Job Closed
This listing is no longer active.
SIXGEN, founded in 2014 and headquartered in Annapolis, Maryland, is a veteran-owned small business specializing in advanced cybersecurity solutions. The compan
Information Systems Security Officer
Location
United States
Posted
68 days ago
Salary
$150K - $160K / year
Seniority
Lead
Job Description
Information Systems Security Officer
SIXGEN
• provides cybersecurity compliance, Risk Management Framework (RMF) implementation, and system authorization support to ensure the customer system meets Department of Defense (DoD) cybersecurity requirements • serves as the primary interface between engineering, testing, and authorization stakeholders to ensure all security controls are properly implemented, documented, and assessed • support RMF lifecycle activities in accordance with DoDI 8510.01 • assist with system categorization and control selection (NIST SP 800-53) • develop and maintain RMF artifacts including System Security Plan (SSP), Plan of Action & Milestones (POA&M), Security Control Traceability Matrix (SCTM), Security CONOPS (SECONOPS), Incident Response Plan (IRP) • coordinate with Authorizing Official (AO), Security Control Assessor (SCA), and Government stakeholders • document implementation of security controls • validate control inheritance from Government Furnished Equipment (GFE) • ensure alignment between system architecture and cybersecurity requirements • support assessment readiness for cyber test events (CVI, CVPA, ACDT, AA) • maintain the system Body of Evidence within eMASS • track control implementation status and associated artifacts • ensure all documentation is complete, current, and audit-ready • support continuous updates based on testing results and design changes • incorporate findings from Cyber test events, MBCRA and CTT activities • translate technical findings into RMF-relevant documentation updates • support risk determination and mitigation tracking • ensure vulnerabilities are properly reflected in POA&M entries • develop recommendations for continuous monitoring strategy • track and report cybersecurity risks to program leadership • support mitigation planning and validation • provide input into system design decisions to reduce cyber risk
Job Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Engineering, or related field
- 10+ years of experience supporting DoD cybersecurity programs
- Demonstrated experience with RMF (DoDI 8510.01) implementation
- Hands-on experience with eMASS
- Knowledge of NIST SP 800-53 security controls
- Experience supporting ATO or interim authorization efforts
- Active Secret or Top Secret clearance (preferred)
- Professional certifications such as CISSP, CAP (Certified Authorization Professional), Security+ (DoD 8570 compliant) (preferred)
- Experience with tactical or embedded systems (preferred)
- Familiarity with Army cybersecurity processes and interoperability testing (preferred)
Benefits
- competitive salary
- other forms of compensation to include our growth incentive program, incentives and benefits
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Engineer, Cloud Security
SpyCloudThe leader in operationalizing Cybercrime Analytics to prevent ATO, ransomware, and online fraud.
• Design, implement, and operate cloud security controls across production and internal environments (primarily AWS). • Own cloud posture management workflows (risk-based triage, exception handling, and automated remediation). • Build and maintain secure-by-default templates and modules (standards, defaults, account structure, secret management, segmentation). • Embed policy-as-code and IaC security controls into CI/CD (PR checks, drift detection) to prevent misconfigurations. • Reduce external and cloud risk by: • Own attack surface discovery/governance and baseline edge protections (e.g., WAF/rate limiting). • Drive automation for triage/remediation and operational efficiency by reducing repeat misconfigurations/toil (triage, routing, dedupe, validation, reporting). • Standardize cloud logging/telemetry and ensure it integrates cleanly into detection/IR workflows. • Work cross-functionally with Product, IT, DevOps, and Engineering to drive best practices and improve baseline security across the whole org. • Create pragmatic documentation, runbooks, and enablement materials that help teams self-serve, safely. • Support cloud/edge incident response: containment playbooks, root cause, and follow-up fixes. • Lead design reviews and threat models for platform/infrastructure (networking/segmentation, service-to-service access, secrets/encryption, logging/monitoring). • Drive continuous improvement of processes, procedures, and tools used across the security engineering organization.
Outside Sales Representative – Home Security Solutions
Vector SecurityIntelligent security tailored for your needs. Offering home and business security solutions for more than 50 years.
• Responsible for selling Vector’s residential solutions and achieving sales orders, RMR and unit targets. • Generates sales opportunities through cold calling, community involvement, creating community partners, and engaging exiting customers. • Actively works assigned leads, documents the status, and maintains a high closing percentage. • Maintains in-depth product knowledge via ongoing training and required certifications. • Educate customers about Vector Security products and services. • Upholds relationships with clients to ensure they remain satisfied, that their questions are answered, and that their needs are met throughout the life of the customer. • Identifies ways to market products to new consumers, including identifying new target market segments/opportunities. • Successful representatives actively build their pipeline through outreach, referrals, and in-person engagement with homeowners.
