
Information Systems Security Officer – Cloud
Posted Aug 12

Posted Aug 12
This is a fully remote position, open to applicants in United States.
• Oversee and assist RMF activities through the processes of categorization, selecting controls, implementation, assessment, authorization, and ongoing monitoring.
• Offer expertise on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, Cloud Computing SRG, and AI-specific recommendations.
• Perform security architecture evaluations and security engineering assessments for Azure workloads that are cloud-native and containerized.
• Review security controls for Kubernetes, Docker, and container orchestration platforms within Azure.
• Analyze security risks associated with generative AI, large language models (LLMs), and AI/ML workloads.
• Create and update System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related RMF documentation.
• Conduct threat modeling, vulnerability assessments, and risk analyses for cloud and AI environments.
• Work in tandem with architects, developers, and DevSecOps teams to embed security within the software development lifecycle (SDLC).
• Assist in security control evaluations and collaborate with external assessors.
• Observe, monitor, and communicate the security compliance status through ongoing Continuous Monitoring processes.
• Must hold an active Secret security clearance.
• Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology is required.
• A minimum of 5 years of experience in cybersecurity, particularly with RMF activities for DoW systems.
• Possession of a security certification such as CompTIA Security+, CISSP, or CISM.
• Hands-on experience with cloud platforms, ideally Azure or GCP, including IAM, VPC, GKE, and related security services.
• In-depth knowledge of Docker, Kubernetes, containerized environments, and container security best practices.
• Understanding of generative AI, LLMs, and AI/ML security considerations is essential.
• Strong comprehension of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
• Experience in drafting and maintaining SSPs, POA&Ms, SARs, and other RMF documentation.
• Excellent communication skills and ability to collaborate with stakeholders.
• Background in performing security risk assessments in DoW environments is preferable.
• Advanced cloud security certifications are desirable.
• Experience in integrating DevSecOps pipelines with RMF compliance processes is an advantage.
• Familiarity with tools like Xacta, eMASS, or OpenRMF is a plus.
• U.S. citizenship or lawful permanent residency is required.
• Opportunity for fully remote work.
• Minimal travel requirements.
• Commitment to equal employment opportunity.
• Compensation may vary based on experience, education, skills, geographic location, internal equity, market data, and applicable contract requirements.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.