Aderas is looking for a Senior Information Systems Security Officer/Compliance Architect to act as the primary security advisor steering system architectures toward FedRAMP 20x Certification Classes. This role orchestrates automated validation data streams, interfaces with federal assessors, and leverages enterprise GRC systems.
Key Responsibilities- Lead FedRAMP authorization workstreams: SSP ownership, control implementation narratives, inheritance strategy, and evidence governance.
- Interpret and apply NIST SP 800-53, NIST 800-37 RMF, 800-30 risk assessment, and 800-61 incident response into system processes.
- Partner with cloud/DevOps teams to ensure secure architectures (IAM, network segmentation, encryption, key management, logging, vulnerability management).
- Manage and defend POA&M strategy: risk acceptance packages, remediation prioritization, milestone realism, and executive reporting.
- Prepare for and lead support of assessments, penetration test coordination (as applicable), and government/customer reviews.
- Establish continuous monitoring cadence and dashboards; ensure evidence is timely, correct, and traceable.
- Drive automation-forward compliance, reusable evidence, standardized exports, "evidence-as-code" patterns, and reduction of manual screenshots.
- Mentor junior ISSOs/analysts; define SOPs, checklists, and quality gates for artifacts and evidence.
Knowledge & Technical Skills- Expertise in JCAM & Federal GRC Platforms: Hands-on command of the Joint Cybersecurity Authorization Management (JCAM) platform, CSAM, or Xacta to drive audit management, control grouping, and API data exchanges with federal authorities.
- Advanced SharePoint Architecture: Ability to architect and govern SharePoint and analytics platforms for cross-functional collaboration, secure evidence repositories, configuration control boards, and live executive metrics tracking.
- FedRAMP 20x Pipeline Automation: Experience deploying automated compliance toolchains to generate machine-readable security data.
- Strong grasp of OSCAL concepts and how machine-readable controls/evidence can streamline assessment and continuous monitoring
- Ability to implement standardized evidence pipelines (e.g., automated exports from SIEM/vuln scanners, config baseline reporting, policy-to-control mapping).
- Familiarity with policy-as-code / compliance-as-code approaches (where appropriate) and integrating compliance checks into CI/CD.
- Comfort translating technical telemetry into assessor-ready evidence.
- Security Decision & Risk Management: Proven success orchestrating Plan of Action and Milestones (POA&M) remediation, establishing secure authorization boundaries, and working knowledge of managing persistent Security Decision Records under FedRAMP 2026 Consolidated Rules.
Certifications, Preferred (two or more):- Active CISSP, CISM, or CASP+ in good standing
- CompTIA Security+
- CRISC
- CCSP (cloud security)
- AWS/Azure/GCP Security Specialty (or equivalent advanced cloud cert)
- ITIL (for service management alignment)
Required Degrees & Experience- Bachelor's or Master's Degree in Cybersecurity, Management Information Systems, or a related technical arena.
- 10 years of information assurance experience backing federal authorizations (ATO) and persistent continuous monitoring.
Security Requirement- Active DoD Secret clearance
Location- Hybrid/On-site requirements
Join the Aderas team!