> Markdown version of [/jobs/ext/2025584-isso-cyber-engineer](https://www.wearedevelopers.com/jobs/ext/2025584-isso-cyber-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO / Cyber Engineer - **Company:** Strategic Inc - **Location:** Springfield, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Azure, Cloud Engineering, Cloud Foundry, Cyber Security, Federated Identity Management, Key Management, Zero Trust Network Access, SAP (Applications), Toolchain, Software Vulnerability Management, Policy as Code, HybridCloud, Data Layers, Kubernetes, Information Technology - **Published:** August 11, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9086533/isso-cyber-engineer ## About the Role * Active TS/SCI clearance and the ability to pass a CI polygraph within 30 days. * Bachelor's degree in Cybersecurity, Computer Science, or a related field, or additional relevant experience in lieu of a degree. * Experience supporting NGA, DoD, or Intelligence Community accreditation efforts. * 10+ years of information systems security / ISSO experience within IC or DoD environments. * Working knowledge of the Risk Management Framework (RMF) and experience supporting ATO packages for cloud-native or hybrid-cloud systems. * Familiarity with Zero Trust Architecture principles and associated technical controls (identity federation, secrets management, policy-as-code, hardened images). * DoD 8570/8140-compliant certification (e.g., Security+, CISSP, or equivalent) at time of hire or shortly thereafter. Desired: * Experience serving as an ISSO or ISSM of record for an accredited IC or DoD system. * Familiarity with Kubernetes security tooling (Kyverno, OPA/Gatekeeper) and supply-chain security practices. * Experience supporting multi-enclave environments (TS/SCI, Secret, SBU, CAP/SAP) and cross-domain solution considerations. * CISSP, CISM, or equivalent advanced cybersecurity certification. ## Description Strategic ACI is seeking an ISSO / Cyber Engineer to support accreditation and cybersecurity for a Digital Engineering Ecosystem (DEE) supporting NGA from program stand-up. This role partners closely with platform engineering and the Enterprise Architect (who holds overall governance ownership for the program) to ensure the Cloud Native Platform, Data Layer, and Digital Engineering tool chain meet ATO and compliance requirements across TS/SCI and future SBU/Secret/CAP-SAP enclaves. The position is embedded in the core delivery team from kickoff, building Zero Trust Architecture (ZTA) hardening into the Cloud Native Platform as it is stood up, and coordinates directly with government security stakeholders on boundary definitions and compliance timelines as the team scales toward FedRAMP Azure Gov and NGA CORE onboarding. As an experienced engineering role, this position ensures completion of assigned technical and compliance tasks within estimated time frames and budget constraints while meeting established quality standards., * Support Authority to Operate (ATO) and compliance activities for the DEE across the Cloud Native Platform, Data Layer, and Digital Engineering tool chain. * Partner with platform engineering to validate Zero Trust Architecture (ZTA) implementation, including identity/access controls, secrets management, hardened container images, and Kubernetes policy enforcement. * Develop and maintain security documentation (e.g., System Security Plans, POA&Ms, risk assessments) required for accreditation of DEE components. * Support continuous monitoring, vulnerability management, and incident response coordination for the DEE environment. * Assess security implications of new tool onboarding and architecture decisions, feeding into the program's Architecture Decision Record (ADR) process. * Coordinate with government security stakeholders on accreditation timelines, boundary definitions, and compliance reviews as the platform scales toward external stakeholder integration. * Support secure onboarding processes for expanding user bases and, eventually, limited external participant access. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Speeding up Web Apps performance with WebAssembly and Emscripten](https://www.wearedevelopers.com/videos/1985-speeding-up-web-apps-performance-with-webassembly-and-emscripten) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [The Power of Developer Communities](https://www.wearedevelopers.com/videos/1109-the-power-of-developer-communities) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)