DoW Information Systems Security Manager (ISSM) - Navy

Amazon.com, Inc.
Fredericksburg, VA, United States
3 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$150,000.0 - $200,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Information Systems Custom Software Infrastructure as a Service (IaaS)
+17 more
Identity and Access Management Information Security Management Systems Development Life Cycle Software Engineering Google Cloud SARS Software Products Cloud Platform System Large Language Models Generative AI Amazon Virtual Private Cloud (VPC) Containerization Kubernetes Information Technology Devsecops Docker Plan of Action and Milestones Vulnerability Analysis

Job description

TDI is seeking a Risk Management Framework (RMF) subject matter experts as Information Systems Security Managers to support cloud-based and Artificial Intelligence (AI) integrated systems. We are looking for candidates who have demonstrated experience building and maintaining RMF packages from development and through sustainment, are technically sharp, and ready to work in a fast-paced environment on some of the nations most advanced systems. We need experts who can support ATO efforts and turn DoW Component RMF, NIST 800-53, and Cloud SRG guidance into clear, defensible deliverables. These roles require in-depth knowledge of DoW requirements and the ability to independently lead and support complex systems integrating cloud IaaS/SaaS, custom applications and AI. if you’re eager to build credibility fast, experience cutting edge technology, leading artificial intelligence models, and make a visible impact on mission systems-including cloud-native, containerized workloads-you’ll fit right in. We have multiple openings supporting DoW programs in the Northern Virginia area. Opportunities are available for both hybrid commute and remote work, depending on skill set and security clearance level. Candidates must possess an active Secret or Top-Secret security clearance., * Lead and support RMF execution and customer coordination in an IL 6 environment

  • Provide expert guidance on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoW-specific frameworks such as Cloud Computing SRG and AI-specific guidance.
  • Conduct security architecture reviews and security engineering analysis for cloud-native and containerized workloads.
  • Evaluate security controls associated with Kubernetes, Docker, and container orchestration platforms within cloud infrastructure.
  • Assess security risks related to generative AI components, including large language models (LLMs) and AI/ML workloads, ensuring responsible and compliant use.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and related RMF documentation.
  • Perform threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and AI technologies.
  • Interface with system architects, developers, and DevSecOps teams to integrate security throughout the Software Development Lifecycle (SDLC).
  • Support security control assessments (SCAs) and coordinate with third-party assessors.
  • Monitor, track, and report on security compliance posture through Continuous Monitoring (ConMon) processes.
  • Minimal travel will be required.

Requirements

  • Active Secret or Top-secret security clearance.
  • Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology, and 8+ years of cybersecurity experience, including demonstrated experience supporting Risk Management Framework (RMF) activities for Department of War (DoW) systems.
  • Security certifications such as Certified Information System Security Professional (CISSP) and/or Certified Information System Manager (CISM).
  • Practical knowledge and application of concepts with cloud platforms. Experience with AWS, Azure and/or Google Cloud Platform (GCP), including IAM, VPC, Kubernetes, and security-related services are preferable.
  • Strong knowledge of containerized environments (e.g., Docker, Kubernetes) and container security best practices.
  • Familiarity with Generative AI technologies, including LLMs and AI/ML security considerations.
  • Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
  • Experience with security risk assessments in DoW environments.

Benefits & conditions

The anticipated salary range for this position is $150,000 - $200,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range. TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States. “TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.” Powered by JazzHR

About the company

Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all