Sr. Information Systems Security Officer - Cloud
New
T
Tetrad Digital IntegrityCybersecurity
United StatesFull-TimeSenior
Salary130,000 - 160,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years
- Required Skills
- DockerKubernetesAzure
Requirements
- Active Secret security clearance.
- Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification.
- Bachelor’s degree in Cybersecurity, Computer Science, or Information Technology.
- 8+ years of cybersecurity experience, including demonstrated experience supporting RMF activities for Department of War (DoW) systems.
- Practical, hands-on experience with at least one cloud platform (AWS, Microsoft Azure, or GCP).
- Demonstrated experience in IAM, VPC/networking, Kubernetes, and cloud security services.
- Strong knowledge of containerized environments (Docker, Kubernetes) and container security best practices.
- Familiarity with Generative AI technologies, including LLMs and AI/ML security considerations.
- Deep understanding of NIST SP 800-53, DoD RMF, and FedRAMP frameworks.
- Experience writing and maintaining RMF artifacts such as SSPs, POA&Ms, and SARs.
Responsibilities
- Lead and support RMF activities throughout all phases including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Provide expert guidance on DoW cloud security policies, NIST SP 800-53 controls, CNSS policies, and DoD-specific frameworks.
- Conduct security architecture reviews and security engineering analysis for cloud-native and containerized workloads hosted in Azure.
- Evaluate security controls associated with Kubernetes, Docker, and container orchestration platforms.
- Assess security risks related to generative AI components, large language models (LLMs), and AI/ML workloads.
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and RMF documentation.
- Perform threat modeling, vulnerability assessments, and risk analysis tailored to cloud environments and AI technologies.
- Interface with system architects, developers, and DevSecOps teams to integrate security throughout the SDLC.
View Full Description & ApplyYou'll be redirected to the employer's site