• Configure, deploy, and maintain security appliances such as firewalls (Palo Alto, Fortinet, Juniper, Check Point), IPS/IDS, load balancers (F5, Citrix ADC), and VPN concentrators. • Develop, implement, and audit firewall and IPS/IDS policies. • Design, configure, and maintain application load balancing for high availability, traffic distribution, and performance optimization. • Configure and support site-to-site and remote access VPNs (IPSec, SSL VPN). • Leverage network/security monitoring tools to track device health, performance, and threats. • Deploy and manage security appliances and load balancers in public cloud environments (AWS, Azure). • Develop and maintain scripts (Python, Bash, PowerShell) to automate routine tasks, configuration backups, and reporting. • Maintain up-to-date documentation for appliance configurations, standard operating procedures (SOPs), and change logs. • Conduct regular security assessments and vulnerability scans.
Company Overview Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company connecting patients, providers, payers, pharmacists, and manufacturers for coordinated care and improved patient outcomes. Backed by nearly 100 years of experience and supported by more than 50,000 employees in nearly 60 countries, Cardinal Health ranks among the top 20 on the Fortune 500. We offer extensive opportunities to grow technical and leadership skills within a culture that values collaboration, continuous improvement, employee well‑being, and career development. Team members enjoy dedicated training programs, supportive mentorship, and a strong sense of community. We are currently seeking a SailPoint Identity Engineer to join our Identity & Access Management organization. This role may be performed remotely. Department Overview: IAM / IAG The Identity and Access Management (IAM) and Identity and Access Governance (IAG) organization at Cardinal Health provides enterprise governance across all IAM solutions, processes, and access controls. The team is responsible for: - User access review operations - Enterprise identity governance - Access certification accuracy and completion - IAM controls and compliance - Collaboration with Security Architecture, Risk, Compliance, and other security teams - Our tools and technologies include SailPoint IdentityIQ, CyberArk, and Okta. Responsibilities IAM Integrations (Build) - Partner with clients and external stakeholders to design and implement IAM‑aligned service solutions. - Define and document technical requirements for data elements to be included in IdentityIQ, Okta, and CyberArk to support access certification and access management objectives. - Design and implement an enterprise Role-Based Access Control (RBAC) framework. - Design, develop, and maintain AI‑driven capabilities within the Identity Governance and Administration (IGA) platform to enhance access reviews, entitlement analysis, role mining, anomaly detection, and risk‑based decisioning across SOX and non‑SOX systems. - Establish requirements for effective, efficient integrations with IAM services. - Identify, design, and implement process improvements aligned with IAM best practices. - Conduct comprehensive testing of implementation solutions to ensure accuracy, reliability, scalability, and compliance with established security controls Access Certifications (Run) - Design and deploy effective access certification campaigns that ensure accuracy, completeness, and alignment with security and regulatory requirements. - Administer IdentityIQ access certification processes, ensuring operational and audit compliance. - Recommend and implement certification process improvements. - Perform data analytics and generate reporting to support governance and compliance activities. - Collaborate with business and technical teams to enhance IAM processes across the identity lifecycle. - Manage ServiceNow incidents, service requests, assessments, and enhancement requests, ensuring adherence to SLAs. - Create and maintain IdentityIQ rules, certification definitions, and workflows to support attestation processes. Qualifications - Proven hands-on experience with SailPoint IdentityIQ or similar identity governance technologies. - Expertise across IdentityIQ components such as installation, build and deployment, Lifecycle Manager, Identity Governance, application onboarding, custom development, debugging, troubleshooting, RBAC, and access/data modeling. - Foundational understanding of information security principles and IAM best practices. - Strong design and development skills with database technologies (e.g., SQL, relational schema design). - Ability to design with non-functional requirements in mind, including performance, scalability, and security. - Experience working within Agile (Scrum) methodologies. - Experience writing code for high‑scalability systems. - SaaS IGA migration experience a plus. - CIEM (Cloud Infrastructure Entitlement Management) integration experience a plus. Anticipated salary range: $94,900 - $135,600 Bonus eligible: No Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being. - Medical, dental and vision coverage - Paid time off plan - Health savings account (HSA) - 401k savings plan - Access to wages before pay day with myFlexPay - Flexible spending accounts (FSAs) - Short- and long-term disability coverage - Work-Life resources - Paid parental leave - Healthy lifestyle programs Application window anticipated to close: 4/15/2026 *if interested in opportunity, please submit application as soon as possible. The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity. Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply. Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law. To read and review this privacy notice click here



