Defense - Senior Information Systems Security Officer- Cloud
Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.
TDI is seeking a hands-on Information Systems Security Officer (ISSO) to support U.S. Marine Corps cloud modernization in a fully remote role. You’ll help application teams securely onboard mission-critical workloads to modern cloud environments while supporting ATO efforts and translating RMF, NIST SP 800-53, and Cloud SRG requirements into actionable security deliverables.
This is a fully remote position supporting mission-critical U.S. Marine Corps programs. An active Secret clearance is required.
RESPONSIBILITIES:
- Lead and support RMF activities throughout all phases (categorization, control selection, implementation, assessment, authorization, and continuous monitoring).
- Provide expert guidance on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoD-specific frameworks such as Cloud Computing SRG and AI-specific guidance.
- Conduct security architecture reviews and security engineering analysis for cloud-native and containerized workloads hosted in Azure.
- Evaluate security controls associated with Kubernetes, Docker, and container orchestration platforms within Azure.
- Assess security risks related to generative AI components, including large language models (LLMs) and AI/ML workloads, ensuring responsible and compliant use.
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and related RMF documentation.
- Perform threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and AI technologies.
- Interface with system architects, developers, and DevSecOps teams to integrate security throughout the Software Development Lifecycle (SDLC).
- Support security control assessments (SCAs) and coordinate with third-party assessors.
- Monitor, track, and report on security compliance posture through Continuous Monitoring (ConMon) processes.
- Minimal travel will be required.
QUALIFICATIONS:
- Active Secret security clearance.
- A current Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification is required.
- Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology, and 8+ years of cybersecurity experience, including demonstrated experience supporting Risk Management Framework (RMF) activities for Department of War (DoW) systems.
- Candidates must have practical, hands-on experience with at least one cloud platform, including AWS, Microsoft Azure, or Google Cloud Platform (GCP), with demonstrated experience in IAM, VPC/networking, Kubernetes, and cloud security services.
- Strong knowledge of containerized environments (e.g., Docker, Kubernetes) and container security best practices.
- Familiarity with Generative AI technologies, including LLMs and AI/ML security considerations.
- Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
- Experience writing and maintaining RMF artifacts such as SSPs, POA&Ms, and SARs.
- Strong communication skills and ability to collaborate effectively with technical and non-technical stakeholders.
- Experience with security risk assessments in DoW environments
PREFERRED QUALIFICATIONS:
- Advanced cloud security certifications, such as Google Professional Cloud Security Engineer, Cloud Certified Security Professional or Azure equivalent.
- Experience integrating DevSecOps pipelines with RMF compliance processes.
- Familiarity with automation tools for RMF documentation and control testing (e.g., Xacta, eMASS, OpenRMF).
PAY RANGE:
The anticipated salary range for this position is $130,000 - $160,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on facto