Senior Principal Cyber Information Systems Security Engineer
Job Description
SAIC is seeking a Senior Principal Cyber Information Systems Security Engineer to lead Risk Management Framework (RMF) package development, management, and authorization across both unclassified and classified environments. In this role, you will serve as a senior principal authority supporting the full RMF lifecycle, from initiation through authorization and continuous monitoring for DoD enterprise IT and network modernization efforts.
This position is based in Norfolk, VA (onsite) and supports concurrent authorization activities for multiple systems, with direct coordination across program, engineering, and government stakeholders to achieve and sustain Authority to Operate (ATO).
Key Responsibilities
- Act as Senior Principal ISSE and subject matter expert responsible for leading development, management, and authorization of RMF packages across unclassified and classified environments supporting DoD enterprise IT and network modernization programs
- Lead end-to-end RMF lifecycle activities aligned to NIST SP 800-39, 800-37, 800-53, 800-53A, and 800-137 for multiple simultaneous unclassified and classified systems
- Categorize systems and information using FIPS 199 and NIST SP 800-60; select and tailor initial security control baselines using FIPS 200 and NIST SP 800-53
- Implement security controls using NIST Special Publication guidance including 800-34, 800-64, and 800-128, and document implemented security controls in a functional manner
- Assess security controls according to NIST SP 800-53A to verify correct implementation, intended operation, and achievement of desired outcomes
- Manage and maintain eMASS records for assigned systems, ensuring accuracy and completeness of all RMF artifacts, POA&Ms, and authorization documentation across the system lifecycle
- Drive RMF packages through the full authorization workflow in accordance with Navy and DoD RMF processes, coordinating with Authorizing Officials (AOs), Information System Owners (ISOs), and Program Managers to achieve and maintain ATO
- Ensure continuous monitoring based on NIST SP 800-137, NIST SP 800-37, NIST SP 800-53A, and related special publications to maintain ongoing ATO compliance
- Collaborate with engineering teams to identify, document, and implement security controls across complex DoD enterprise IT and network infrastructure environments
- Perform internal auditing functions supporting ISO/IEC 9000, 20000, and 27001, and coordinate with external auditors to ensure actions meet industry standards
- Conduct policy analysis to author or support authoring of new enterprise cybersecurity policy aligned with DoD and Navy security requirements
- Provide expert technical guidance and mentorship to junior cybersecurity team members on RMF processes, eMASS management, and ATO authorization workflows
- Serve as organizational spokesperson and prime ISSE technical contact for significant cybersecurity authorization matters requiring coordination between program teams, engineering organizations, and government stakeholders
- Support business development through technical proposal development, capability demonstrations, and customer relationship management for program re-compete and growth opportunities
Required Qualifications
- U.S. Citizen
- Bachelor’s degree with 14+ years of related experience; Master’s degree with 12+ years; or PhD or JD with 9+ years
- 10+ years of hands-on ISSE and RMF experience with demonstrated senior principal-level contributions across complex DoD program authorization environments
- Must have an Active Secret Clearance at start
- Must be able to obtain TS/SCI after start
- DoD 8570/8140 IAM Level III or IAT Level III certification required (CISSP, CISM, or equivalent)
- CompTIA Security+ CE required at minimum
- RMF lifecycle management experience covering NIST 800-37, 800-53, 800-53A, and 800-137
- Experience with eMASS system management and ATO package development
- Experience with FIPS 199/200 system categorization and security control selection
- Experience with POA&M development, tracking, and remediation management
- Experience with unclassified and classified system authorization workflows
- Background in DoD enterprise IT and network infrastructure security
Technologies
- Risk Management Framework (RMF)
- eMASS
- NIST SP 800-39, 800-37, 800-53, 800-53A, 800-137
- FIPS 199 and NIST SP 800-60
- FIPS 200
- NIST SP 800-34, 800-64, 800-128
- ISO/IEC 9000, ISO/IEC 20000, ISO/IEC 27001
- NIST Special Publication guidance
- POA&M
Compensation: USD 160,001 - 200,000 per year.
Experience Level: 10+ years minimum; structured qualifications reflect degree-dependent experience requirements.