Job Requirements
Remote Washington, DC
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$140,000 - $150,000
Job Description
Zachary Piper Solutions is seeking an Information Systems Security Officer (ISSO) to support mission-critical cloud and SaaS platforms operating within DoD environments. This role is responsible for executing the Risk Management Framework (RMF), maintaining ATO packages, managing continuous monitoring activities, and ensuring compliance across cloud-native environments supporting national security missions. The ideal candidate has hands-on experience with eMASS, DoD RMF, DISA PPSM, and cybersecurity compliance in regulated government environments.
Work Environment:
Remote position supporting innovative cloud and SaaS technologies delivering mission-critical capabilities to the Department of Defense. This role works closely with cybersecurity, engineering, product, and government stakeholders to maintain secure and compliant cloud environments.
Candidate must reside in DC, Maryland, or Virginia with the ability to get a CAC card and from time to time report to events.
Position is primarily remote with some DMV site visits.
Responsibilities:
- Execute and maintain RMF activities across the full authorization lifecycle, including assessment, authorization, and continuous monitoring.
- Build, manage, and maintain authorization packages within eMASS.
- Manage DISA PPSM registrations and maintain ports, protocols, and services documentation.
- Develop and maintain SSPs, POA&Ms, Risk Assessments, security narratives, and accreditation documentation.
- Drive continuous monitoring activities including vulnerability management, patch compliance, control assessments, and remediation tracking.
- Review STIG compliance, vulnerability scan results, and security findings to ensure adherence to DoD requirements.
- Partner with engineering teams to implement and validate security controls across cloud-native environments.
- Support security assessments, audits, readiness reviews, and interactions with ISSMs, SCAs, and Authorizing Officials.
- Translate DoD cybersecurity requirements into actionable technical guidance for development and engineering teams.
- Support automation of compliance activities through GRC and evidence-collection tools.
Qualifications:
- 3–5 years of experience supporting DoD cybersecurity, RMF, ATO, or information assurance programs.
- Hands-on experience building and maintaining authorization packages in eMASS.
- Experience with DISA PPSM, NIST 800-37, NIST 800-53, RMF, STIGs, ACAS/Nessus, and DoD cybersecurity requirements.
- Understanding of cloud-native architectures including AWS, Kubernetes, containers, and CI/CD pipelines.
- Strong documentation skills with experience creating assessor-ready security artifacts.
- Ability to work directly with engineers, ISSMs, government stakeholders, and security assessors.
Certifications & Requirements:
- DoD 8570/8140 IAM Level I or IAT Level II certification required (Security+, CISSP, or equivalent), or ability to obtain within 90 days.
Clearance Requirement:
- Active Secret Clearance required.
- Ability to obtain higher levels of access as required.
- TS/SCI eligibility preferred.
Preferred:
- Experience supporting DoD IL4/IL5 environments and cloud authorization efforts.
- Experience with GRC tools such as Xacta, RegScale, Drata, or similar platforms.
- Experience supporting compliance automation, Infrastructure as Code, or cloud security evidence collection.
- Advanced cybersecurity certifications including CISSP, CISM, CASP+, or CCNA Security.
- Experience supporting classified, SAP, or national security programs.
Compensation:
$140,000 - $150,000 (Based on years of relevant experience)
Benefits:
Comprehensive benefits package including medical, dental, vision, 401k, 15-20 days of paid time off, 11 federal holidays, and sick leave
Relocation assistance can be provided
Application Period: Opens on 09/23/2025 and will be accepted for at least 30 days from the posting date.
Work Environment:
Remote position supporting innovative cloud and SaaS technologies delivering mission-critical capabilities to the Department of Defense. This role works closely with cybersecurity, engineering, product, and government stakeholders to maintain secure and compliant cloud environments.
Candidate must reside in DC, Maryland, or Virginia with the ability to get a CAC card and from time to time report to events.
Position is primarily remote with some DMV site visits.
Responsibilities:
- Execute and maintain RMF activities across the full authorization lifecycle, including assessment, authorization, and continuous monitoring.
- Build, manage, and maintain authorization packages within eMASS.
- Manage DISA PPSM registrations and maintain ports, protocols, and services documentation.
- Develop and maintain SSPs, POA&Ms, Risk Assessments, security narratives, and accreditation documentation.
- Drive continuous monitoring activities including vulnerability management, patch compliance, control assessments, and remediation tracking.
- Review STIG compliance, vulnerability scan results, and security findings to ensure adherence to DoD requirements.
- Partner with engineering teams to implement and validate security controls across cloud-native environments.
- Support security assessments, audits, readiness reviews, and interactions with ISSMs, SCAs, and Authorizing Officials.
- Translate DoD cybersecurity requirements into actionable technical guidance for development and engineering teams.
- Support automation of compliance activities through GRC and evidence-collection tools.
Qualifications:
- 3–5 years of experience supporting DoD cybersecurity, RMF, ATO, or information assurance programs.
- Hands-on experience building and maintaining authorization packages in eMASS.
- Experience with DISA PPSM, NIST 800-37, NIST 800-53, RMF, STIGs, ACAS/Nessus, and DoD cybersecurity requirements.
- Understanding of cloud-native architectures including AWS, Kubernetes, containers, and CI/CD pipelines.
- Strong documentation skills with experience creating assessor-ready security artifacts.
- Ability to work directly with engineers, ISSMs, government stakeholders, and security assessors.
Certifications & Requirements:
- DoD 8570/8140 IAM Level I or IAT Level II certification required (Security+, CISSP, or equivalent), or ability to obtain within 90 days.
Clearance Requirement:
- Active Secret Clearance required.
- Ability to obtain higher levels of access as required.
- TS/SCI eligibility preferred.
Preferred:
- Experience supporting DoD IL4/IL5 environments and cloud authorization efforts.
- Experience with GRC tools such as Xacta, RegScale, Drata, or similar platforms.
- Experience supporting compliance automation, Infrastructure as Code, or cloud security evidence collection.
- Advanced cybersecurity certifications including CISSP, CISM, CASP+, or CCNA Security.
- Experience supporting classified, SAP, or national security programs.
Compensation:
$140,000 - $150,000 (Based on years of relevant experience)
Benefits:
Comprehensive benefits package including medical, dental, vision, 401k, 15-20 days of paid time off, 11 federal holidays, and sick leave
Relocation assistance can be provided
Application Period: Opens on 09/23/2025 and will be accepted for at least 30 days from the posting date.
group id: 10430981