Unknown Company

Principal Cybersecurity Systems Security Officer

washington, dc • Posted Today
Remote Contract Professional Services

The Principal Cybersecurity Systems Security Officer at Amtrak provides cybersecurity governance and risk management for assigned systems and services, with a focus on maintaining acceptable risk levels and audit readiness. This position establishes security governance practices, improves control effectiveness, and ensures security is built into system design and day-to-day operations while coordinating cybersecurity staff and partners to reduce risk and support operational objectives.

Key responsibilities

  • Develop and maintain security documentation, including System Security Plans (SSPs) , Security Design Reviews , Secure Design Directives (SDDs) , risk assessments, exception requests, and remediation plans.
  • Act as the primary cybersecurity advisor for Agile Release Trains (ARTs) , working with business, portfolio, product, architecture, and engineering stakeholders to embed security-by-design, DevSecOps practices, and risk management into Program Increment (PI) Planning and solution delivery.
  • Lead security architecture and design reviews to uncover security gaps, evaluate risks, and select mitigating and compensating controls.
  • Lead assessment and audit assurance readiness by setting evidence strategies, maintaining high-quality security documentation, coordinating reviews, and ensuring timely closure of findings and gaps.
  • Drive security assessment and authorization or attestation activities by keeping security plans, control implementations, and decision artifacts current, traceable, and defensible.
  • Operate and evolve continuous monitoring programs by defining security telemetry needs, reviewing control health, overseeing vulnerability and configuration management activities, and tracking residual risk trends.
  • Lead risk decision-making, including prioritizing remediation, adjudicating exceptions and compensating controls, and escalating material risks with impact statements and recommended actions.
  • Coordinate with engineering, architecture, and operations stakeholders to integrate security requirements into system design, change management, release readiness, and lifecycle sustainment processes.

Required qualifications

  • Bachelor’s Degree or equivalent combination of education, training, and/or relevant experience.
  • 7 years of relevant work experience, or 11+ years in lieu of degree.
  • ISC2 CISSP (Certified Information Systems Security Professional) .

Preferred qualifications

  • Bachelor’s Degree in Cybersecurity, Information Systems , or equivalent combination of education, training, and/or relevant experience, plus 9 years of relevant work experience.
  • Industry-standard certifications such as CISM , CISA , CRISC , GCIH , GPEN , CEH , CHFI , Security+ , CASP , OSCP , and others.

Tools, frameworks, and technologies

  • Agile Release Trains (ARTs), DevSecOps, Program Increment (PI) Planning
  • ISO/IEC 27001 , NIST RMF , NIST CSF , CIS Controls
  • GRC tooling, OT/ICS , and DOT regulations

Location and work arrangement

  • Washington, DC , Philadelphia, PA , or Wilmington, DE (remote)
  • Work arrangement: 02-Remote Optional
  • Relocation offered: No
  • Travel requirements: 0 - 5%

Compensation

USD 113,200 - 146,664 per year.

Additional details

  • Minimum experience: 7 years
  • Requisition ID:

Benefits

  • Health, Dental, and Vision Insurance
  • 401K with Employer Match
  • Generous Paid Time Off
  • Wellness Programs
  • Railroad Retirement Benefits
  • Paid Caregiving Days and Backup Care
  • Health Savings Account
  • Public Service Student Loan Forgiveness
  • Fertility and Family Building Benefits
  • No-cost Personal Health Advocate
  • Student Loan Assistance
  • Adoption and Surrogacy Assistance
  • Medical Plan Opt-out Credit
  • Tuition and Education Reimbursement
  • Paid Family Leave
  • Life Insurance
  • Rail Pass Privileges
  • Short- and Long-term Disability Insurance
  • Employee Assistance Program
  • No-cost Financial Advisor Sessions
  • Commuter and Flexible Spending Accounts

Knowledge, skills, and abilities

  • Build cross-functional alignment and lead complex cross-functional programs.
  • Strong written and verbal communication skills, including translating technical findings and regulatory requirements.
  • Demonstrated experience performing security architecture reviews, risk assessments, threat modeling, vulnerability management, and security control evaluations across applications, infrastructure, networks, and cloud environments.
  • Demonstrated success building or scaling an ISSO/ISSM operating model across multiple products, platforms, or business units.
  • Expert knowledge of cybersecurity governance, risk management, and control frameworks, including mapping requirements to implemented controls and measurable evidence.
  • Design and operate continuous monitoring programs, including security telemetry, vulnerability management, configuration baselines, exception handling, and metrics.
  • Lead audit and assurance activities, including preparing control narratives, evidence packages, and stakeholder responses under tight deadlines.
  • Experience implementing or operating an ISO/IEC 27001-aligned information security management system (ISMS) and supporting external audits and attestations.
  • Strong knowledge of cybersecurity frameworks and standards, including NIST RMF, NIST CSF, CIS Controls, and other applicable industry and regulatory frameworks.
  • Knowledge of OT/ICS cybersecurity principles, including cyber-to-physical risk, safety impacts, and operational constraints that affect control selection and implementation.
  • Experience with GRC tooling (controls library management, evidence workflows, risk registers) and security KPI/KRI design.
  • Experience coordinating third-party risk and contract security requirements for cloud/SaaS and managed service providers.
#J-18808-Ljbffr

Principal Cybersecurity Systems Security Officer in washington at Unknown Company

Typical pay
$32,240–$39,520

For context, most security guards earn between $32,240–$39,520 a year according to Bureau of Labor Statistics wage data. What this particular role pays is set by the employer — check the description above.

This position is listed as contract and able to be worked remotely.

Back to Job Search