Information Systems Security Officer

Oak Ridge National Laboratory logo
Oak Ridge National LaboratoryVisit Oak Ridge National Laboratory website

Oak Ridge National Laboratory (ORNL) is a U.S. Department of Energy national laboratory conducting multidisciplinary research in computing, AI, energy, materials, nuclear science, neutron science, isotopes, and national security.

Oak Ridge, Tennessee, United States
About Oak Ridge National Laboratory

ORNL is a government-owned, contractor-operated U.S. Department of Energy research laboratory in Oak Ridge, Tennessee. UT-Battelle operates ORNL for DOE; the laboratory currently provides AI and high-performance-computing capabilities alongside science and engineering research infrastructure.

View jobs by Oak Ridge National Laboratory

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will provide cybersecurity support for classified SCI systems and maintain RMF documentation and authorization artifacts. You will implement and assess security controls, manage Splunk and SolarWinds monitoring, investigate incidents, conduct audits and vulnerability management, track system changes, train users, and support inspections and local security policies.

Requirements

  • BS/BA in information technology or technical equivalent and at least 5 years of cybersecurity and certification and accreditation experience, or equivalent education and experience
  • Active Q and/or TS/SCI clearance
  • Working knowledge of Risk Management Framework, NIST, and CNSSI requirements
  • Experience developing, testing, and collecting RMF package artifacts and bases of estimate for multiple systems
  • Experience with authorized data transfers across systems and classifications
  • Visa sponsorship is not available
  • Ability to obtain and maintain a Secret Compartmented Information clearance
  • Pass a pre-placement drug test and participate in random drug testing
  • May be subject to random polygraph testing

Responsibilities

  • Provide cybersecurity support for classified SCI systems
  • Ensure compliance with DOE-IN, DoW, and NIST requirements
  • Develop and maintain System Security Plans and RMF artifacts
  • Implement security controls aligned with DISA STIGs and NIST 800-53
  • Conduct architecture reviews, risk assessments, vulnerability analyses, and mitigation planning
  • Manage Splunk and SolarWinds monitoring environments
  • Create dashboards, alerts, and reports
  • Investigate incidents and implement corrective measures
  • Conduct audit log reviews, authorized data transfers, and media control
  • Maintain authorization documentation and continuous monitoring activities
  • Conduct account reviews, self-inspections, and compliance testing
  • Train users and system administrators on security procedures

Benefits

  • Medical plans
  • Retirement plans
  • Flexible work hours
  • On-site fitness facilities
  • On-site banking facilities
  • On-site cafeteria facilities
  • Prescription drug plan
  • Dental plan
  • Vision plan
  • 401(k) retirement plan
  • Contributory pension plan
  • Life insurance
  • Disability benefits
  • Vacation and holidays
  • Parental leave
  • Legal insurance with identity theft protection
  • Employee assistance plan
  • Flexible spending accounts
  • Health savings accounts
  • Wellness programs
  • Educational assistance
  • Relocation assistance
  • Employee discounts