Jobs and Careers
BO

Chief Information Security Officer

Booz Allen Hamilton
Alexandria, United Statesfull_timeVerifiedPosted 18 Aug 2025
💰 $257,000/yr($112,800/yr$257,000/yr)

About the role

Chief Information Security Officer

The Opportunity:

Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to Department of Defense (DoD) agencies and related components. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you—a Chief Information Security Officer (CISO), where you will serve as the senior point of contact and lead for ensuring that DoD and industry best practices for maintaining Confidentiality, Integrity, and Availability of IT systems and services are applied and executed for a large-scale complex data platform. You will be responsible for leading secure product design, management, and delivery efforts focused on bringing the competitive, economic, and security benefits of cloud computing and data analytics to DoD customers. 

As CISO, you will manage the platform’s information security program while working collaboratively with government stakeholders and product delivery teams to ensure a comprehensive approach to security across the program. In these efforts, you will review technical artifacts for various platform capabilities, current and new, to assess the entire threat landscape and provide recommendations to improve security design of the platform architecture and safeguarding of data. You will implement strategies to safeguard information by leading security initiatives such as DoD Zero Trust and ensure the security program is compliant with regulations and audit requirements. You will work with your client to translate security concepts so they can make the best decisions to secure cloud infrastructure, artificial intelligence (AI) solutions, containerized applications, CI/CD application pipelines, and sensitive data repositories.

You will lead your team in developing and enforcing security policies to protect the platform’s critical data and infrastructure. You will be responsible for defining and enhancing the platform’s risk identification and assessment procedures while ensuring consistent adherence to these procedures and high-quality assessments from the cyber delivery team. You will be involved in organized Incident Response actions, including consulting, guiding, and reporting back to key stakeholders. You will lead a cyber team in meeting authorization timelines and coordinating communications with external entities in support of that objective.

This is your opportunity to be the security leader for a challenging, leading-edge DoD data platform while working at one of the world’s most respected companies. Work with us as we protect the DoD's critical analytic capabilities.

Join us. The world can’t wait.

You Have:  

  • 10+ years of experience implementing risk management methodologies contained in best practice documentation such as NIST SP 800-30, SP 800-53, SP 800-128, SP 800-160, SP 800-171, or CIS benchmarks in support of system security configurations, practices, and oversight

  • 5+ years of experience applying DoD Security Management and Security Engineering policy guidance and directives in a leadership role managing ISSOs, ISSMS, or cybersecurity engineers while interfacing with Program Managers, Cyber Assessors, and Authorizing Officials

  • 5+ years of experience with DoD Risk Management Framework (RMF), vulnerability assessments, IA Vulnerability Alerts (IAVA) reporting, and Information Assurance (IA) problem resolution

  • Experience with control implementations associated with RMF, FedRAMP, ICD 503, and DoD Information Levels, including applying them to the design and implementation of IT solutions to achieve system authorizations

  • Experience implementing and maintaining security controls within a complex system architecture, including AWS cloud, DevSecOps, and containerized COTS, GOTS, and custom software products within Agile development and production environments

  • Experience developing and reviewing ATO authorization packages in eMASS or Xacta

  • Ability to demonstrate executive presence

  • Top Secret clearance

  • Bachelor’s degree in IT or Cybersecurity

  • CISSP Certification

Nice If You Have:  

  • Experience managing a cybersecurity team consisting of cybersecurity engineers, ISSOs, and ISSMs collectively responsible for developing and implementing enterprise security policies and practices

  • Experience developing, testing, and sustaining a secure sol

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Booz Allen Hamilton

View company profile →