
Senior Information Systems Security Officer – Cloud
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in District of Columbia.
• Oversee and facilitate RMF activities, including categorization, control selection, implementation, assessment, authorization, and ongoing monitoring.
• Provide guidance on DoW cloud security policies, NIST SP 800-53, CNSS policies, Cloud Computing SRG, and AI-specific directives.
• Conduct reviews of security architecture and perform security engineering analyses for Azure cloud-native and containerized applications.
• Evaluate security controls for Kubernetes, Docker, and container orchestration within Azure.
• Assess risks associated with generative AI, LLMs, and AI/ML workloads.
• Create and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related RMF documentation.
• Execute threat modeling, vulnerability assessments, and risk analyses focused on cloud and AI.
• Work collaboratively with architects, developers, and DevSecOps teams throughout the Software Development Life Cycle (SDLC).
• Assist in security control assessments and liaise with external assessors.
• Monitor, track, and communicate security compliance status through Continuous Monitoring processes.
• Active Secret security clearance is required.
• Current CISSP or CISM certification is mandatory.
• Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology is required.
• 8+ years of experience in cybersecurity, specifically with RMF for Department of War systems.
• Practical experience with AWS, Microsoft Azure, or Google Cloud Platform is essential.
• Proficiency in IAM, VPC/networking, Kubernetes, and cloud security services.
• Strong understanding of Docker, Kubernetes, and best practices in container security.
• Familiarity with Generative AI, LLMs, and security considerations for AI/ML.
• In-depth knowledge of NIST SP 800-53, DoD RMF, FedRAMP, and pertinent cybersecurity frameworks.
• Experience in writing and maintaining SSPs, POA&Ms, and SARs.
• Experience conducting security risk assessments within DoW environments.
• Ability to collaborate effectively with both technical and non-technical stakeholders.
• U.S. citizenship or lawful permanent resident status is required.
• Preferred qualifications include advanced cloud security certification, experience in DevSecOps/RMF integration, and familiarity with Xacta, eMASS, or OpenRMF.
• Fully remote work arrangement.
• Limited travel requirements.
• Commitment to equal employment opportunities.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.