Information Systems Security Officer
Job description
Information Systems Security Officer at Spear Ai.
About the role
The Information Systems Security Officer at Spear Ai will serve as the senior cybersecurity leader responsible for establishing and maintaining the security posture across all program information systems. This role owns the end-to-end oversight of security policy implementation, risk management frameworks, and compliance activities that govern classified information environments. The individual in this position acts as the definitive subject matter expert for the Intelligence Community on security standards, operational procedures, and regulatory adherence. They will directly advise program leadership and Authorizing Officials on complex cybersecurity risks and acceptable levels of residual risk. This position drives the development of security policies that are specifically tailored to the demanding requirements of IC operational environments. The role ensures that security architecture decisions consistently support mission success while adhering to strict government directives. Ultimately, this officer is accountable for the integrity, confidentiality, and availability of the information systems that enable our national security mission.
Key facts
What you'll do
- Serve as the senior security authority providing comprehensive oversight for all program information systems and directing the activities of ISSOs and security staff.
- Lead and manage the complete Risk Management Framework (RMF) process across multiple classified systems, ensuring Authorization to Operate (ATO) achievements and sustained compliance with ICD 503 and established NIST standards.
- Develop, implement, and enforce a comprehensive suite of information security policies, procedures, and standards that align with IC operational environment requirements.
- Provide authoritative cybersecurity risk advice to program leadership and the Authorizing Official (AO) regarding potential threats, mitigation strategies, and formal residual risk acceptance decisions.
- Oversee continuous monitoring programs, execute rigorous security control assessments, and direct vulnerability management activities to maintain robust security postures.
- Lead complex incident response operations, conduct detailed forensic investigations, and author thorough after-action reports for security events affecting classified information systems.
- Manage and mentor ISSO personnel by establishing clear role responsibilities, defining security workflows, and fostering professional development within the security team.
- Coordinate extensively with IC and Department of Defense security stakeholders, including Inspectors General and various oversight bodies, to ensure transparent and compliant operations.
- Ensure all security architecture and engineering decisions are meticulously aligned with mission requirements and strictly adhere to applicable directives such as ICD 503, CNSSI 1253, and NIST SP 800-53.
- Evaluate emerging cyber threats and drive proactive security improvements specifically focused on AI/ML systems and data platforms to counter evolving risks.
- Support comprehensive audits, inspections, and reviews conducted by government oversight authorities, preparing detailed documentation and responses.
- Maintain detailed security documentation and ensure all security processes are current, accurate, and readily available for review.
Requirements
- Possess an active Top Secret security clearance with a SCI eligibility, and demonstrate the ability to successfully obtain and maintain a Polygraph clearance as required by the position.
- Exhibit deep, current expertise in the Risk Management Framework (RMF), ICD 503 guidance, CNSSI 1253 policies, and all applicable IC and Department of Defense security policy frameworks.
- Provide documented, proven experience in achieving and maintaining Authorizations to Operate for complex, multi-system programs operating within classified environments at high levels of sensitivity.
- Show a strong background in designing security architectures, managing enterprise-level risk, and directing incident response activities within Joint Worldwide Intelligence Communications System (JWICS) or similar classified network infrastructures.
- Demonstrate proven leadership capabilities in directing and mentoring security teams, fostering a culture of security awareness and compliance in a fast-paced, mission-critical environment.
- Hold professional cybersecurity certifications including a current CISSP; additionally, certifications such as CISM, CAP, or CASP+ are strongly preferred and highly valued.
- Maintain current compliance with DoD 8570/8140 standards, specifically achieving IAM Level III compliance as a mandatory requirement for this role.
- Demonstrate an ability to interpret complex regulatory documents and translate them into actionable security controls and procedural updates for the organization.
- Show a commitment to maintaining security best practices through continuous learning and adaptation to new security challenges and technologies.
- Exhibit strong written and verbal communication skills necessary for interacting with senior government officials, technical teams, and oversight bodies.
- Possess the ability to manage multiple high-priority initiatives simultaneously while maintaining attention to detail and adherence to strict deadlines.
- Demonstrate analytical problem-solving skills to assess security risks, determine appropriate mitigations, and make informed decisions in complex scenarios.
- Show the capability to work independently with minimal supervision while also functioning effectively within a collaborative team environment.
- Maintain U.S. citizenship or meet the specific nationality requirements necessary for handling classified information at the level associated with this position.
- Be prepared to undergo a thorough background investigation and satisfy all requirements for government security clearance processing.
Nice to have
- Bring experience addressing security architecture and implementation challenges specific to AI/ML systems and their unique threat models.
- Contribute knowledge of security controls and best practices within AWS GovCloud or Azure Government environments relevant to this mission.
- Offer prior professional experience within Military Intelligence roles or other Intelligence Community agencies.
Practical notes
This role operates under full-time employment guidelines. Travel requirements are determined by mission needs and program operations. Candidates must meet all eligibility requirements for U.S. government security clearances. This position is subject to continuous monitoring and reinvestigation requirements to maintain clearance eligibility.
Why work with us
- We ship - We don't work on 18-month projects that are irrelevant before they're even finished.
- Our work has impact - We build products that are deployed to U.S. submarines and integrate with the sonobuoys we manufacture.
- We're growing responsibly - We have the resources to hire a lot more people, but we don't want to build a massive team of people who don't share our values.
- We're profitable - We aren't burning through cash trying to make the business work. But we also have investors who believe in us and are committed to our success.
- We care about doing great work - You don't need permission to sweat the details here.
- We don't take ourselves too seriously - We're building products that make the world safer. But we don't let that get to our heads.
What we offer
- Unlimited PTO - Take the time you need to recharge and maintain work-life balance.
- Dedicated Sick Time - Your health and well-being come first.
- Comprehensive Health & Benefits - Medical, dental, and vision coverage to keep you and your family protected.
- 11 Paid Holidays - Enjoy time off throughout the year to celebrate and spend time with loved ones.
- Professional Development - Educational opportunities and resources to help you grow your skills and advance your career.
- Collaborative Environment - Work directly with leadership in our flat organizational structure, where your ideas and contributions matter.
- Mission-driven work - Engage in projects that directly enhance the capabilities of warfighters and contribute to national defense.
- Opportunities for career advancement within a growing defense contracting company dedicated to cutting-edge solutions.
- A culture that values innovation, excellence, and direct impact on critical missions.
- An inclusive workplace that encourages collaboration across Hardware, Software, and Services divisions.
- The satisfaction of working on real-world projects with tangible effects on military operations and success.
- Supportive supervision and mentorship from leadership committed to your professional growth.
- A stable financial environment with investors who provide long-term commitment to the company's vision.
- Access to resources that enable continuous learning and skill development in cybersecurity.
- The ability to contribute to projects that integrate directly with deployed military assets such as sonobuoys and submarine systems.
- A professional atmosphere that balances rigorous security requirements with a healthy work culture.
- Potential for telework options as determined by mission requirements and operational needs.
- Entry into a dynamic organization that values technical expertise and mission-focused results.