freehire launches on Product Hunt on 26 August.

Follow →

Defense - Senior Information Systems Security Officer- Cloud

Summary

Leads cloud security and RMF compliance for U.S. Marine Corps modernization, securing Azure workloads, containers, and AI systems while guiding teams through authorization to operate (ATO) processes.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Defense - Senior Information Systems Security Officer- Cloud based in United States.

This is a fully remote opportunity supporting mission-critical U.S. Marine Corps cloud modernization initiatives.
The role focuses on securing cloud-native and containerized workloads while enabling successful Authority to Operate (ATO) outcomes.
You will lead Risk Management Framework activities and translate federal and defense security requirements into practical deliverables.
The position combines cloud security engineering, compliance, risk assessment, and hands-on security architecture.
You will work closely with architects, developers, DevSecOps teams, assessors, and other technical stakeholders.
The role also addresses emerging security considerations around generative AI, LLMs, and AI/ML workloads.
It offers the opportunity to influence the security of modern government systems while working in a highly specialized cybersecurity environment.

Accountabilities

  • Lead and support Risk Management Framework (RMF) activities across categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Translate NIST SP 800-53, DoD security policies, CNSS requirements, Cloud Computing SRG guidance, and AI-related security requirements into actionable security practices.
  • Conduct security architecture reviews and security engineering assessments for cloud-native and containerized workloads, particularly within Azure environments.
  • Evaluate security controls for Kubernetes, Docker, and other container orchestration technologies and identify opportunities to strengthen cloud security.
  • Assess risks associated with generative AI, large language models, and AI/ML workloads, supporting secure and responsible adoption of these technologies.
  • Develop, maintain, and manage RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and related artifacts.
  • Perform threat modeling, vulnerability assessments, and risk analyses tailored to cloud and emerging AI technologies.
  • Partner with system architects, developers, and DevSecOps teams to embed security throughout the software development lifecycle.
  • Support security control assessments and coordinate with third-party assessors and other stakeholders.
  • Monitor, track, and communicate security compliance through continuous monitoring processes and provide clear visibility into the security posture.
  • Provide expert guidance to technical and non-technical stakeholders while supporting secure modernization initiatives.
  • Perform minimal travel as required by program needs.
  • Requirements

    • Active Secret security clearance is required.
    • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, combined with 8+ years of cybersecurity experience, including hands-on RMF experience supporting defense systems.
    • Current CISSP or CISM certification is required.
    • Practical experience securing at least one major cloud platform, such as AWS, Microsoft Azure, or Google Cloud Platform, including IAM, networking, Kubernetes, and cloud security services.
    • Strong knowledge of containerized environments, including Docker and Kubernetes, and associated security best practices.
    • Familiarity with generative AI technologies, LLMs, and security considerations for AI/ML workloads.
    • Deep understanding of NIST SP 800-53, DoD RMF, FedRAMP, and other relevant cybersecurity frameworks.
    • Demonstrated experience creating and maintaining RMF artifacts such as SSPs, POA&Ms, and SARs.
    • Experience conducting security risk assessments in Department of War environments.
    • Strong communication and collaboration skills, with the ability to work effectively with technical teams, leadership, assessors, and other stakeholders.
    • Ability to translate complex security, compliance, and risk requirements into clear and actionable recommendations.
    • Preferred: advanced cloud security certifications, such as Google Professional Cloud Security Engineer, CCSP, or an Azure equivalent.
    • Preferred: experience integrating DevSecOps pipelines with RMF compliance processes.
    • Preferred: familiarity with RMF automation and compliance tools such as Xacta, eMASS, or OpenRMF.
    • U.S. citizenship or lawful permanent resident status is required due to applicable federal government employment restrictions.
    • Benefits

      • Salary: Anticipated base salary range of $130,000–$160,000, with final compensation based on experience, education, skills, location, internal equity, market data, and applicable contract requirements.
      • Work arrangement: Fully remote position within the United States.
      • Mission-driven work: Opportunity to support mission-critical U.S. Marine Corps programs and modern cloud security initiatives.
      • Career development: Exposure to cloud modernization, DevSecOps, RMF, container security, and emerging AI/ML security challenges.
      • Professional impact: Opportunity to influence security architecture, compliance, and risk management for complex government systems.
      • Travel: Minimal travel requirements.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available