Sr. Information Systems Security Officer
Oak Ridge National LaboratoryAbout the role
Requisition Id 15070
Overview:
As a U.S. Department of Energy (DOE) Office of Science national laboratory, ORNL has an impressive 80-year legacy of addressing the nation’s most pressing challenges. Our team is made up of over 7,000 dedicated and innovative individuals! Our goal is to create an environment where a variety of perspectives and backgrounds are valued, ensuring ORNL is known as a top choice for employment. These principles are essential for supporting our broader mission to drive scientific breakthroughs and translate them into solutions for energy, environmental, and security challenges facing the nation.
The Field Intelligence Operations Division (FIOD) is seeking a Cybersecurity Specialist to provide day-to-day support for Sensitive Compartmented Information (SCI) and Special Access Program (SAP) systems. Qualified applicants have Information Systems Security Officer (ISSO) experience to support FIOD Operations for classified operations across a wide-breadth of information environments. The ISSO supports the Information Systems Security Manager (ISSM) in the certification and accreditation (C&A) of systems/networks and implementation of cyber security requirements and procedures across the National Security Sciences Directorate at Oak Ridge National Laboratory (ORNL). This role ensures compliance with DOE security policies and procedures as outlined in System Security Plans (SSPs), with a focus on system operations, maintenance, and disposal.
As part of our team, you will help be joining a vibrant group of professionals eager to provide premier customer service to ensure people and information technology remain secure. The team is collaborative and strives to ensure security practices and procedures are understood, implemented, and enforced.
Major Duties/Responsibilities:
• Oversee compliance with DOE cybersecurity policies and SSPs across multiple facilities.
• Conduct routine self-inspections, audits, and incident investigations, ensuring timely resolution and remediation.
• Manage continuous monitoring activities, system recovery processes, and contingency planning.
• Administer access controls, evaluate user accounts annually, and support ISSM in enforcing cybersecurity policy.
• Create, review, and maintain SSPs using Xacta, and support certification and accreditation activities.
• Perform and lead system certification testing, periodic and functional security testing, and annual self-inspections.
• Monitor system audit logs, execute authorized data transfers, and manage classified media in accordance with policy.
• Communicate effectively with stakeholders, document best practices, and deliver user training on security procedures.
• Uphold high ethical standards and maintain a commitment to ES&H protocols.
• Deliver ORNL’s mission by aligning behaviors, priorities, and interactions with our core values of Impact, Integrity, Teamwork, Safety, and Service. Promote equal opportunity by fostering a respectful workplace – in how we treat one another, work together, and measure success.
Basic Qualifications:
- BS / BA degree in information technology or technical equivalent and a minimum of five years of experience in cyber security and the C&A process
- Previous experience supporting SCI environments
- Security + or equivalent DoD Directive 8570 / 8140 Information Assurance Management Level I - III certification
- Working knowledge of:
- Risk Management Framework (RMF) process & requirements.
- NIST and CNSSI requirements
- Intelligence Community Directive 503 (ICD-503)
- Joint Special Access Program (SAP) Implementation Guide (JSIG)
- Excellent written and oral communication skills
- Demonstrated organizational skills
- Must be organized, self-motivated, and be able to work with minimal guidance
- Excellent written and verbal communication skills with an ability to interface with numerous cognizant security agencies, customers, and senior managers
- Previous experience in developing, testing, and collecting artifacts for RMF packages and BoEs of multiple systems
- Experience in authorized data transfers across multiple systems and different classifications
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s