Senior Information System Security Officer/Compliance Architect

Aderas, Inc
Washington, DC, United States
27 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Xacta Application Programming Interfaces (APIs) Amazon Web Services Business Analytics Applications Software System Penetration Testing Microsoft Azure Cloud Computing Security Configuration Management CompTIA Security+ Cyber Security Continuous Integration DevOps
+14 more
Identity and Access Management Information Security Management Information Systems Security Architecture Professional Key Management Network Segmentation Microsoft SharePoint Security Information and Event Management Software Vulnerability Management Policy as Code Data Logging Google Cloud Delivery Pipeline RSA Archer Platform Plan of Action and Milestones

Job description

  • Lead FedRAMP authorization workstreams: SSP ownership, control implementation narratives, inheritance strategy, and evidence governance.
  • Interpret and apply NIST SP 800-53, NIST 800-37 RMF, 800-30 risk assessment, and 800-61 incident response into system processes.
  • Partner with cloud/DevOps teams to ensure secure architectures (IAM, network segmentation, encryption, key management, logging, vulnerability management).
  • Manage and defend POA&M strategy: risk acceptance packages, remediation prioritization, milestone realism, and executive reporting.
  • Prepare for and lead support of assessments, penetration test coordination (as applicable), and government/customer reviews.
  • Establish continuous monitoring cadence and dashboards; ensure evidence is timely, correct, and traceable.
  • Drive automation-forward compliance, reusable evidence, standardized exports, “evidence-as-code” patterns, and reduction of manual screenshots.
  • Mentor junior ISSOs/analysts; define SOPs, checklists, and quality gates for artifacts and evidence.

Requirements

  • Expertise in JCAM & Federal GRC Platforms: Hands-on command of the Joint Cybersecurity Authorization Management (JCAM) platform, CSAM, or Xacta to drive audit management, control grouping, and API data exchanges with federal authorities.
  • Advanced SharePoint Architecture: Ability to architect and govern SharePoint and analytics platforms for cross-functional collaboration, secure evidence repositories, configuration control boards, and live executive metrics tracking.
  • FedRAMP 20x Pipeline Automation: Experience deploying automated compliance toolchains to generate machine-readable security data. *

  • Strong grasp of OSCAL concepts and how machine-readable controls/evidence can streamline assessment and continuous monitoring
  • Ability to implement standardized evidence pipelines (e.g., automated exports from SIEM/vuln scanners, config baseline reporting, policy-to-control mapping).
  • Familiarity with policy-as-code / compliance-as-code approaches (where appropriate) and integrating compliance checks into CI/CD.
  • Comfort translating technical telemetry into assessor-ready evidence.
  • Security Decision & Risk Management: Proven success orchestrating Plan of Action and Milestones (POA&M) remediation, establishing secure authorization boundaries, and working knowledge of managing persistent Security Decision Records under FedRAMP 2026 Consolidated Rules.

Certifications, Preferred (two or more):

  • Active CISSP, CISM, or CASP+ in good standing
  • CompTIA Security+
  • CRISC
  • CCSP (cloud security)
  • AWS/Azure/GCP Security Specialty (or equivalent advanced cloud cert)
  • ITIL (for service management alignment)

Required Degrees & Experience

  • Bachelor’s or Master’s Degree in Cybersecurity, Management Information Systems, or a related technical arena.
  • 10 years of information assurance experience backing federal authorizations (ATO) and persistent continuous monitoring.

Security Requirement

  • Active DoD Secret clearance

About the company

Aderas is looking to recruit and retain only the best and brightest. If you like working with emerging technologies, using your unique personal skills to solve technical, functional, and organizational issues, and can easily adapt to the ever-changing IT market, then Aderas is the place for you! We are a vibrant company delivering implementation services & support for enterprise solutions and custom application development. We strive to form long-term partnerships with our clients to foster an environment based on trust, a proven history of delivery, and camaraderie.

Why Aderas?

We sincerely try to shape our employees’ lives by administering a generous package of employee benefits. Our company culture encourages collaboration, creative thinking, and growth. Headquartered in Reston Town Center, in Reston, VA, the Aderas main office is a short step away from shopping, dining, and a movie theater.

Beyond the tangible and intangible rewards, Aderas provides the following:

  • Pay for Life, AD&D, Short-term disability, and Long-term disability at no cost to the employee.
  • Employer contribution toward monthly health insurance premiums.
  • 401k plan which employees are eligible for after being with the company for 3 months.
  • Safe Harbor plan in which Aderas contributes 3% of employees’ salaries once a year.
  • A week of paid training and reimbursement for approved professional courses and tests.
  • Monthly allowance for cell phone bills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

Videos

See all

Related articles

See all