> Markdown version of [/jobs/ext/2433084-senior-information-system-security-officer-compliance-architect](https://www.wearedevelopers.com/jobs/ext/2433084-senior-information-system-security-officer-compliance-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer/Compliance Architect - **Company:** Aderas, Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Application Programming Interfaces (APIs), Amazon Web Services, Business Analytics Applications, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Configuration Management, CompTIA Security+, Cyber Security, Continuous Integration, DevOps, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Key Management, Network Segmentation, Microsoft SharePoint, Security Information and Event Management, Software Vulnerability Management, Policy as Code, Data Logging, Google Cloud, Delivery Pipeline, RSA Archer Platform, Plan of Action and Milestones - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a65c3e7373335e0a ## About the Role * Expertise in JCAM & Federal GRC Platforms: Hands-on command of the Joint Cybersecurity Authorization Management (JCAM) platform, CSAM, or Xacta to drive audit management, control grouping, and API data exchanges with federal authorities. * Advanced SharePoint Architecture: Ability to architect and govern SharePoint and analytics platforms for cross-functional collaboration, secure evidence repositories, configuration control boards, and live executive metrics tracking. * FedRAMP 20x Pipeline Automation: Experience deploying automated compliance toolchains to generate machine-readable security data. * + Strong grasp of OSCAL concepts and how machine-readable controls/evidence can streamline assessment and continuous monitoring + Ability to implement standardized evidence pipelines (e.g., automated exports from SIEM/vuln scanners, config baseline reporting, policy-to-control mapping). + Familiarity with policy-as-code / compliance-as-code approaches (where appropriate) and integrating compliance checks into CI/CD. + Comfort translating technical telemetry into assessor-ready evidence. * Security Decision & Risk Management: Proven success orchestrating Plan of Action and Milestones (POA&M) remediation, establishing secure authorization boundaries, and working knowledge of managing persistent Security Decision Records under FedRAMP 2026 Consolidated Rules. Certifications, Preferred (two or more): * Active CISSP, CISM, or CASP+ in good standing * CompTIA Security+ * CRISC * CCSP (cloud security) * AWS/Azure/GCP Security Specialty (or equivalent advanced cloud cert) * ITIL (for service management alignment) Required Degrees & Experience * Bachelor's or Master's Degree in Cybersecurity, Management Information Systems, or a related technical arena. * 10 years of information assurance experience backing federal authorizations (ATO) and persistent continuous monitoring. Security Requirement * Active DoD Secret clearance ## Description * Lead FedRAMP authorization workstreams: SSP ownership, control implementation narratives, inheritance strategy, and evidence governance. * Interpret and apply NIST SP 800-53, NIST 800-37 RMF, 800-30 risk assessment, and 800-61 incident response into system processes. * Partner with cloud/DevOps teams to ensure secure architectures (IAM, network segmentation, encryption, key management, logging, vulnerability management). * Manage and defend POA&M strategy: risk acceptance packages, remediation prioritization, milestone realism, and executive reporting. * Prepare for and lead support of assessments, penetration test coordination (as applicable), and government/customer reviews. * Establish continuous monitoring cadence and dashboards; ensure evidence is timely, correct, and traceable. * Drive automation-forward compliance, reusable evidence, standardized exports, "evidence-as-code" patterns, and reduction of manual screenshots. * Mentor junior ISSOs/analysts; define SOPs, checklists, and quality gates for artifacts and evidence. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)