Jobs and Careers
AM

Cyber Information Security Specialist (ISSM) Level 3

Amentum
Falls Church, United Statesfull_timeVerifiedPosted 15 May 2026
💰 $230,000/yr($210,000/yr$230,000/yr)

About the role

Purpose and Impact: Provides deployed security services across ZENITH program components for the full range of security disciplines, including personnel security, information security, operational security, program protection, compartment security, and physical security.  Program has six program teams working across four customer locations.

Work Schedule: 8 hours per day x 5 days weekly. 

Essential Responsibilities: Cyber and Information Security Specialist (ISSM) Level 3 demonstrates substantive functional knowledge of all disciplines and requires almost no guidance.

  • Cyber and Information Security Specialist (ISSM) Level 3 independently and consistently demonstrates comprehensive knowledge of all disciplines.
  • INFOSEC Specialists/ISSM serve as a directorate level resource.  INFOSEC Specialist/ISSM shall provide comprehensive Information Security (INFOSEC) assistance and oversight to customers throughout the mission space in their role supporting Sponsor Information Systems Security Managers (ISSMs).  The INFOSEC Specialists coordinate with the ISSOs, who are collocated with Sponsor’s Office Departments, or Programs, to ensure that INFOSEC policy and ISSM guidance is appropriately followed and documented, and deliver outcomes as follows:
  • Review and analyze systems architecture diagrams and networks.
  • Assess security system needs and provide corrective actions into a coherent security strategy.
  • Support Assessment and Authorization (A&A) requirements and process and apply ICD 503, NISPOM, and other federal guidelines in support of systems used at contractor facilities.
  • Help in the creations of new processes to support Sponsor and partners to advance security and lower risk:
    • Cyber Reset – binning and profile system initiative.  This is a major initiative to completely change the way assessments are conducted, and risks are presented in Sponsor system.
    • Pilot and enhance Sponsor Front Office initiatives based on direct requests.
    • Create custom documentations and step-by-step processes to streamline cyber risk reduction, security relevant changes, and help maintain the current understanding of Sponsor systems.
  • Assist Sponsor systems owners and/or service providers throughout the risk management framework (RMF), including the assessment and authorization (A&A) processes, as follows:
    • Provide advice to Sponsor system owners and/or service providers on the creation of required system documentation or body of evidence; review and provide recommendation for approval or disapproval, as appropriate.  
    • Assess security and privacy controls and data protection in sponsor information systems and environments of operation as part of the initial security assessment and during operational changes affecting information systems’ security posture.
    • Assist the security control accessors (SCA), as appropriate, in performing security systems assessments and reviewing risk elements in the executive Risk System (ERS) report.
    • Create plans of action & milestones (POA&Ms) and/or request risk acceptance through a security assessor (SA), who will certify the ERS report to the appropriate authorizing official (AO) or designated AO.
  • Provide oversight and guidance to ensure compliance with Sponsor information security regulations and policies on processes and request, such as Data Transfer Request; Access Request; Service/Change Request; Purchase Request; Accountable Property Management; Waivers, including medical devices and introduction (use) of equipment /devices into SCIF; and Equipment Transport. 
  • Build relationships, to include Interagency, with system owners and stakeholders.
  • Review and approve requests to include but not limited to Sponsor system access system, crypto, hardware orders, and Sponsor portal waivers (SCIF 705, IT, DTO, medical devices, and Sponsor Certs.
  • Facilitate development, maintenance and security review of AIS security plans for computers, networks, and information systems deployed and used at contractor facilities, ensuring that sponsor and program approving signatures are acquired and documented.
  • Conduct technical exchange meetings to facilitate AIS security solutions for both industrial contractors and government systems; and produce comprehensive solutions to technically complex systems and challenges.
  • Advise and answer questions regarding Sponsor’s AIS policies, including providing recommendations on waivers and mitigations as appropriate to meet mission requirements.
  • Ensure documentation is complete and accurate in accordance with Sponsor AIS policies and requirements.
  • As necessary, support the investigation of virus/malware alerts/incidents to determine root cause, entry point of code, damage risk, and report this information.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Amentum

View company profile →