> Markdown version of [/jobs/ext/629341-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/629341-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Knexus Research LLC - **Location:** United States (Remote available) - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Engineering, CompTIA Security+, Computer Literacy, Identity and Access Management, Information Security Management, Software Architecture, Google Cloud, Multi-Cloud - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1b96db7d7c747afc ## About the Role Do you have experience in Security compliance frameworks implementation?, * Clearance: Must be a US Citizen with the ability to obtain and maintain a federal security clearance. * #1 Experience Ask: Direct and technical ATO experience with the federal government We don't need an Infrastructure Engineer to write code, nor do we need a rigid auditor who just says "no." We need a Technical ISSO/ISSP who loves the challenge of the Authority to Operate (ATO) process. You will own our compliance paperwork, navigate NIST frameworks, and act as a consultative partner to our engineering team-showing them exactly how to adjust our software to clear federal hurdles., * Direct ATO Experience: Proven track record of successfully guiding commercial SaaS or cloud-based software through the federal ATO, cATO, or FedRAMP authorization processes. Prior success as an ISSO or Information System Security Professional (ISSP). * The "Developer Whisperer" Mindset: Strong technical literacy. You must be comfortable digging into the details of cloud architecture and containerization so you can give developers hyper-specific remediation steps, not generic compliance checklists. * Framework Fluency: Deep, hands-on familiarity with NIST frameworks (800-53, 800-37) and DISA STIGs. * Cloud Agnostic Awareness: Solid understanding of security best practices within major cloud providers (AWS, Azure, and GCP). * Industry Credentials: Possession of (or immediate eligibility for) standard DoD 8570/8140 IAM/IAT certifications, such as CISSP, Security+, CISM, or equivalent ISSP/ISSM aligned baselines. * Autonomous Drive: Exceptional organizational skills to handle heavy documentation loads independently in a fully remote environment. ## Description * Own the ATO Process: Drive the end-to-end Risk Management Framework (RMF) and ATO/cATO processes to get our cloud-based software approved for government use. * Translate Compliance to Code: Work hand-in-hand with our development team. You won't be writing the code or taking coding tests, but you must be able to translate complex NIST SP 800-53 controls and DISA STIG requirements into precise, actionable technical instructions for developers. * Conquer the Paperwork: Author, update, and maintain critical compliance artifacts, including System Security Plans (SSP), POAMs, and continuous monitoring documentation. * Multi-Cloud Vigilance: Ensure our software architecture meets rigorous compliance baselines across various cloud environments (including AWS, Azure, and GCP). * Be the Security Liaison: Serve as the primary technical point of contact for external government assessors, ISSMs, and internal engineering stakeholders. ## Related Videos - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)