Defense - Senior Information Systems Security Officer- Cloud

Posted Yesterday
Be an Early Applicant
Arlington, VA, USA
In-Office
130K-160K Annually
Senior level
Computer Vision • Cybersecurity
The Role
Lead RMF and ATO activities for U.S. Marine Corps cloud workloads. Conduct Azure cloud and container security reviews, assess Kubernetes and Docker environments, evaluate generative AI and ML security risks, develop SSPs, SARs, and POA&Ms, perform threat modeling and vulnerability assessments, support control assessments, and manage continuous monitoring. Collaborate with architects, developers, DevSecOps teams, and assessors to maintain compliance with DoD, NIST, and cloud security requirements.
Summary Generated by Built In
Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.

TDI is seeking a hands-on Information Systems Security Officer (ISSO) to support U.S. Marine Corps cloud modernization in a fully remote role. You’ll help application teams securely onboard mission-critical workloads to modern cloud environments while supporting ATO efforts and translating RMF, NIST SP 800-53, and Cloud SRG requirements into actionable security deliverables.

 This is a fully remote position supporting mission-critical U.S. Marine Corps programs. An active Secret clearance is required.

RESPONSIBILITIES:
  • Lead and support RMF activities throughout all phases (categorization, control selection, implementation, assessment, authorization, and continuous monitoring).
  • Provide expert guidance on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoD-specific frameworks such as Cloud Computing SRG and AI-specific guidance.
  • Conduct security architecture reviews and security engineering analysis for cloud-native and containerized workloads hosted in Azure.
  • Evaluate security controls associated with Kubernetes, Docker, and container orchestration platforms within Azure.
  • Assess security risks related to generative AI components, including large language models (LLMs) and AI/ML workloads, ensuring responsible and compliant use.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and related RMF documentation.
  • Perform threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and AI technologies.
  • Interface with system architects, developers, and DevSecOps teams to integrate security throughout the Software Development Lifecycle (SDLC).
  • Support security control assessments (SCAs) and coordinate with third-party assessors.
  • Monitor, track, and report on security compliance posture through Continuous Monitoring (ConMon) processes.
  • Minimal travel will be required.
QUALIFICATIONS:
  • Active Secret security clearance.
  • A current Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification is required.
  • Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology, and 8+ years of cybersecurity experience, including demonstrated experience supporting Risk Management Framework (RMF) activities for Department of War (DoW) systems.
  • Candidates must have practical, hands-on experience with at least one cloud platform, including AWS, Microsoft Azure, or Google Cloud Platform (GCP), with demonstrated experience in IAM, VPC/networking, Kubernetes, and cloud security services.
  • Strong knowledge of containerized environments (e.g., Docker, Kubernetes) and container security best practices.
  • Familiarity with Generative AI technologies, including LLMs and AI/ML security considerations.
  • Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
  • Experience writing and maintaining RMF artifacts such as SSPs, POA&Ms, and SARs.
  • Strong communication skills and ability to collaborate effectively with technical and non-technical stakeholders.
  • Experience with security risk assessments in DoW environments
PREFERRED QUALIFICATIONS:
  • Advanced cloud security certifications, such as Google Professional Cloud Security Engineer, Cloud Certified Security Professional or Azure equivalent.
  • Experience integrating DevSecOps pipelines with RMF compliance processes.
  • Familiarity with automation tools for RMF documentation and control testing (e.g., Xacta, eMASS, OpenRMF).
PAY RANGE:
The anticipated salary range for this position is $130,000 - $160,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.

Skills Required

  • Active Secret security clearance
  • Current CISSP or CISM certification
  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology
  • 8+ years of cybersecurity experience
  • Experience supporting RMF activities for Department of War systems
  • Hands-on experience with AWS, Microsoft Azure, or Google Cloud Platform
  • Experience with IAM, VPC/networking, Kubernetes, and cloud security services
  • Experience with Docker, Kubernetes, and container security best practices
  • Familiarity with generative AI, LLMs, and AI/ML security considerations
  • Knowledge of NIST SP 800-53, DoD RMF, FedRAMP, and related cybersecurity frameworks
  • Experience writing and maintaining SSPs, POA&Ms, SARs, and other RMF artifacts
  • Strong communication and stakeholder collaboration skills
  • Experience with security risk assessments in Department of War environments
  • Advanced cloud security certification, such as Google Professional Cloud Security Engineer, CCSP, or Azure equivalent
  • Experience integrating DevSecOps pipelines with RMF compliance processes
  • Familiarity with Xacta, eMASS, or OpenRMF
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Washington, DC
50 Employees
Year Founded: 2001

What We Do

For over 20 years, TDI’s one and only passion has been delivering cybersecurity solutions to effectively manage the business of cyber. At the global vanguard of innovation, we created Cybersecurity Performance Management (CPM) and the industry-leading CPM platform, CnSight®. Combining CnSight® with our remarkable historical experience and our exceptional capabilities of cyber operations and compliance, we offer Managed Cybersecurity Performance, a first of its kind managed CPM offering. TDI’s CPM solutions mitigate risk, reduce ransomware, provide continuous compliance, improve cyber-ROI, and provide comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, particularly for Boards of Directors. CnSight® is the industry-leading Cybersecurity Performance Management (CPM) platform which mitigates risk, reduces ransomware, provides continuous compliance, improves cyber-ROI, and provides comprehensive instantaneous visibility into how an organization is performing against its cyber strategy, so executives and Boards may effectively manage the business of cybersecurity– the result: reduced stress, better performance, less cost, and a true understanding of cyber investment. With CnSight® at its core, TDI’s Managed Cybersecurity Performance offering ensures strategic cyber goals are met to protect an organization’s investments, assets and reputation by reducing the risk of ransomware, lowering cyber insurance premiums, improving ROI, reducing legal and fiduciary liability, delivering actionable reporting to the Board and C-Suite, providing on-call advice, ensuring continuous compliance and providing subject matter expertise on the organization’s behalf in meeting with the C-Suite and the Board, dealing with auditors, and supporting budget decisions – the result: reduced stress, better performance, less cost, and a true understanding of cyber investment.

Similar Jobs

Remote or Hybrid
US
15100 Employees
143K-214K Annually
Remote or Hybrid
US
15100 Employees
135K-188K Annually

CDW Logo CDW

Senior Security Engineer

Information Technology
Remote or Hybrid
US
15100 Employees
109K-151K Annually

DraftKings Logo DraftKings

Software Engineering Manager

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
161K-201K Annually

Similar Companies Hiring

HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees
Blissway Thumbnail
Computer Vision • Fintech • Hardware • Internet of Things • Machine Learning • Software • Transportation
Denver, CO
24 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account