Information Systems Security Officer

Raft Company Website

• $150K — $190K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in ISSO, cybersecurity compliance, or related role.
  • Strong knowledge of RMF and NIST guidance, especially SP 800-37 and SP 800-53 Rev 5.
  • Experience with RMF and NIST security controls in cloud-native contexts like Kubernetes.
  • Proven skills in developing RMF artifacts such as SSPs and risk assessments.
  • Familiarity with continuous monitoring and DISA STIG compliance in federal or DoD settings.
  • Strong organizational skills for prioritizing security activities across systems.
  • Ability to convey technical findings to both engineers and leadership.
  • Security+ or relevant certification or the ability to obtain within six months.

Responsibilities

  • Manage ISSO oversights across product contracts and ensure RMF practices are followed.
  • Develop RMF authorization packages, including essential security documentation.
  • Translate system architectures into control implementation statements and procedures.
  • Coordinate with stakeholders to gather evidence and maintain authorization readiness.
  • Automate compliance reporting and evidence collection with engineering teams.
  • Conduct ongoing assessments of security risks influenced by cloud posture and vulnerability analyses.
  • Manage POA&Ms, ensuring risk prioritization and effective remediation.

Benefits

  • Fully covered healthcare, dental, and vision coverage.
  • 401(k) with company match.
  • Flexible PTO policy plus 11 paid holidays.
  • Education and training benefits.
  • Generous referral bonuses.
Full Job Description
This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S.

About the role:

As an Information Systems Security Officer and Manager, you will manage security and compliance activities supporting Raft's cloud-native products and customer environments. You will work closely with engineering and program teams to apply the Risk Management Framework, maintain accurate authorization documentation, assess security risk, and support IATT and ATO efforts across systems at different stages of authorization.

This role requires strong working knowledge of RMF and NIST guidance and experience applying security controls in Kubernetes, containerized workloads, and other cloud-native environments.
What you will do
  • Provide ISSO oversight across Raft's product contracts, applying consistent RMF practices while accounting for each customer's system boundary and authorization requirements.
  • Develop and maintain mature RMF authorization packages, including System Security Plans, security control traceability matrices, Ports Protocols and Services Management artifacts, architecture and data-flow diagrams, POA&Ms, and bodies of evidence.
  • Translate system architectures and operational processes into accurate control implementation statements, policies, procedures, and supporting evidence aligned with applicable security control baselines.
  • Coordinate control owners, engineers, system administrators, and program stakeholders to collect evidence, address gaps, prepare for assessments, and maintain authorization readiness across supported environments.
  • Partner with engineering teams to make evidence collection and recurring compliance reporting more automated, repeatable, reusable across systems, and traceable to authoritative sources.
  • Conduct ongoing security risk assessments using findings from cloud and Kubernetes posture reviews, vulnerability and CVE analysis, DISA STIG scans, network monitoring, software-supply-chain reviews, configuration-drift detection, and endpoint protection tools.
  • Manage POA&Ms from identification through validated closure, including risk prioritization, owners, milestones, due dates, remediation evidence, and status reporting.
  • Evaluate proposed architecture, configuration, boundary, and deployment changes for security-control and authorization impact.
  • Conduct continuous monitoring, configuration reviews, control assessments, and readiness reviews; embed security requirements early and help technical teams select practical mitigations.

What we are looking for:
  • At least four years of experience in ISSO, ISSM, cybersecurity compliance, information assurance, or a closely related role.
  • Strong understanding of the Risk Management Framework and applicable NIST guidance, including NIST SP 800-37, NIST SP 800-53 Revision 5, and NIST SP 800-60.
  • Demonstrated experience applying RMF and NIST security controls in cloud-native environments, including Kubernetes and containerized workloads.
  • Experience developing and maintaining RMF artifacts such as SSPs, control implementation statements, traceability matrices, PPSM packages, POA&Ms, risk assessments, assessment plans and reports, vulnerability results, and supporting evidence.
  • Experience with continuous monitoring, vulnerability management, DISA STIG compliance, security assessments, and remediation tracking in federal or DoD environments.
  • Ability to organize and prioritize security activities, evidence, risks, and authorization milestones across multiple systems and customer environments.
  • Ability to understand technical architectures and findings, connect them to security controls and mission risk, and communicate clearly with engineers, program leaders, and security stakeholders.
  • Security+ or another qualifying DoD 8140 or contract-required certification at hire, or the ability to obtain it within six months of employment with Raft.

Highly preferred:
  • Bachelor's degree in cybersecurity, information assurance, information technology, or a related field.
  • CISSP, CISM, CISA, CGRC, or another relevant advanced cybersecurity certification.
  • Experience with eMASS or a similar governance, risk, and compliance tool.
  • Experience supporting or completing an IATT or ATO process.
  • Experience securing Kubernetes-based DevSecOps platforms or software factories, particularly within Platform One or a comparable DoD environment.
  • Experience implementing or assessing FIPS requirements.
  • Experience writing and reviewing RMF control implementation statements, security policies, and procedures.
  • Experience communicating security risk and authorization status to program or executive leadership.

Clearance Requirements:
  • Active Secret security clearance with the ability to obtain and maintain a Top Secret security clearance.

Salary Range: $150,000.00 - $190,000.00

Work Type:
  • The selected candidate will work onsite in Honolulu, Hawaii; Hanscom Air Force Base, Massachusetts; Tampa, Florida; Colorado Springs, CO; or the National Capital Region.
    The position may require up to 35 percent travel to CONUS and OCONUS locations. Candidates must possess a valid, active U.S. passport with at least six months of validity beyond the intended travel period.

What we will offer you:
  • Highly competitive salary
  • Fully covered healthcare, dental, and vision coverage
  • 401(k) and company match
  • Take as you need PTO + 11 paid holidays
  • Education & training benefits
  • Generous Referral Bonuses
  • And More!

}

Similar Jobs

More Jobs at Raft Company Website

  • Engineer
    $120K — $160K *
    Honolulu, HI 96817 (Honolulu County)
    Technical Services
    In-Person
  • Information Systems Security Officer
    $150K — $190K *
    Colorado Springs, CO 80918 (El Paso County)
    Information Technology
    In-Person
  • Engineer
    $140K — $180K *
    Colorado Springs, CO 80918 (El Paso County)
    Information Technology
    In-Person
  • Information Systems Security Officer
    $150K — $190K *
    Aberdeen Proving Ground, MD 21005 (Harford County)
    Information Technology
    In-Person
  • Product Manager
    $130K — $170K *
    San Antonio, TX 78228 (Bexar County)
    Aerospace & Defense
    In-Person

More Information Technology Jobs

Find similar Information Systems Security Officer jobs: