Talent.com
Information Systems Security Officer
Information Systems Security OfficerOak Ridge National Laboratory • Oak Ridge, TN, US
Information Systems Security Officer

Information Systems Security Officer

Oak Ridge National Laboratory • Oak Ridge, TN, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Select how often (in days) to receive an alert :

Overview

We are currently seeking qualified applicants with Information Systems Security Officer (ISSO) experience to support the Field Intelligence Operations Division's classified operations in the areas of Classified Intelligence IT / Information Assurance (IA), Classified R&D Computing, and physical and personnel security in the Field Intelligence Operations Division (FIOD) - where cutting-edge research and technology meets national defense. Under the Department of Energy (DOE), Office of Intelligence and Counterintelligence (IN) authorities, the FIOD serves as the ORNL focal point for all intelligence community matters and supports national security science by providing secure IT, communications, facilities, and analysis.

Purpose : The ISSO will assist the Information Systems Security Manager (ISSM) in the certification and accreditation (C&A) of systems / networks and implementation of cyber security requirements and procedures across the National Security Sciences Directorate at Oak Ridge National Laboratory (ORNL). The National Security Sciences Directorate conducts research and development to solve some of the nation's most difficult security challenges and adversaries. The directorate houses S&T leadership in cybersecurity and cyber-physical resiliency, data analytics, geospatial science and technology, nuclear nonproliferation, and high-performance computing for sensitive national security missions. The FIOD is housed within NSSD and provides the operational security, information assurance, and information technology support needed for ORNL to maintain Sensitive Compartmented Information Facilities, clearances, and systems.

Duties and Responsibilities

The ISSO is a primary stakeholder and facilitator of the continuous monitoring efforts that promote RMF compliance throughout the organization. The ISSO provides clear direction and assists programmatic IT and infrastructure support personnel with the application of security patches and secure configurations commensurate with Security Technical Implementation Guides (STIGs). The ideal candidate will have experience in designing, implementing, and managing security solutions within classified environments, with particular emphasis on leveraging Splunk for security information and event management (SIEM). Routine collaboration and consultation with the Information Systems Security Manager (ISSM) regarding the design, development, integration, and analysis of classified information systems under general supervision, the candidate is responsible for performing a full range of Information Assurance functions in support of the security needs of the ORNL FIE ISSM / Group lead.

System Security Oversight

  • Provide day-to-day cybersecurity support for classified / Sensitive Compartmented Information (SCI) systems.
  • Ensure compliance with DOE-IN, DoD, and NIST requirements across multiple facilities.
  • Develop, review, and maintain System Security Plans (SSPs) and related RMF artifacts (hardware / software lists, diagrams, PPSM, categorization forms, continuous monitoring plans, contingency plans).

Security Engineering & Compliance

  • Support design and implementation of security controls, ensuring alignment with DISA STIGs and NIST 800-53.
  • Assist with security architecture reviews, risk assessments, vulnerability analyses, and mitigation strategies.
  • Provide technical input for STIG feasibility and implementation, including possible automation of compliance checks.
  • Manage Splunk and SolarWinds environments for log collection, correlation, and monitoring.
  • Create and maintain dashboards, alerts, and reports to support real-time detection and response.
  • Investigate security incidents, document findings, and implement corrective measures.
  • Perform regular audit log reviews, authorized data transfers, and media control in accordance with policy.
  • Develop and maintain system documentation to support system authorization and accreditation.
  • Track system changes, security impact assessments, and coordinate with ISSM on approvals.
  • Conduct and support continuous monitoring activities, including vulnerability management and reporting.
  • Governance & Training

  • Conduct annual account reviews, self-inspections, and compliance testing.
  • Train users and system administrators on security procedures and policy.
  • Support ISSM in implementing local policies, reporting metrics, and preparing for inspections.
  • Continuously update and enhance documentation best practices and local security procedures, train users on these procedures, and consistently apply appropriate ES&H standards.
  • Maintain a strong commitment to the implementation and perpetuation of values and ethics.
  • Basic Requirements

