> Markdown version of [/jobs/ext/1451270-grc-engineer-isso](https://www.wearedevelopers.com/jobs/ext/1451270-grc-engineer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Engineer/ISSO - **Company:** OPTIMAL BUSINESS SOLUTIONS - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Integration, Information Security Management, Microsoft Dynamics, Systems Development Life Cycle, Azure Active Directory, Software Engineering, Software Vulnerability Management, Privacy Controls, Devsecops - **Published:** July 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=abd0e3f341af4691 ## About the Role * 7-10 or more years of experience in cybersecurity, governance, risk, compliance, security engineering, information assurance, or ISSO functions. * Strong experience applying the Federal Risk Management Framework. * Strong knowledge of NIST SP 800-53 security and privacy controls. * Experience supporting federal ATO, ongoing authorization, or continuous authorization activities. * Experience with FedRAMP requirements and cloud security compliance. * Required professional experience with Microsoft Azure, including Azure security, governance, compliance, or cloud control implementation. * Required professional experience with Microsoft 365, including Microsoft 365 security, compliance, identity, governance, or enterprise administration. * Experience working with Microsoft Entra ID, formerly Azure Active Directory, and identity and access management concepts. * Understanding of cloud control inheritance, shared-responsibility models, and enterprise cloud governance. * Experience working within the software development lifecycle and familiarity with CI/CD, DevSecOps, or enterprise engineering practices. * Experience partnering with cloud engineers, architects, developers, system owners, and security teams. * Demonstrated ability to translate regulatory and security requirements into practical technical recommendations. * Strong client-facing communication, consulting, and stakeholder-management skills. * Demonstrated success managing competing priorities and delivering results in a demanding environment. * Ability to work independently, exercise sound judgment, and communicate risks clearly. * Experience supporting federal agencies, regulated industries, financial services organizations, or large enterprise environments., * Have you spent at least 2-3 years with a Big 4 firm, major technology company, defense contractor, or similarly structured engineering organization? * Do you have at least 7 years of experience in cybersecurity, GRC, security engineering, information assurance, or ISSO work? * Are you a U.S. citizen and able to successfully obtain and maintain a federal Public Trust clearance? Experience: * RMF: 3 years (Required) * FedRAMP: 3 years (Required) * NIST standards: 3 years (Required) * Microsoft Dynamics 365: 3 years (Required) * Azure: 3 years (Required) ## Description We are seeking a highly experienced Senior GRC Engineer / Information System Security Officer (ISSO) to support a long-term federal cybersecurity program. This is not a traditional, documentation-only ISSO or checkbox-compliance position. The ideal candidate will operate at the intersection of governance, risk, and compliance, cloud security, and enterprise engineering. The Senior GRC Engineer / ISSO will apply deep knowledge of the Risk Management Framework, FedRAMP, and NIST security requirements while partnering with cloud, platform, security, and engineering teams to turn regulatory requirements into practical, scalable security controls. The successful candidate will help accelerate Authority to Operate activities, improve continuous monitoring, reduce audit friction, and embed security into cloud platforms and enterprise technology environments., * Serve as a senior cybersecurity and compliance advisor to system owners, engineers, technical teams, and federal stakeholders. * Lead and support Risk Management Framework activities throughout the system development lifecycle. * Translate NIST, FedRAMP, and federal security requirements into practical technical guidance, cloud security guardrails, and repeatable implementation patterns. * Support the development, review, and maintenance of security authorization documentation, including System Security Plans, Security Assessment Reports, Plans of Action and Milestones, control implementation statements, and supporting evidence. * Help accelerate ATO and ongoing authorization efforts by identifying security requirements and implementation gaps early in the development process. * Partner with Azure, Microsoft 365, platform engineering, cloud security, and DevSecOps teams to design secure and compliant solutions. * Evaluate the implementation and effectiveness of security and privacy controls. * Support continuous monitoring through automated evidence collection, vulnerability management, metrics, dashboards, and control validation. * Analyze control inheritance, shared-service dependencies, and cloud shared-responsibility models. * Prepare teams for independent security assessments, audits, and regulatory reviews. * Track cybersecurity risks, vulnerabilities, findings, and remediation activities. * Provide clear status updates, risk assessments, and recommendations to technical and nontechnical stakeholders. * Manage multiple priorities, deadlines, and client requirements in a fast-paced federal consulting environment. * Identify opportunities to improve GRC, ATO, continuous monitoring, and security engineering processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026)