Security Engineer - ISSO

Accenture Federal ServicesChantilly, VA
5d

About The Position

At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations. Join Accenture Federal Services, a technology company and part of global Accenture, to do work that matters in a collaborative and caring community, where you feel like you belong and are empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more. Join us to drive positive, lasting change that moves missions and the government forward! Accenture Federal Services is seeking an experienced Information Systems Security Officer to lead security oversight for our secure cloud platform implementations supporting government customers. This role ensures continuous compliance with federal security standards while enabling agile delivery of cloud infrastructure solutions in classified and sensitive environments. What you’ll do: Security Program Leadership Serve as primary security authority for secure cloud platform implementations Develop and maintain Information System Security Plans (ISSP) for government systems Lead security control assessments and continuous monitoring programs Coordinate with government security officers, SCAs, ISSMs, and AOs for system authorization Risk Management & Compliance Implement and maintain Risk Management Framework (RMF) processes Conduct security control assessments using NIST 800-53 and DoD requirements Manage Plan of Action & Milestones (POA&M) and security remediation efforts Ensure continuous compliance with FedRAMP, FISMA, and DoD security standards and applicable overlays Cloud Security Architecture Design security controls for multi-cloud and hybrid government environments Implement cloud-native security solutions: encryption, IAM, network segmentation Configure security monitoring and incident response capabilities Validate security implementations against STIG and CIS benchmarks Security Integration & DevSecOps Integrate security controls into CI/CD pipelines and Infrastructure as Code Implement security automation and continuous compliance monitoring Collaborate with engineering teams to embed security throughout delivery lifecycle Conduct security reviews for cloud architecture and deployment patterns Documentation & Reporting Maintain security documentation packages for government reviews and audits in defined systems including but not limited to eMass Prepare security deliverables: SSP, SAR, security briefings, and compliance reports Support security audits, assessments, and customer security reviews Create security standards, procedures, and training materials Tools Work in AWS GovCloud, Azure Government, or Oracle Cloud Work with vulnerability scanners, SIEM, monitoring platforms Handle Infrastructure as Code security: Terraform, CloudFormation security Review container security: Kubernetes security, container scanning, runtime protection Review network security: VPC design, firewalls, intrusion detection

Requirements

  • 5 years of cybersecurity experience with government systems and cloud environments
  • 3 years of direct ISSO experience supporting federal programs or systems
  • 3 years’ experience with risk management frameworks (RMF) and security control implementation
  • 6 months of eMASS experience
  • Experience with FedRAMP, FISMA, and/or DoD security compliance requirements
  • CompTIA Security+ (current) or equivalent DoD 8570 IAT Level II certification
  • AWS certification - Solutions Architect - Associate within 6 months of start date
  • Must have an active TS SCI eligibility level clearance
  • Ability to obtain and maintain higher classifications as required

Nice To Haves

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field or 4 years of comparable work or military experience
  • CISSP, CISM, or GIAC certification
  • Cloud security certifications (AWS Security, Azure Security)
  • Strong attention to detail balanced with practical risk management approach
  • Excellent communication skills for engaging with government security officers
  • Collaborative mindset for working with agile development teams
  • Proactive approach to identifying and mitigating security risks
  • Ability to balance security requirements with operational efficiency

Responsibilities

  • Serve as primary security authority for secure cloud platform implementations
  • Develop and maintain Information System Security Plans (ISSP) for government systems
  • Lead security control assessments and continuous monitoring programs
  • Coordinate with government security officers, SCAs, ISSMs, and AOs for system authorization
  • Implement and maintain Risk Management Framework (RMF) processes
  • Conduct security control assessments using NIST 800-53 and DoD requirements
  • Manage Plan of Action & Milestones (POA&M) and security remediation efforts
  • Ensure continuous compliance with FedRAMP, FISMA, and DoD security standards and applicable overlays
  • Design security controls for multi-cloud and hybrid government environments
  • Implement cloud-native security solutions: encryption, IAM, network segmentation
  • Configure security monitoring and incident response capabilities
  • Validate security implementations against STIG and CIS benchmarks
  • Integrate security controls into CI/CD pipelines and Infrastructure as Code
  • Implement security automation and continuous compliance monitoring
  • Collaborate with engineering teams to embed security throughout delivery lifecycle
  • Conduct security reviews for cloud architecture and deployment patterns
  • Maintain security documentation packages for government reviews and audits in defined systems including but not limited to eMass
  • Prepare security deliverables: SSP, SAR, security briefings, and compliance reports
  • Support security audits, assessments, and customer security reviews
  • Create security standards, procedures, and training materials
  • Work in AWS GovCloud, Azure Government, or Oracle Cloud
  • Work with vulnerability scanners, SIEM, monitoring platforms
  • Handle Infrastructure as Code security: Terraform, CloudFormation security
  • Review container security: Kubernetes security, container scanning, runtime protection
  • Review network security: VPC design, firewalls, intrusion detection
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service