  • Bachelor's degree in information technology or technical equivalent and a minimum of five years of experience in cyber security and the C&A process. An overall combination of equivalent education and experience may be considered.
  • Current TS clearance with SCI eligibility
  • Working knowledge of RMF process & requirements
  • Working knowledge of NIST and CNSSI requirements
  • Must be organized, self-motivated, and able to work with minimal guidance
  • Excellent written and verbal communication skills with an ability to interface with numerous cognizant security agencies, customers, and senior managers
  • Previous experience in developing, testing, and collecting artifacts for RMF packages and BoEs of multiple systems
  • Experience in authorized data transfers across multiple systems and different classifications
  • Desired Skills

  • Current TS clearance with SCI eligibility
  • Relevant ISSO / ISSE experience within the DoD or Intelligence Community
  • CISSP, SEC+, or other relevant certifications
  • Previous experience supporting SCI environments
  • Deep understanding of incident response procedures and enterprise security tool implementation
  • Knowledge of the DISA STIGs and configuration standards
  • Working knowledge of industry-standard tools for audit reduction, vulnerability scanning, and malware analysis (e.g., Splunk, Tenable Nessus, HBSS components, SCAP Checker, STIG viewer)
  • Experience with Security Directives, Policies, Publications, and Regulations
  • Special Requirement

    This position requires the ability to obtain and maintain a Sensitive Compartmented Information (SCI) clearance from the Department of Energy. It is a Workplace Substance Abuse (WSAP) testing designated position requiring a pre-placement drug test and ongoing random drug testing. Due to the SCI, you may also be subject to random polygraph testing.

    Security, Credentialing, and Eligibility Requirements

    For employment at ORNL, a Real ID compliant form of identification is required. ORNL is subject to DOE access restrictions. All employees must be able to obtain and maintain a federal PIV card as mandated by HSPD-12 and DOE Order 473.1A, which requires a favorable post-employment background investigation. New employees must successfully complete and pass a Federal Tier 1 background check. This investigation includes disclosure of illegal drug activities within the last year and may include substances that are illegal under federal law.

    For foreign national candidates : If you have not resided in the U.S. for three consecutive years, you are not eligible for the PIV credential and must obtain a favorable Local Site Specific Only (LSSO) risk determination. After meeting the residency requirement, you will be required to obtain a PIV credential to maintain employment.

    About ORNL

    As a U.S. Department of Energy (DOE) Office of Science national laboratory, ORNL has an 80-year legacy of addressing the nation's challenges. Our team includes over 7,000 individuals. Our goal is to create an environment where diverse perspectives are valued, supporting ORNL as a top choice for employment.

    ORNL offers competitive pay and benefits, including medical and retirement plans, flexible work hours, on-site fitness, banking, and cafeteria facilities.

    Benefits

  • Prescription Drug Plan
  • Dental Plan
  • Vision Plan
  • 401(k) Retirement Plan
  • Contributory Pension Plan
  • Life Insurance
  • Disability Benefits
  • Generous Vacation and Holidays
  • Parental Leave
  • Legal Insurance with Identity Theft Protection
  • Employee Assistance Plan
  • Flexible Spending Accounts
  • Health Savings Accounts
  • Wellness Programs
  • Educational Assistance
  • Relocation Assistance
  • Employee Discounts
  • If you have difficulty using the online application system or need an accommodation to apply due to a disability, please email : ORNLRecruiting@ornl.gov

    This position will remain open for a minimum of 5 days after which it will close when a qualified candidate is identified and / or hired.

    We accept Word (.doc, .docx), Adobe (unsecured .pdf), Rich Text Format (.rtf), and HTML (.htm, .html) up to 5MB in size. Resumes from third party vendors will not be accepted; these resumes will be deleted and the candidates submitted will not be considered for employment.

    If you have trouble applying for a position, please email ORNLRecruiting@ornl.gov.

