Information System Security Officer (ISSO)

Knexus Research LLC
United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cloud Engineering CompTIA Security+ Computer Literacy Identity and Access Management Information Security Management Software Architecture Google Cloud Multi-Cloud

Job description

  • Own the ATO Process: Drive the end-to-end Risk Management Framework (RMF) and ATO/cATO processes to get our cloud-based software approved for government use.
  • Translate Compliance to Code: Work hand-in-hand with our development team. You won’t be writing the code or taking coding tests, but you must be able to translate complex NIST SP 800-53 controls and DISA STIG requirements into precise, actionable technical instructions for developers.
  • Conquer the Paperwork: Author, update, and maintain critical compliance artifacts, including System Security Plans (SSP), POAMs, and continuous monitoring documentation.
  • Multi-Cloud Vigilance: Ensure our software architecture meets rigorous compliance baselines across various cloud environments (including AWS, Azure, and GCP).
  • Be the Security Liaison: Serve as the primary technical point of contact for external government assessors, ISSMs, and internal engineering stakeholders.

Requirements

Do you have experience in Security compliance frameworks implementation?, * Clearance: Must be a US Citizen with the ability to obtain and maintain a federal security clearance.

  • 1 Experience Ask: Direct and technical ATO experience with the federal government

We don’t need an Infrastructure Engineer to write code, nor do we need a rigid auditor who just says “no.” We need a Technical ISSO/ISSP who loves the challenge of the Authority to Operate (ATO) process. You will own our compliance paperwork, navigate NIST frameworks, and act as a consultative partner to our engineering team-showing them exactly how to adjust our software to clear federal hurdles., * Direct ATO Experience: Proven track record of successfully guiding commercial SaaS or cloud-based software through the federal ATO, cATO, or FedRAMP authorization processes. Prior success as an ISSO or Information System Security Professional (ISSP).

  • The “Developer Whisperer” Mindset: Strong technical literacy. You must be comfortable digging into the details of cloud architecture and containerization so you can give developers hyper-specific remediation steps, not generic compliance checklists.
  • Framework Fluency: Deep, hands-on familiarity with NIST frameworks (800-53, 800-37) and DISA STIGs.
  • Cloud Agnostic Awareness: Solid understanding of security best practices within major cloud providers (AWS, Azure, and GCP).
  • Industry Credentials: Possession of (or immediate eligibility for) standard DoD 8570/8140 IAM/IAT certifications, such as CISSP, Security+, CISM, or equivalent ISSP/ISSM aligned baselines.
  • Autonomous Drive: Exceptional organizational skills to handle heavy documentation loads independently in a fully remote environment.

About the company

Knexus has been delivering AI solutions to the government for over 20 years. Getting our tech into the hands of government operators requires navigating complex security landscapes. We are looking for an ATO Warrior-a technical compliance expert who bridges the gap between federal security requirements and modern software development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Overcoming developer challenges in multi-cloud environments

Sandeep Pal Sandeep Pal · Coffee With Developers

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

1:20 min

Introduction to multi-cloud development infrastructure

Sandeep Pal Sandeep Pal · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all