CDS Information Systems Security Officer (ISSO)
Type of Requisition:
RegularClearance Level Must Currently Possess:
Top Secret/SCIClearance Level Must Be Able to Obtain:
Top Secret/SCIPublic Trust/Other Required:
NoneJob Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Cross Domain Solutions, Cybersecurity Controls, Risk Management FrameworkCertifications:
NoneExperience:
8 + years of related experienceUS Citizenship Required:
YesJob Description:
CDS Information Systems Security Officer (ISSO)
Advance your career while impacting our national security in cyber as a Cybersecurity Analyst Senior at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.
The Cybersecurity Auditor / Information Systems Security Officer (ISSO) is responsible for maintaining the operational security posture of assigned Cross Domain Solution (CDS) systems and ensuring continuous compliance with Department of Defense (DoW) and Intelligence Community (IC) security requirements, with a strong emphasis on Linux-based security auditing and continuous monitoring.
This role works closely with the Information System Security Manager (ISSM), system owners, enclave teams, and CDS engineering staff to execute day-to-day security operations focused on:
• Direct audit and review of CDS system logs and security-relevant events
• Continuous monitoring of guard behavior and data flows
• Validation of enforcement rules and configuration baselines
• Collection and organization of bodies of evidence for RMF and assessments
The Cybersecurity Auditor / ISSO provides technical expertise in:
• Linux system administration and command-line analysis
• Native log review and correlation (e.g., syslog, auditd, application logs)
• Transfer decision validation and sanitization evidence review
• Development of procedures and checklists for recurring security audits
This work ensures compliance with NIST SP 800-53, DoWI 8510.01 and CDS boundary protection requirements, and helps maintain CDS systems in an audit-ready, fail-secure posture.
RESPONSIBILITIES
• Assist the ISSM in meeting assigned duties and responsibilities in accordance with DoDI 8510.01 and NIST RMF guidance.
• Conduct continuous monitoring activities for assigned authorization boundaries, with specific focus on CDS guard behavior and data flows.
• Perform detailed security audits directly on Linux-based CDS systems, including review of operating system, application, and custom guard logs.
• Monitor guard behavior and validate data flow enforcement rules to ensure only authorized transfers occur across domains.
• Develop and maintain procedures for Linux log collection, rotation, retention, and secure storage to support audit requirements.
• Prepare, review, and update authorization documentation related to audit and monitoring controls (e.g., SSP sections, monitoring procedures, control implementation summaries).
• Conduct periodic reviews of information systems to ensure compliance with the security authorization package and applicable policies.
• Assess the security impact of system changes (e.g., configuration updates, patching, rule changes) and provide recommendations to the ISSM prior to implementation.
• Validate time synchronization, log integrity, and audit completeness across CDS components.
• Identify and troubleshoot logging gaps, misconfigurations, or failures directly on Linux systems (e.g., auditd, rsyslog, custom logging services).
• Provide log extracts, audit trails, and evidence packages to support internal and external audits and assessments.
• Ensure audit records are reviewed and documented, including identification, investigation, and resolution of anomalies.
• Ensure appropriate logging and monitoring of all internal components that make up the HSG/TSG [consider expanding or clarifying this acronym in the final posting].
• Coordinate with system and network administrators to ensure logging and monitoring requirements are embedded in system deployments and configuration baselines.
• Support RMF lifecycle activities within XACTA, including maintenance of control implementations and bodies of evidence.
• Maintain SSP sections related to monitoring and audit architecture, and keep documentation current with system changes.
• Validate STIG implementation (particularly OS and application STIGs) and audit configuration settings, and coordinate remediation for non-compliant findings.
• Assist with development and maintenance of assessment and authorization documentation and other bodies of evidence.
Education and Experience:
• 7+ years of cybersecurity experience.
• Strong Linux experience (e.g., RHEL/CentOS/Ubuntu), including command-line, log analysis, and basic system administration.
• Experience supporting DoD Risk Management Framework (RMF) and continuous monitoring activities.
• Experience reviewing DISA STIGs and correlating vulnerability findings with system logs and configuration settings.
• Working knowledge of NIST SP 800-53 Rev. 5 controls, particularly the AU (Audit) and SI (System and Information Integrity) control families.
• Experience conducting security audits, direct log/telemetry review on Linux systems, incident investigations, and preparing associated documentation or reports.
________________________________________
EDUCATION / CERTIFICATIONS
• Technical training, cybersecurity-related certification(s), or bachelor’s degree in Computer Science, Information Assurance, Cybersecurity, or a related field.
• Relevant industry certifications preferred (e.g., Security+, CISSP, CASP, CEH, Linux-related certifications like LPIC-1, RHCSA), depending on contract requirements.
Clearance: TS/SCI
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
● Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.
#GDITPriority #DefenseOCONUS
The likely salary range for this position is $106,250 - $143,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.Total compensation for international positions varies by tax, social security, and immigration statuses, as well as location. Generally, an international assignment may include allowances, premium uplifts, and/or relocation or transportation benefits, above base salary range noted.Scheduled Weekly Hours:
40Travel Required:
Less than 10%Telecommuting Options:
OnsiteWork Location:
InternationalAdditional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events atEqual Opportunity Employer / Individuals with Disabilities / Protected Veterans