Principal Information Security Specialist(Information System Security Officer)
Position OverviewThe position is part of a team of software and platform engineers building a unified, multi-tenant control plane that abstracts away infrastructure differences across AWS, Azure, and on-premises environments. The platform allows application teams to provision secure, isolated Kubernetes clusters and workloads dynamically. The control plane runs Crossplane and Cluster API (CAPI).
As the Principal Information Security Specialist your primary responsibility is translating traditional federal and enterprise security frameworks (e.g., DoDI 8510.01, JSIG, NIST SP 800-37) into clear, prioritized requirements for the development and engineering teams. You will act as a compliance partner to the teams, guiding them on what guardrails need to exist while they handle the implementation. Additionally, you will own the entire Authorization to Operate (ATO) package lifecycle, specializing in writing governance policies, preparing and modifying site addendums, and executing continuous risk management processes to achieve authorizations across the full Information System (IS) boundary. Lastly, you will manage continuous monitoring (ConMon) reporting and documentation obligations.
The ideal candidate is highly independent, capable of navigating complex regulatory frameworks with minimal supervision, and possesses a deep engineering curiosity regarding containerization and cloud infrastructure.
Key Responsibilities- ATO package and authorization documentation: Own the ATO and all associated documentation, including the SSP, control statements, POA&Ms, boundary and interconnection agreements. Keep all documents accurate to the live state of the system, with authority as the final word on documentation completeness.
- Continuous monitoring and risk management: Own ConMon reporting, POA&M tracking, and SBOM/supply-chain representation. Coordinate with engineers on anything requiring technical changes.
- System boundary coordination: Draft, update, and manage the system's formal boundary mappings, site addendums, delta-SSPs, inheritance packages, and ISAs that streamline the path to authorization.
- Policy generation and governance: Author and review system security policies, SOPs, and Rules of Behavior. Develop a pragmatic plan for phasing manual Day-1 controls into automation over time.
- Compliance-to-engineering translation: Turn NIST 800-53 controls into clear backlog requirements and evidence standards, working as a compliance enabler rather than a bottleneck.
QualificationsSkills & Experience- RMF & NIST Mastery: 5+ years of experience guiding complex information systems through the NIST SP 800-37 Risk Management Framework (RMF), DoDI 8510.01, or JSIG lifecycles to achieve government authorizations.
- Technical Writing & Policy Formulation: Proven track record of authoring clear, concise, and unassailable security policies, SOPs, control statements, and system configuration narratives.
- ATO Package Administration: Expert proficiency managing system packages within federal governance frameworks and data tools of record like eMASS or XACTA.
- Cross-Functional Collaboration: Demonstrated success partnering with software developers, cloud engineers, or SREs, serving as a proactive compliance enabler rather than an operational bottleneck.
- Conceptual Tech Literacy: A strong conceptual understanding of cloud environments (AWS/Azure) and core container concepts (Kubernetes). You do not need to build, code, or configure these tools, but you must be able to understand an architecture diagram and discuss security requirements intelligently with engineers.
- Active industry certifications (e.g., CISSP, CISM, CCSP)
Soft Skills & Engineering Mindset- Agile & Pragmatic Risk Management: Experience working in sprint-based engineering environments where security documentation is treated as a living artifact; comfortable leveraging manual controls on Day 1 while driving toward automation.
- Clear Communicator: Strong capability to translate rigid compliance terminology and policy expectations into actionable tasks for developers, and conversely, translating complex cloud-native architectures into risk-management language for traditional auditors.
- Extreme Ownership: Takes absolute accountability for the accuracy, completeness, and on-time delivery of the compliance packages, site addendums, and system security files to government stakeholders.
Preferred Qualifications- Hands-on experience using automated governance tools or GitOps-driven compliance engines.
- Prior experience working directly with Authorizing Officials (AOs) to transition highly dynamic or ephemeral cloud infrastructures to a continuous authorization state.
Salary Range: $100,000 - $330,000