    ORNL is an equal opportunity employer. All qualified applicants, including individuals with disabilities and protected veterans, are encouraged to apply. UT-Battelle is an E-Verify employer.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Information System Security Officer • Oak Ridge, TN, US

    Job_description.internal_linking.related_jobs
    Information Security Manager

    Information Security Manager

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Manager to oversee security operations and ensure compliance with federal standards. Key Responsibilities : Develop and implement security policies,...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Manager, Information Security

    Senior Manager, Information Security

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    Manager, Information Security Risk Management.Key Responsibilities Lead the supplier governance program and oversee supplier due diligence processes Partner with stakeholders for supplier sourci...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Assistant Manager

    Assistant Manager

    Sonic • Andersonville, TN, US
    serp_jobs.job_card.full_time
    Hot burgers, cold shakes, and little moments of magic right in the neighborhood.At SONIC, we do things a little differently. We find the fun, the moment of chill in the everyday.Working at SONIC, yo...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Manager, Offensive Security

    Senior Manager, Offensive Security

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    Key Responsibilities Lead Red Team operations and development, mentoring less experienced staff Conduct assessments to identify vulnerabilities in software, systems, and networks Manage the Bug...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Senior SOC Manager

    Senior SOC Manager

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Operations Center (SOC) Manager.Key Responsibilities Oversee daily SOC activities for timely detection and response to security incidents Manage, mento...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information System Security Engineer

    Information System Security Engineer

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information System Security Engineer.Key Responsibilities : Serve as the technical lead for system security engineering efforts supporting FISMA and FedRAMP ATOs Devel...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Security Systems Administrator

    Security Systems Administrator

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a System Administrator (Security Systems).Key Responsibilities Manage and maintain security systems and infrastructure Implement security protocols and monitor system pe...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Information Security Architect

    Information Security Architect

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Lead Architect.Key Responsibilities Develop and implement information security architecture strategy and roadmap Provide guidance and oversight t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Systems Engineer

    Information Systems Engineer

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Systems Engineer to oversee data center infrastructure and support relevant systems. Key Responsibilities Provide operational support for hypervisors, VDI, ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Business Information Security Officer

    Business Information Security Officer

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a Business Information Security Officer (BISO).Key Responsibilities Integrate business partner associates into risk prioritized cybersecurity processes and controls Part...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Security Analyst

    Senior Security Analyst

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    Security Analyst, Falcon Complete (Hybrid).Key Responsibilities Exercise incident handling processes across Windows, Mac, and Linux platforms Perform malware analysis and develop processes for i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Attack Surface Management Security Architect 1444153

    Attack Surface Management Security Architect 1444153

    Cisco Systems, Inc. • Knoxville, TN, United States
    serp_jobs.job_card.permanent
    The application window is expected to close on : October 18, 2025.Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.The successful a...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cyber Security Analyst

    Cyber Security Analyst

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Security Analyst for a 100% remote W2 contract position.Key Responsibilities Monitor, manage, and respond to security events in collaboration with the internal cy...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Field Chief Information Security Officer

    Field Chief Information Security Officer

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a Field CISO to serve as a trusted advisor to clients in navigating cybersecurity challenges.Key Responsibilities Act as a virtual CISO for key clients, providing executi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Operational Technology Security Analyst

    Operational Technology Security Analyst

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for an Operational Technology Security Analyst to support the delivery of Operational Technology security services. Key Responsibilities Assist with delivering OT services inc...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Security Analyst

    Security Analyst

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Analyst to enhance the protection of its systems, networks, and applications.Key Responsibilities Monitor security dashboards, alerts, and logs; assist in tria...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Security Analyst

    Information Security Analyst

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Tech Analyst Jr.Key Responsibilities Administer and maintain security tools, monitoring alerts for cybersecurity threats Investigate and respond ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Cyber Security Architect III

    Cyber Security Architect III

    VirtualVocations • Knoxville, Tennessee, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Security Architect / Engineer III.Key Responsibilities Guide the design and implementation of secure solutions across business and IT support areas Develop securit...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new