Senior Information System Security Officer/Compliance Architect

Aderas, Inc

$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in information assurance focusing on federal authorizations (ATO) and continuous monitoring.
  • Bachelor's or Master's Degree in Cybersecurity, Management Information Systems, or related field.
  • Active DoD Secret clearance required.
  • Certifications like CISSP, CISM, CCSP, or equivalent cloud security cert preferred.
  • Hands-on experience with JCAM and federal GRC platforms.

Responsibilities

  • Lead authorization workstreams for FedRAMP compliance.
  • Interpret NIST standards to integrate into system processes.
  • Collaborate with DevOps to ensure secure system architectures.
  • Manage and report on remediation strategies within POA&M.
  • Prepare for assessments and coordinate penetration tests when necessary.
  • Establish continuous monitoring practices and maintain evidence quality.
  • Drive initiatives towards automation and reusable compliance evidence.

Benefits

  • Hybrid and on-site work options available.
  • Opportunity to mentor junior staff in a collaborative environment.
  • Exposure to advanced security and compliance tools and practices.
  • Engage with federal assessors and customers in meaningful assessments.
  • Be part of a leading team on the FedRAMP accreditation journey.
Full Job Description
Aderas is looking for a Senior Information Systems Security Officer/Compliance Architect to act as the primary security advisor steering system architectures toward FedRAMP 20x Certification Classes. This role orchestrates automated validation data streams, interfaces with federal assessors, and leverages enterprise GRC systems.

Key Responsibilities
  • Lead FedRAMP authorization workstreams: SSP ownership, control implementation narratives, inheritance strategy, and evidence governance.
  • Interpret and apply NIST SP 800-53, NIST 800-37 RMF, 800-30 risk assessment, and 800-61 incident response into system processes.
  • Partner with cloud/DevOps teams to ensure secure architectures (IAM, network segmentation, encryption, key management, logging, vulnerability management).
  • Manage and defend POA&M strategy: risk acceptance packages, remediation prioritization, milestone realism, and executive reporting.
  • Prepare for and lead support of assessments, penetration test coordination (as applicable), and government/customer reviews.
  • Establish continuous monitoring cadence and dashboards; ensure evidence is timely, correct, and traceable.
  • Drive automation-forward compliance, reusable evidence, standardized exports, "evidence-as-code" patterns, and reduction of manual screenshots.
  • Mentor junior ISSOs/analysts; define SOPs, checklists, and quality gates for artifacts and evidence.

Knowledge & Technical Skills
  • Expertise in JCAM & Federal GRC Platforms: Hands-on command of the Joint Cybersecurity Authorization Management (JCAM) platform, CSAM, or Xacta to drive audit management, control grouping, and API data exchanges with federal authorities.
  • Advanced SharePoint Architecture: Ability to architect and govern SharePoint and analytics platforms for cross-functional collaboration, secure evidence repositories, configuration control boards, and live executive metrics tracking.
  • FedRAMP 20x Pipeline Automation: Experience deploying automated compliance toolchains to generate machine-readable security data.
    • Strong grasp of OSCAL concepts and how machine-readable controls/evidence can streamline assessment and continuous monitoring
    • Ability to implement standardized evidence pipelines (e.g., automated exports from SIEM/vuln scanners, config baseline reporting, policy-to-control mapping).
    • Familiarity with policy-as-code / compliance-as-code approaches (where appropriate) and integrating compliance checks into CI/CD.
    • Comfort translating technical telemetry into assessor-ready evidence.
  • Security Decision & Risk Management: Proven success orchestrating Plan of Action and Milestones (POA&M) remediation, establishing secure authorization boundaries, and working knowledge of managing persistent Security Decision Records under FedRAMP 2026 Consolidated Rules.

Certifications, Preferred (two or more):
  • Active CISSP, CISM, or CASP+ in good standing
  • CompTIA Security+
  • CRISC
  • CCSP (cloud security)
  • AWS/Azure/GCP Security Specialty (or equivalent advanced cloud cert)
  • ITIL (for service management alignment)

Required Degrees & Experience
  • Bachelor's or Master's Degree in Cybersecurity, Management Information Systems, or a related technical arena.
  • 10 years of information assurance experience backing federal authorizations (ATO) and persistent continuous monitoring.

Security Requirement
  • Active DoD Secret clearance

Location
  • Hybrid/On-site requirements

Join the Aderas team!

Similar Jobs

More Jobs at Aderas, Inc

More Information Technology Jobs

Find similar Senior Information System Security Officer/Compliance Architect jobs: