DoW Cloud Information Systems Security Officer (ISSO)
- Own the RMF “engine room”: maintain day-to-day RMF execution across all phases (categorization, control selection, implementation, assessment, authorization, and continuous monitoring) for modern cloud-hosted systems.
- Apply DoD cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoD-specific frameworks such as the Cloud Computing SRG and applicable AI-related guidance.
- Develop and maintain RMF artifacts including SSPs, SARs, POA&Ms, control implementation details, evidence mappings, and assessor-ready supporting documentation with strict traceability from control → implementation → evidence.
- Execute POA&M management with discipline: validate substantiation, track owners/dates, drive remediation follow-through, and ensure closure evidence is real and audit-ready (no “paper POA&Ms”).
- Support security change governance activities (CCB inputs, impact analyses, drift detection) and ensure artifacts/evidence stay aligned to reality after each approved change.
- Conduct security engineering analysis for cloud-native and containerized workloads hosted in Google Cloud Platform (GCP), including baseline validation for Kubernetes/Docker environments and control-implementation verification.
- Assist with threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and (as applicable) AI/ML and LLM components.
- Partner with system architects, developers, DevSecOps, and platform teams to integrate security throughout the SDLC and translate requirements into actionable implementation steps and measurable evidence outputs.
- Support SCAs and coordinate with third-party assessors by preparing artifacts, evidence packages, interview prep, and timely responses to RFIs including managing RFI intake, tracking, and closure.
- Monitor, track, and report security compliance posture through Continuous Monitoring (ConMon) processes and recurring metrics/dashboards including vulnerability and configuration compliance trends, control health, and evidence freshness.
- Optimize and automate compliance operations: develop repeatable workflows (scripts/automation; responsible AI-enabled methods where appropriate) to reduce manual evidence collection, improve quality, and shorten cycle time.
- Active Top-secret clearance.
- Required security certification: CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO. (More standard for IAM II / ISSO-type role)
- Demonstrated experience supporting or leading DoD RMF for modern systems, including authorization package contributions and post-ATO sustainment activities.
- Strong working knowledge of NIST 800-53 and practical RMF execution (inheritance strategy, evidence planning, assessor/AO engagement support, and risk tradeoffs).
- Hands-on cloud security experience (AWS/Azure/GCP) including IAM, logging/monitoring, networking, encryption/KMS, and secure architecture patterns; GCP experience preferred.
- Experience with STIG implementation/validation in production environments.
- Strong writing and communication skills: able to produce assessor- and customer-ready deliverables with minimal oversight in a high-change environment.
- Demonstrated adoption of automation (scripts, repeatable workflows, and responsible AI-enabled methods) to reduce manual compliance effort and improve quality.
- Comfort operating in high-change environments with CCBs, shifting priorities, and competing stakeholder demands.
- Cloud certification (e.g., CCSP or cloud provider security/professional certs such as Google’s Professional Cloud DevOps Engineer, Professional Cloud Security Engineer, or Professional Cloud Network Engineer).
If you are looking for a template-driven RMF job, stable requirements, or work where someone else keeps the artifacts/evidence aligned to reality, this will not be a fit. If you can execute RMF with urgency, run disciplined POA&M and evidence management, keep pace with CCB-driven change, and deliver customer-ready outputs with minimal oversight, we want to meet you.
TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.
“TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.”
Recommended Jobs
MRI Tech - Evening
Cooperidge Consulting Firm is seeking an MRI Technologist (Evening Shift) for a top healthcare client in Roanoke, VA . This role performs high-quality MRI exams across a diverse patient popul…
Clinical Care Transition Educator/ Registered Nurse - Per Diem
Extraordinary Careers. Endless Possibilities. With the nation’s largest home infusion provider, there is no limit to the growth of your career. Option Care Health, Inc. is the largest independen…
Group Exercise Instructor (Part Time) (Williamsburg)
Description: The Group Exercise Instructor works under the direction of the Health Club Manager and is responsible for planning and instructing assigned classes. HOURS Instruction times vary be…
AQP S57 - Acquisition Program Analyst, Senior - TS/SCI
Acquisition Program Analyst – Senior Clearance: TS/SCI Onsite 5 days per week This position provides critical PEM support for programs of record (PoR) across the AQP portfolio. SAF/AQP – …
Kennedy Shelter - Cook, FT
Title: Cook Department: Kennedy Emergency Shelter Reports to: Kitchen Manager Salary: $20-$21 FLSA Status: Non-Exempt About Us: Shelter House was established in 1981 as a grassroot…
Janitorial Crew
Join a fast-paced, growing, and exciting company full of great opportunities! Kellermeyer Bergensons Services (KBS) has an immediate opportunity to join our Janitorial Services Team as a Janitorial…
Leasing Consultant
Overview: As a Leasing Consultant you will be responsible for the leasing, marketing and maintaining positive resident relations of residential apartments, including: Assist Property Manage…
Senior/Staff/Senior Staff Software Engineer, 3DGS Enablement (SDK)
Senior/Staff/Senior Staff Software Engineer, 3DGS Enablement (SDK) About Ofinno: Ofinno is a leading research and development lab headquartered in Reston, Virginia, specializing in advancing co…
System Administrator
Procon is a top-ranked construction management and technology consulting firm with 25 years of experience delivering high‑impact projects across the U.S. and worldwide. An ENR Top 100 CM/PM firm for …
Auto Body Paint Technician
For a quick application text APPLY1 to 82174 About Dent Wizard Dent Wizard is the nation’s undisputed leader in automotive reconditioning services and vehicle protection products – and our suc…