TELOS

Xacta SaaS Information System Owner (ISO)

TELOS$105K — $130K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • US Citizen
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field
  • One or more relevant professional certifications (CISSP, CISM, CCSP, etc.)
  • 5-7 years of experience in cybersecurity and cloud security
  • Experience supporting federal security frameworks like FedRAMP or NIST RMF
  • Familiarity with system security plans and vulnerability management processes
  • Proficiency in coordinating across diverse teams in cybersecurity, operations, and compliance

Responsibilities

  • Serve as operational owner for FedRAMP Certification of the Cloud Service Offering
  • Ensure alignment of security controls, documentation, and procedures
  • Coordinate continuous monitoring activities and deliverables for FedRAMP
  • Oversee vulnerability management and risk-acceptance processes
  • Assess changes for security, compliance, and authorization impact
  • Collaborate with DevSecOps teams on secure cloud architectures
  • Evaluate and escalate significant security risks and compliance issues

Benefits

  • Comprehensive benefits package includes health, dental, and vision insurance
  • 401(k) plan with company match
  • Paid time off and paid holidays
  • Professional development opportunities including training and certifications
  • Flexible working arrangements and work-life balance options
Full Job Description
Job Title

Xacta SaaS Information System Owner (ISO)

Job Description

This position will be based at Ashburn, VA

We are seeking an experienced Information System Owner (ISO) to provide security, risk, compliance, and authorization leadership for a FedRAMP-authorized Cloud Service Offering (CSO). The ISO will serve as the accountable operational owner for maintaining the system's availability, security and authorization/certification posture, ensuring that the production environment remain aligned with applicable FedRAMP and NIST requirements.

This role requires a combination of cybersecurity expertise, cloud and DevSecOps knowledge, risk-management judgment, and the ability to coordinate activities across engineering, operations, security, compliance, product, and executive stakeholders. The successful candidate will be able to translate regulatory requirements into practical operational controls while identifying opportunities to automate compliance activities and reduce the cost and effort required to maintain authorization.

Responsibilities:
• Serve as the primary operational owner for the CSO's FedRAMP Certification and operational posture.
• Maintain alignment among the production environment, authorization boundary, System Security Plan (SSP), security controls, architecture documentation, inventories, policies, procedures, and supporting evidence.
• Coordinate FedRAMP continuous monitoring activities and required recurring deliverables.
• Oversee availability, vulnerability management, remediation tracking, POA&M activities, deviations, exceptions, and risk-acceptance processes.
• Evaluate infrastructure, application, architecture, and configuration changes for security, compliance, and authorization impact.
• Coordinate control owners and technical teams to ensure NIST SP 800-53 security requirements are appropriately implemented and evidenced.
• Partner with DevSecOps and engineering teams on secure cloud architecture, CI/CD processes, configuration management, IAM, logging, encryption, vulnerability management, and related security capabilities.
• Coordinate responses to 3PAO assessments, annual assessments, penetration testing, government reviews, customer inquiries, and evidence requests.
• Evaluate findings and security issues based on technical severity, operational impact, regulatory requirements, and overall system risk.
• Escalate significant risks, compliance deficiencies, and authorization concerns to appropriate technical and executive stakeholders.
• Support incident response, contingency planning, system recovery, and related FedRAMP operational security requirements.
• Identify opportunities to automate security and compliance activities, including control evidence collection, asset reconciliation, vulnerability workflows, compliance telemetry, and recurring reporting.
• Develop security and risk metrics that provide leadership with visibility into the CSO's operational and authorization posture.
• Promote continuous improvement of security, compliance, and DevSecOps processes.

Job Requirements

Required Qualifications:
• US Citizen
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related discipline, or equivalent combination of education and relevant professional experience.
• One or more relevant professional certifications such as CISSP, CISM, CCSP, CGRC, comparable cybersecurity credentials.
• Approximately 5 - 7 years or more of progressive experience in cybersecurity, information assurance, cloud security, security operations, or related disciplines.
• Demonstrated experience supporting FedRAMP, NIST Risk Management Framework (RMF), FISMA, or comparable federal security authorization environments.
• System Security Plans, Plans of Action and Milestones (POA&M's), continuous monitoring, vulnerability management, security control assessments, control evidence collection, and risk-management activities.
• Experience with Xacta or other GRC platforms
• Experience operating or securing enterprise cloud or SaaS environments.
• Working knowledge of cloud security concepts including identity and access management, network security, encryption, logging and monitoring, vulnerability scanning, configuration management, and incident response.
• Ability to interpret technical vulnerability, configuration, and security data and translate findings into remediation priorities and risk decisions.
• Experience coordinating security activities across engineering, operations, cybersecurity, and compliance teams.
• Experience supporting security assessments, audits, or independent third-party assessments.
• Strong analytical, written, verbal, and executive communication skills.
• Ability to communicate technical and regulatory issues effectively to both technical and non-technical stakeholders.

Preferred Qualifications:
• Direct experience supporting or maintaining a FedRAMP CSO environment.
• AWS certification; or related cloud security certification
• Working knowledge and use of Artificial Intelligence (AI) Tools, prompt engineering and agentic workflows
• Experience interacting directly with 3PAOs, government assessors, or authorizing organizations.
• Experience with DevSecOps environments, CI/CD pipelines, containers, Kubernetes, infrastructure as code, and automated security tooling.
• Experience with API Security, automated evidence collection, and continuous control monitoring.
• Familiarity with FedRAMP 20x and machine-readable security and compliance standards like OSCAL.
• Experience integrating security telemetry from vulnerability scanners, cloud platforms, SIEM systems, CI/CD pipelines, and related security tools.
• Experience supporting federal government customers or regulated cloud environments.

The successful candidate must meet eligibility requirements to access sensitive information, which requires US citizenship.

Job Type

Full-Time

Location

Ashburn, VA 20147 US (Primary)

About TELOS

Telos Corporation is an information technology and cybersecurity company located in Ashburn, Virginia. Telos primarily serves government and enterprise clients, receiving a large number of its contracts from the United States Department of Defense. Customers are primarily military, intelligence and civilian agencies of the US government and NATO allies. Telos was founded in 1969 in Santa Monica, California and incorporated in Maryland in 1971. John B. Wood joined the company in 1992, and became president and chief executive in 1994. Today, Telos is headquartered in Ashburn, Virginia. On 16 June 2020, Telos Corporation reported its Automated Message Handling System service was granted an additional five years and $15.6 million contract by the Defense Information Systems Agency. On 20 May 2020, Telos named retired general Keith B. Alexander as its advisory board's inaugural leader. In November 2020, the company filed for an initial public offering.
Learn more about TELOS
Market Cap
$328.6 million
Industry
Net Income
-$5.6 million
Founded
1971
5 Year Trend
+12.4%
Revenue
$181.5 million
NASDAQ

Similar Jobs

More Jobs at TELOS

More Education, Government & Non-Profit Jobs

  • Deputy Building Official
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Deputy Assessor
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Civil Engineer II
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Accounting Manager
    $80K — $100K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Manager, Clinical Business Development
    $115K — $120K *
    Columbia University Irving Medical Center
    New York, NY 10032 (New York County)

Find similar Xacta SaaS Information System Owner (ISO) jobs: