Information Systems Security Officer

Raft Company Website

• $150K — $190K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience in ISSO, ISSM, cybersecurity compliance, or information assurance.
  • Strong understanding of Risk Management Framework and NIST guidelines (e.g., SP 800-37, SP 800-53, SP 800-60).
  • Experience with RMF security controls in cloud-native settings, particularly Kubernetes and containers.
  • Proficient in developing RMF artifacts like SSPs, traceability matrices, and risk assessments.
  • Familiarity with continuous monitoring and DISA STIG compliance in federal or DoD environments.
  • Strong organizational and prioritization skills for security activities across multiple systems.
  • Active Secret clearance with the ability to obtain Top Secret clearance.

Responsibilities

  • Oversee ISSO functions across product contracts with consistent RMF practices.
  • Develop RMF authorization packages, including necessary security documentation.
  • Translate system architectures into security control implementation statements and policies.
  • Coordinate with various stakeholders to ensure evidence collection and maintenance of authorization readiness.
  • Work with engineering teams to automate evidence collection and compliance reporting.
  • Conduct continuous security risk assessments in cloud-native environments.
  • Manage POA&Ms from identification through closure, overseeing risk prioritization and remediation efforts.

Benefits

  • Fully covered healthcare, dental, and vision coverage.
  • 401(k) with company match.
  • Unlimited PTO plus 11 paid holidays.
  • Education and training benefits.
  • Generous referral bonuses.
  • Opportunities for professional growth and development.
Full Job Description
This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S.

About the role:

As an Information Systems Security Officer and Manager, you will manage security and compliance activities supporting Raft's cloud-native products and customer environments. You will work closely with engineering and program teams to apply the Risk Management Framework, maintain accurate authorization documentation, assess security risk, and support IATT and ATO efforts across systems at different stages of authorization.

This role requires strong working knowledge of RMF and NIST guidance and experience applying security controls in Kubernetes, containerized workloads, and other cloud-native environments.
What you will do
  • Provide ISSO oversight across Raft's product contracts, applying consistent RMF practices while accounting for each customer's system boundary and authorization requirements.
  • Develop and maintain mature RMF authorization packages, including System Security Plans, security control traceability matrices, Ports Protocols and Services Management artifacts, architecture and data-flow diagrams, POA&Ms, and bodies of evidence.
  • Translate system architectures and operational processes into accurate control implementation statements, policies, procedures, and supporting evidence aligned with applicable security control baselines.
  • Coordinate control owners, engineers, system administrators, and program stakeholders to collect evidence, address gaps, prepare for assessments, and maintain authorization readiness across supported environments.
  • Partner with engineering teams to make evidence collection and recurring compliance reporting more automated, repeatable, reusable across systems, and traceable to authoritative sources.
  • Conduct ongoing security risk assessments using findings from cloud and Kubernetes posture reviews, vulnerability and CVE analysis, DISA STIG scans, network monitoring, software-supply-chain reviews, configuration-drift detection, and endpoint protection tools.
  • Manage POA&Ms from identification through validated closure, including risk prioritization, owners, milestones, due dates, remediation evidence, and status reporting.
  • Evaluate proposed architecture, configuration, boundary, and deployment changes for security-control and authorization impact.
  • Conduct continuous monitoring, configuration reviews, control assessments, and readiness reviews; embed security requirements early and help technical teams select practical mitigations.

What we are looking for:
  • At least four years of experience in ISSO, ISSM, cybersecurity compliance, information assurance, or a closely related role.
  • Strong understanding of the Risk Management Framework and applicable NIST guidance, including NIST SP 800-37, NIST SP 800-53 Revision 5, and NIST SP 800-60.
  • Demonstrated experience applying RMF and NIST security controls in cloud-native environments, including Kubernetes and containerized workloads.
  • Experience developing and maintaining RMF artifacts such as SSPs, control implementation statements, traceability matrices, PPSM packages, POA&Ms, risk assessments, assessment plans and reports, vulnerability results, and supporting evidence.
  • Experience with continuous monitoring, vulnerability management, DISA STIG compliance, security assessments, and remediation tracking in federal or DoD environments.
  • Ability to organize and prioritize security activities, evidence, risks, and authorization milestones across multiple systems and customer environments.
  • Ability to understand technical architectures and findings, connect them to security controls and mission risk, and communicate clearly with engineers, program leaders, and security stakeholders.
  • Security+ or another qualifying DoD 8140 or contract-required certification at hire, or the ability to obtain it within six months of employment with Raft.

Highly preferred:
  • Bachelor's degree in cybersecurity, information assurance, information technology, or a related field.
  • CISSP, CISM, CISA, CGRC, or another relevant advanced cybersecurity certification.
  • Experience with eMASS or a similar governance, risk, and compliance tool.
  • Experience supporting or completing an IATT or ATO process.
  • Experience securing Kubernetes-based DevSecOps platforms or software factories, particularly within Platform One or a comparable DoD environment.
  • Experience implementing or assessing FIPS requirements.
  • Experience writing and reviewing RMF control implementation statements, security policies, and procedures.
  • Experience communicating security risk and authorization status to program or executive leadership.

Clearance Requirements:
  • Active Secret security clearance with the ability to obtain and maintain a Top Secret security clearance.

Salary Range: $150,000.00 - $190,000.00

Work Type:
  • The selected candidate will work onsite in Honolulu, Hawaii; Hanscom Air Force Base, Massachusetts; Tampa, Florida; Colorado Springs, CO; or the National Capital Region.
    The position may require up to 35 percent travel to CONUS and OCONUS locations. Candidates must possess a valid, active U.S. passport with at least six months of validity beyond the intended travel period.

What we will offer you:
  • Highly competitive salary
  • Fully covered healthcare, dental, and vision coverage
  • 401(k) and company match
  • Take as you need PTO + 11 paid holidays
  • Education & training benefits
  • Generous Referral Bonuses
  • And More!

Similar Jobs

More Jobs at Raft Company Website

  • Engineer
    $120K — $160K *
    Honolulu, HI 96817 (Honolulu County)
    Technical Services
    In-Person
  • Information Systems Security Officer
    $150K — $190K *
    Colorado Springs, CO 80918 (El Paso County)
    Information Technology
    In-Person
  • Engineer
    $140K — $180K *
    Colorado Springs, CO 80918 (El Paso County)
    Information Technology
    In-Person
  • Information Systems Security Officer
    $150K — $190K *
    Aberdeen Proving Ground, MD 21005 (Harford County)
    Information Technology
    In-Person
  • Product Manager
    $130K — $170K *
    San Antonio, TX 78228 (Bexar County)
    Aerospace & Defense
    In-Person

More Information Technology Jobs

Find similar Information Systems Security Officer jobs: