Senior Principal Information System Security Officer
Job description
About the role
You will own the end-to-end information security posture for national security programs, driving data compliance and cyber security across the full system lifecycle. You will serve as the primary liaison between technical teams, leadership, and government customers on data protection and regulatory matters. This role requires deep expertise in data classification, secure architecture, and cross-domain solutions to safeguard US Person and Controlled Unclassified Information. You will design and enforce security policies that align with federal mandates and evolving mission requirements. You will lead risk assessments, manage authorization processes, and ensure continuous compliance across all environments. You will mentor teams on security best practices and foster a culture of accountability and operational excellence. You will translate complex regulatory frameworks into actionable technical controls that protect critical data assets.
Key facts
What you'll do
You will define and maintain a secure data schema that governs the movement and storage of information across classification boundaries and enclaves, with a focus on Cross Domain Solutions. You will author, implement, and audit data policies in close collaboration with the Chief Data Officer of the COCOM to ensure alignment with regulatory requirements and mission objectives. You will conduct rigorous assessments of cloud infrastructure within the program's scope, verifying adherence to ATO conditions and established security policies. You will perform detailed evaluations of platform infrastructure components, confirming that security configurations meet all applicable standards and control frameworks. You will review application code and infrastructure designs, identifying potential weaknesses and ensuring that security is embedded throughout the development lifecycle. You will lead vulnerability and compliance management activities, driving remediation for STIG findings, ACAS/Tenable alerts, and CVEs through structured POA&Ms. You will develop, update, and enforce security policies, operating procedures, and technical documentation to support clear governance and reduce operational risk. You will manage the full Risk Management Framework lifecycle, including system authorization, continuous monitoring, and oversight of eMASS, SSPs, and POA&Ms in alignment with NIST 800-53 requirements.
Requirements
You must be a United States Citizen eligible for public trust clearance. You must possess a Top Secret security clearance with the ability to obtain and maintain a TS/SCI clearance. You must have extensive experience with federal information security policies, directives, and compliance frameworks such as NIST 800-53, RMF, and ATO processes. You must demonstrate deep knowledge of data protection practices for PII, CUI, CAI/PAI, data classification schemas, retention schedules, and lifecycle management. You must have hands-on experience with encryption technologies, key management systems, HSMs, and secrets management for data at rest and in transit. You must have a proven track record in vulnerability scanning, compliance monitoring, and remediation tracking using tools such as STIG checklists, ACAS, and Tenable. You must have strong analytical skills to interpret security risks, assess program impact, and develop effective risk mitigation strategies. You must have excellent written and verbal communication skills to articulate technical security concepts to both technical and executive audiences.
Nice to have
Experience with Cloud and Kubernetes Security in environments such as AWS GovCloud, containerized workloads, Kubernetes orchestration, and network security controls. Experience with Identity and Access Management frameworks, including RBAC, ABAC, Zero Trust architectures, PKI, and multi-factor authentication implementations. Experience with security architecture design and data platform technologies including ETL pipelines, API security, data lakes, secure data pipelines, and mechanisms for cross-domain data sharing.
Practical notes
This role may require specific hours to meet mission needs, including occasional after-hours support for critical deployments or incident response. Travel may be required to client sites or secure facilities in support of program objectives. Candidates must be eligible for US government clearances and background investigations. This job description is not an exhaustive list of all responsibilities, skills, or requirements, subject to change based on organizational needs.
Clarity Innovations is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.