> Markdown version of [/jobs/ext/45415-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/45415-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** Advanced - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Information Systems, Cloud Platform System, Information Technology - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=07c519a8f6693631 ## About the Role Do you have experience in Team management?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. * 10+ years of progressive experience in cybersecurity, information security, or IT risk management, including senior leadership responsibility. * Direct experience in a government contracting, defense industrial base, or regulated federal environment. * Demonstrated experience leading or materially supporting Cybersecurity Maturity Model Certification implementation, assessment readiness, and ongoing compliance sustainment. * Strong working knowledge of NIST SP 800-171, security control assessment practices, and the protection of Controlled Unclassified Information. * Experience with DFARS cybersecurity requirements, security documentation, risk remediation planning, and supplier or third-party security oversight. * Experience maintaining system security plans, plans of action and milestones, compliance evidence, and executive-facing risk and compliance reporting. * Proven ability to communicate security, compliance, and business risk to executives, program leaders, auditors, and non-technical stakeholders., * Master's degree in Cybersecurity, Information Systems, Business Administration, or a related discipline. * Professional certifications such as CISSP, CISM, CRISC, or equivalent. * Experience preparing for or supporting independent assessments in support of CMMC Level 2 or similar compliance frameworks. * Knowledge of SPRS reporting, contractor assessment workflows, secure enclave design, and cloud security within federal contracting environments. * Experience with security requirements flowing to subcontractors, vendors, and business partners in a government contracting supply chain. * Experience supporting business development, proposal responses, and customer discussions related to cybersecurity posture and compliance maturity. Key Competencies * Strategic thinking and business alignment * Cybersecurity leadership and team development * Risk analysis and sound judgment * Crisis management and resilience planning * Executive communication and stakeholder influence * Policy development and governance oversight * Continuous improvement and operational excellence ## Description The Chief Information Security Officer is responsible for leading the organization's enterprise-wide cybersecurity strategy, governance, risk management, and compliance program within a government contracting environment. This executive role is accountable for safeguarding Federal Contract Information and Controlled Unclassified Information, aligning security operations with business objectives, and ensuring readiness for customer, regulatory, and third-party assessments. The position requires demonstrated experience leading Cybersecurity Maturity Model Certification implementation efforts and sustaining compliance with applicable Department of Defense cybersecurity requirements., * Lead the enterprise cybersecurity strategy and operating model for a government contracting organization supporting federal and defense-related work. * Direct implementation, maturation, and sustainment of the Cybersecurity Maturity Model Certification program across the organization. * Oversee the protection of Federal Contract Information and Controlled Unclassified Information across systems, networks, cloud environments, endpoints, and third-party relationships. * Ensure alignment with applicable contractual, regulatory, and security requirements, including DFARS cybersecurity clauses and NIST-based control frameworks. * Lead development and maintenance of security governance, policies, standards, procedures, and evidence needed for assessments and audits. * Own enterprise assessment readiness, including system scoping, gap analysis, remediation planning, evidence collection, and executive reporting. * Oversee system security plans, plans of action and milestones, risk registers, and continuous monitoring activities. * Coordinate internal stakeholders, external assessors, managed service providers, and program teams to drive compliant and sustainable security operations. * Lead cyber incident response, escalation, reporting, recovery, and post-incident improvement activities in accordance with contractual and operational requirements. * Provide executive and board-level reporting on cyber risk, compliance posture, assessment readiness, and remediation progress. * Build and lead a high-performing security and compliance team capable of supporting growth, audit readiness, and secure contract execution., * Successful implementation and sustainment of the organization's CMMC compliance program. * Improved readiness for customer, regulatory, and third-party cybersecurity assessments. * Reduction in security control gaps, unmanaged risks, and overdue remediation items. * Timely and effective protection, monitoring, and reporting for systems handling sensitive government information. * Clear executive visibility into cyber risk, compliance posture, and the organization's ability to support current and future contract requirements. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)