Sr. Principal Information Security Engineer
Job description
Principal Information Security Specialist
(Information System Security Officer)
About the Role
The role owns the end-to-end security compliance lifecycle for cloud-native platforms serving national security missions. You translate complex federal frameworks into actionable engineering requirements for development teams. You serve as the central compliance authority for the Authorization to Operate (ATO) process, owning documentation and risk management artifacts. The position drives the implementation of security guardrails within modern containerized and cloud infrastructure environments. You will act as a bridge between rigorous regulatory standards and pragmatic software delivery. The role ensures continuous monitoring and governance practices align with evolving mission needs.
What You'll Do
- Define and maintain the Authorization to Operate (ATO) package, including System Security Plan (SSP), control statements, Plan of Action and Milestones (POA&M), boundary agreements, and interconnection statements.
- Serve as the primary compliance owner responsible for continuous monitoring (ConMon) reporting, POA&M tracking, and Supply Chain Risk Management (SCRM) representation.
- Draft, update, and manage formal system boundary mappings, site addendums, delta-SSP documentation, and Interconnection Security Agreements (ISA) to streamline authorization pathways.
- Author, review, and govern system security policies, Standard Operating Procedures (SOPs), and Rules of Behavior while planning the transition from manual Day-1 controls toward future automation.
- Translate NIST 800-53 control families into clear backlog requirements, evidence collection standards, and implementation guidance for engineering teams.
- Collaborate closely with software developers, cloud engineers, and Site Reliability Engineers to act as a proactive compliance enabler rather than a delivery obstacle.
- Develop and maintain a strong conceptual understanding of cloud architectures on AWS and Azure, including container orchestration via Kubernetes, to discuss security requirements intelligently.
- Leverage active industry security certifications such as CISSP, CISM, or CCSP to reinforce technical credibility and governance authority.
- Operate effectively within Agile and iterative engineering environments where documentation is treated as a living artifact.
- Act with extreme ownership for the accuracy, completeness, and timely delivery of all compliance artifacts to government stakeholders.
Requirements
- Demonstrate 5 or more years of experience guiding complex information systems through the NIST SP 800-37 Risk Management Framework (RMF), DoDI 8510.01, or JSIG lifecycles to achieve government authorization.
- Possess proven ability to author clear, concise, and defensible security policies, System Security Plans, control statements, and Standard Operating Procedures.
- Show expert-level proficiency in managing system security packages within federal governance frameworks and data tools of record such as eMASS or XACTA.
- Exhibit a strong track record of successful cross-functional collaboration with software developers, cloud infrastructure engineers, and SREs in a mission-focused context.
- Maintain a strong conceptual understanding of cloud service models, AWS and Azure environments, and core containerization concepts including Kubernetes, without needing to code or configure these platforms.
- Hold active industry security certifications such as CISSP, CISM, or CCSP.
- Thrive in Agile, sprint-based environments where security documentation must evolve alongside rapidly changing cloud-native architectures.
- Communicate effectively to convert rigid compliance terminology into actionable tasks for engineers and complex cloud architectures into risk-management language for auditors.
- Embrace extreme ownership for compliance deliverables, ensuring precision, completeness, and timeliness in all government-facing documentation.
Preferred Qualifications
- Hands-on experience using automated governance tools or GitOps-driven compliance workflows.
- Prior experience working directly with Authorizing Officials (AOs) to transition highly dynamic or ephemeral cloud infrastructures to a continuous authorization state.
Position Overview
The position is part of a team of software and platform engineers building a unified, multi-tenant control plane that abstracts away infrastructure differences across AWS, Azure, and on-premises environments. The platform allows application teams to provision secure, isolated Kubernetes clusters and workloads dynamically. The control plane runs Crossplane and Cluster API (CAPI).
As the Principal Information Security Specialist your primary responsibility is translating traditional federal and enterprise security frameworks (e.g., DoDI 8510.01, JSIG, NIST SP 800-37) into clear, prioritized requirements for the development and engineering teams. You will act as a compliance partner to the teams, guiding them on what guardrails need to exist while they handle the implementation. Additionally, you will own the entire Authorization to Operate (ATO) package lifecycle, specializing in writing governance policies, preparing and modifying site addendums, and executing continuous risk management processes to achieve authorizations across the full Information System (IS) boundary. Lastly, you will manage continuous monitoring (ConMon) reporting and documentation obligations.
The ideal candidate is highly independent, capable of navigating complex regulatory frameworks with minimal supervision, and possesses a deep engineering curiosity regarding containerization and cloud infrastructure.
Skills & Experience
- RMF & NIST Mastery: 5+ years of experience guiding complex information systems through the NIST SP 800-37 Risk Management Framework (RMF), DoDI 8510.01, or JSIG lifecycles to achieve government authorizations.
- Technical Writing & Policy Formulation: Proven track record of authoring clear, concise, and unassailable security policies, SOPs, control statements, and system configuration narratives.
- ATO Package Administration: Expert proficiency managing system packages within federal governance frameworks and data tools of record like eMASS or XACTA.
- Cross-Functional Collaboration: Demonstrated success partnering with software developers, cloud engineers, or SREs, serving as a proactive compliance enabler rather than an operational bottleneck.
- Conceptual Tech Literacy: A strong conceptual understanding of cloud environments (AWS/Azure) and core container concepts (Kubernetes). You do not need to build, code, or configure these tools, but you must be able to understand an architecture diagram and discuss security requirements intelligently with engineers.
- Active industry certifications (e.g., CISSP, CISM, CCSP)
Soft Skills & Engineering Mindset
- Agile & Pragmatic Risk Management: Experience working in sprint-based engineering environments where security documentation is treated as a living artifact; comfortable leveraging manual controls on Day 1 while driving toward automation.
- Clear Communicator: Strong capability to translate rigid compliance terminology and policy expectations into actionable tasks for developers, and conversely, translating complex cloud-native architectures into risk-management language for traditional auditors.
- Extreme Ownership: Takes absolute accountability for the accuracy, completeness, and on-time delivery of the compliance packages, site addendums, and system security files to government stakeholders.
Location, Compensation, and Equal Opportunity
Location: USA
Compensation: $100,000 - $330,000
We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.