - Manage third-party risk and vendor security assessments. - Lead the incident response program, including detection, investigation, communication, and remediation. - Oversee vulnerability management, penetration testing, and security monitoring. - Partner with Infrastructure and DevOps teams to secure servers, cloud environments (AWS/Azure), and CI/CD pipelines. - Integrate secure development lifecycle (SDLC) practices into engineering workflows. - Stay current on emerging security threats, technologies, and frameworks, and advise leadership accordingly. IT & Platform Security: - Collaborate with internal IT to harden employee laptops and mobile devices, ensuring encryption, endpoint protection, and compliance with policy. - Manage and optimize the company’s mobile device management (MDM) platform. - Support and guide internal IT in maintaining secure onboarding/offboarding and access management processes. - Coordinate internal penetration testing efforts and develop recommendations for infrastructure hardening. - Assist with network and system security, including identity management and monitoring. - Develop and lead employee security and HIPAA awareness training programs. - Maintain visibility into and tracking of vulnerabilities and remediation efforts.
Director of Information Security
ECPClinical and operations software solutions for assisted living providers
ECP is a market-leading SaaS software solution that enables senior living communities to better care for their residents. ECP is used in over 8,000 communities. We're looking to further expand by increasing the number of customers that use our software and increasing the scope of how we serve our customers by developing and releasing new products. ECP is seeking a Director of Information Security to lead and execute our cybersecurity and compliance strategy. This is a hands-on role responsible for ensuring the confidentiality, integrity, and availability of our systems and customer data within the context of healthcare regulations (HIPAA) and SOC 2 Type II compliance. The ideal candidate brings a blend of technical expertise, regulatory understanding, and practical execution, partnering closely with our Infrastructure and IT teams to strengthen our security posture across the company. You’ll manage annual audits, harden systems, guide best practices, and foster a culture of security awareness. This position reports to the VP of Engineering and collaborates cross-functionally with DevOps, Infrastructure, Compliance, and IT. Note: We are open to remote candidates located in the U.S. Cybersecurity: - Develop and execute ECP’s information security strategy, aligned with business goals and risk tolerance. - Maintain and evolve SOC 2 Type II compliance, including evidence gathering, documentation, and audit coordination. - Ensure compliance with HIPAA and other healthcare data protection standards. - Establish, implement, and maintain security policies, procedures, and standards consistent with regulatory and customer expectations. - Manage third-party risk and vendor security assessments. - Lead the incident response program, including detection, investigation, communication, and remediation. - Oversee vulnerability management, penetration testing, and security monitoring. - Partner with Infrastructure and DevOps teams to secure servers, cloud environments (AWS/Azure), and CI/CD pipelines. - Integrate secure development lifecycle (SDLC) practices into engineering workflows. - Stay current on emerging security threats, technologies, and frameworks, and advise leadership accordingly. IT & Platform Security: - Collaborate with internal IT to harden employee laptops and mobile devices, ensuring encryption, endpoint protection, and compliance with policy. - Manage and optimize the company’s mobile device management (MDM) platform. - Support and guide internal IT in maintaining secure onboarding/offboarding and access management processes. - Coordinate internal penetration testing efforts and develop recommendations for infrastructure hardening. - Assist with network and system security, including identity management and monitoring. - Develop and lead employee security and HIPAA awareness training programs. - Maintain visibility into and tracking of vulnerabilities and remediation efforts.
Director of Information Security
ECPClinical and operations software solutions for assisted living providers
ECP is a market-leading SaaS software solution that enables senior living communities to better care for their residents. ECP is used in over 8,000 communities. We're looking to further expand by increasing the number of customers that use our software and increasing the scope of how we serve our customers by developing and releasing new products. ECP is seeking a Director of Information Security to lead and execute our cybersecurity and compliance strategy. This is a hands-on role responsible for ensuring the confidentiality, integrity, and availability of our systems and customer data within the context of healthcare regulations (HIPAA) and SOC 2 Type II compliance. The ideal candidate brings a blend of technical expertise, regulatory understanding, and practical execution, partnering closely with our Infrastructure and IT teams to strengthen our security posture across the company. You’ll manage annual audits, harden systems, guide best practices, and foster a culture of security awareness. This position reports to the VP of Engineering and collaborates cross-functionally with DevOps, Infrastructure, Compliance, and IT. Note: We are open to remote candidates located in the U.S. Cybersecurity: - Develop and execute ECP’s information security strategy, aligned with business goals and risk tolerance. - Maintain and evolve SOC 2 Type II compliance, including evidence gathering, documentation, and audit coordination. - Ensure compliance with HIPAA and other healthcare data protection standards. - Establish, implement, and maintain security policies, procedures, and standards consistent with regulatory and customer expectations. - Manage third-party risk and vendor security assessments. - Lead the incident response program, including detection, investigation, communication, and remediation. - Oversee vulnerability management, penetration testing, and security monitoring. - Partner with Infrastructure and DevOps teams to secure servers, cloud environments (AWS/Azure), and CI/CD pipelines. - Integrate secure development lifecycle (SDLC) practices into engineering workflows. - Stay current on emerging security threats, technologies, and frameworks, and advise leadership accordingly. IT & Platform Security: - Collaborate with internal IT to harden employee laptops and mobile devices, ensuring encryption, endpoint protection, and compliance with policy. - Manage and optimize the company’s mobile device management (MDM) platform. - Support and guide internal IT in maintaining secure onboarding/offboarding and access management processes. - Coordinate internal penetration testing efforts and develop recommendations for infrastructure hardening. - Assist with network and system security, including identity management and monitoring. - Develop and lead employee security and HIPAA awareness training programs. - Maintain visibility into and tracking of vulnerabilities and remediation efforts.

