GRC Engineer/ISSO

OPTIMAL BUSINESS SOLUTIONS
United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$150,000.0 - $170,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Cloud Computing Security Cyber Security Continuous Integration Information Security Management Microsoft Dynamics Systems Development Life Cycle Azure Active Directory Software Engineering Software Vulnerability Management Privacy Controls
+1 more
Devsecops

Job description

We are seeking a highly experienced Senior GRC Engineer / Information System Security Officer (ISSO) to support a long-term federal cybersecurity program.

This is not a traditional, documentation-only ISSO or checkbox-compliance position. The ideal candidate will operate at the intersection of governance, risk, and compliance, cloud security, and enterprise engineering.

The Senior GRC Engineer / ISSO will apply deep knowledge of the Risk Management Framework, FedRAMP, and NIST security requirements while partnering with cloud, platform, security, and engineering teams to turn regulatory requirements into practical, scalable security controls.

The successful candidate will help accelerate Authority to Operate activities, improve continuous monitoring, reduce audit friction, and embed security into cloud platforms and enterprise technology environments., * Serve as a senior cybersecurity and compliance advisor to system owners, engineers, technical teams, and federal stakeholders.

  • Lead and support Risk Management Framework activities throughout the system development lifecycle.
  • Translate NIST, FedRAMP, and federal security requirements into practical technical guidance, cloud security guardrails, and repeatable implementation patterns.
  • Support the development, review, and maintenance of security authorization documentation, including System Security Plans, Security Assessment Reports, Plans of Action and Milestones, control implementation statements, and supporting evidence.
  • Help accelerate ATO and ongoing authorization efforts by identifying security requirements and implementation gaps early in the development process.
  • Partner with Azure, Microsoft 365, platform engineering, cloud security, and DevSecOps teams to design secure and compliant solutions.
  • Evaluate the implementation and effectiveness of security and privacy controls.
  • Support continuous monitoring through automated evidence collection, vulnerability management, metrics, dashboards, and control validation.
  • Analyze control inheritance, shared-service dependencies, and cloud shared-responsibility models.
  • Prepare teams for independent security assessments, audits, and regulatory reviews.
  • Track cybersecurity risks, vulnerabilities, findings, and remediation activities.
  • Provide clear status updates, risk assessments, and recommendations to technical and nontechnical stakeholders.
  • Manage multiple priorities, deadlines, and client requirements in a fast-paced federal consulting environment.
  • Identify opportunities to improve GRC, ATO, continuous monitoring, and security engineering processes.

Requirements

  • 7-10 or more years of experience in cybersecurity, governance, risk, compliance, security engineering, information assurance, or ISSO functions.
  • Strong experience applying the Federal Risk Management Framework.
  • Strong knowledge of NIST SP 800-53 security and privacy controls.
  • Experience supporting federal ATO, ongoing authorization, or continuous authorization activities.
  • Experience with FedRAMP requirements and cloud security compliance.
  • Required professional experience with Microsoft Azure, including Azure security, governance, compliance, or cloud control implementation.
  • Required professional experience with Microsoft 365, including Microsoft 365 security, compliance, identity, governance, or enterprise administration.
  • Experience working with Microsoft Entra ID, formerly Azure Active Directory, and identity and access management concepts.
  • Understanding of cloud control inheritance, shared-responsibility models, and enterprise cloud governance.
  • Experience working within the software development lifecycle and familiarity with CI/CD, DevSecOps, or enterprise engineering practices.
  • Experience partnering with cloud engineers, architects, developers, system owners, and security teams.
  • Demonstrated ability to translate regulatory and security requirements into practical technical recommendations.
  • Strong client-facing communication, consulting, and stakeholder-management skills.
  • Demonstrated success managing competing priorities and delivering results in a demanding environment.
  • Ability to work independently, exercise sound judgment, and communicate risks clearly.
  • Experience supporting federal agencies, regulated industries, financial services organizations, or large enterprise environments., * Have you spent at least 2-3 years with a Big 4 firm, major technology company, defense contractor, or similarly structured engineering organization?
  • Do you have at least 7 years of experience in cybersecurity, GRC, security engineering, information assurance, or ISSO work?
  • Are you a U.S. citizen and able to successfully obtain and maintain a federal Public Trust clearance?

Experience:

  • RMF: 3 years (Required)
  • FedRAMP: 3 years (Required)
  • NIST standards: 3 years (Required)
  • Microsoft Dynamics 365: 3 years (Required)
  • Azure: 3 years (Required)

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • 401(k)
  • Paid time off
  • Vision insurance
  • Dental insurance, * 401(k)
  • Dental insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all