Jobgether
Defense - Senior Information Systems Security Officer- Cloud
engineeringfull-timeUS
SALARY
$130k – $160k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Accountabilities
- Lead and support Risk Management Framework (RMF) activities across categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Translate NIST SP 800-53, DoD security policies, CNSS requirements, Cloud Computing SRG guidance, and AI-related security requirements into actionable security practices.
- Conduct security architecture reviews and security engineering assessments for cloud-native and containerized workloads, particularly within Azure environments.
- Evaluate security controls for Kubernetes, Docker, and other container orchestration technologies and identify opportunities to strengthen cloud security.
- Assess risks associated with generative AI, large language models, and AI/ML workloads, supporting secure and responsible adoption of these technologies.
- Develop, maintain, and manage RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related artifacts.
- Perform threat modeling, vulnerability assessments, and risk analyses tailored to cloud and emerging AI technologies.
- Partner with system architects, developers, and DevSecOps teams to embed security throughout the software development lifecycle.
- Support security control assessments and coordinate with third-party assessors and other stakeholders.
- Monitor, track, and communicate security compliance through continuous monitoring processes and provide clear visibility into the security posture.
- Provide expert guidance to technical and non-technical stakeholders while supporting secure modernization initiatives.
- Perform minimal travel as required by program needs.
- Active Secret security clearance is required.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, combined with 8+ years of cybersecurity experience, including hands-on RMF experience supporting defense systems.
- Current CISSP or CISM certification is required.
- Practical experience securing at least one major cloud platform, such as AWS, Microsoft Azure, or Google Cloud Platform, including IAM, networking, Kubernetes, and cloud security services.
- Strong knowledge of containerized environments, including Docker and Kubernetes, and associated security best practices.
- Familiarity with generative AI technologies, LLMs, and security considerations for AI/ML workloads.
- Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
- Demonstrated experience creating and maintaining RMF artifacts such as SSPs, POA&Ms, and SARs.
- Experience conducting security risk assessments in Department of War environments.
- Strong communication and collaboration skills, with the ability to work effectively with technical teams, leadership, assessors, and other stakeholders.
- Ability to translate complex security, compliance, and risk requirements into clear and actionable recommendations.
- Preferred: advanced cloud security certifications, such as Google Professional Cloud Security Engineer, CCSP, or an Azure equivalent.
- Preferred: experience integrating DevSecOps pipelines with RMF compliance processes.
- Preferred: familiarity with RMF automation and compliance tools such as Xacta, eMASS, or OpenRMF.
- U.S. citizenship or lawful permanent resident status is required due to applicable federal government employment restrictions.
- Salary: Anticipated base salary range of $130,000–$160,000, with final compensation based on experience, education, skills, location, internal equity, market data, and applicable contract requirements.
- Work arrangement: Fully remote position within the United States.
- Mission-driven work: Opportunity to support mission-critical U.S. Marine Corps programs and modern cloud security initiatives.
- Career development: Exposure to cloud modernization, DevSecOps, RMF, container security, and emerging AI/ML security challenges.
- Professional impact: Opportunity to influence security architecture, compliance, and risk management for complex government systems.
- Travel: Minimal travel requirements.
Requirements
Benefits
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply