Source Job

US Unlimited PTO

  • Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
  • Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
  • Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.

RMF NIST 800-53 EMASS DevSecOps CISSP

20 jobs similar to Cyber Security Engineer / Information Systems Security Engineer (ISSE)

Jobs ranked by similarity.

US

  • Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
  • Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
  • Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.

This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

US

  • Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
  • Maintain STIG/SRG checklists and monthly status reports.
  • Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.

DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.

India

  • Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
  • Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
  • Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.

The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.

US

  • Design and implement cybersecurity architectures, controls, and technologies for secure government systems.
  • Manage Authority to Operate (ATO) activities, including security documentation, compliance tracking, and continuous monitoring.
  • Apply NIST SP 800 security controls and support Risk Management Framework (RMF) implementation.

The partner organization provides advanced cybersecurity solutions for critical government technology environments. They operate in a mission-driven, collaborative culture with a focus on protecting federal systems.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.

US

  • Execute formal SCA/R duties and lead security assessment efforts.
  • Establish reusable security playbooks and assessment frameworks for rapid AI deployment.
  • Evaluate technical control effectiveness across AWS cloud, DevSecOps pipelines, and AI/LLM stacks.

Dark Wolf Solutions specializes in cybersecurity engineering, cloud architecture, and DevSecOps prototyping for high-priority projects, including AI/LLM technologies. The company is an EEO/AA employer and focuses on fast-paced, collaborative environments.

$145,000–$160,000/yr
US

  • Design, implement, and maintain enterprise security solutions to strengthen cybersecurity posture and advance Zero Trust maturity.
  • Operate security tools like EDR, SIEM, and vulnerability scanners, integrating security into CI/CD pipelines.
  • Build dashboards to measure security performance and Zero Trust maturity metrics.

Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. Named one of the fastest-growing privately held companies, they pride themselves on an employee-centric culture and great benefits.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.

US

  • Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
  • Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
  • Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.

Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.

$117,500–$166,250/yr
US

  • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
  • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
  • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.

Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.

US

  • Design and implement security controls across AWS GovCloud environments.
  • Integrate security into CI/CD pipelines using Terraform and GitLab.
  • Ensure compliance with FedRAMP and DoD IL-4/5 standards.

Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

US

  • Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
  • Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
  • Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.

Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.

$130,000–$160,000/yr
US Unlimited PTO

  • Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
  • Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
  • Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.

Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.

$123,601–$159,000/yr
US

  • Design and automate infrastructure and deployment solutions to optimize software development and release processes.
  • Implement CI/CD pipelines and automation tools to accelerate development cycles and ensure continuous integration and delivery.
  • Collaborate with stakeholders and ensure system security, reliability, and efficiency through best practices and monitoring.

EXPANSIA is a defense technology platform delivering high-impact technologies and services to the U.S. Department of Defense. As a multi-entity enterprise, they focus on scalable growth, operational excellence, and long-term value creation.

US

  • Lead the security strategy, governance, and operational execution for enterprise platforms supporting mission-critical capabilities across the Department of Defense and USSOCOM.
  • Develop enterprise security strategies aligned to Zero Trust principles and oversee implementation of security controls across cloud, hybrid, and containerized environments.
  • Provide technical leadership for identity and access management, cloud security posture management, and security automation initiatives while ensuring compliance with DoD RMF.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed, delivering commercial-grade platforms and mission-ready AI to federal agencies. Headquartered in Tysons, Virginia, LMI serves the defense, space, healthcare, and energy sectors, focusing on agility and collaboration to help agencies navigate complexity.

$175,000–$265,000/yr
US Unlimited PTO

  • Develop and execute cybersecurity strategy, roadmap, and governance to protect Voyager's information systems and mission-critical environments.
  • Lead security operations, incident response, vulnerability management, and compliance with government regulations like CMMC and NIST.
  • Oversee security architecture, risk management, and team leadership to enable secure innovation in aerospace and defense.

Voyager is an innovative space, defense, and national security technology company delivering transformative, mission-critical solutions. It fosters a culture where innovation thrives, curiosity is rewarded, and impact is real, with a team of doers, thinkers, and builders united by purpose.

US 3w PTO

  • Design, develop, and maintain automated workflows for RMF, A&A, and continuous monitoring.
  • Develop integrations between GRC platforms, security tools, and reporting solutions.
  • Automate evidence collection, control validation, and compliance activities to improve efficiency.

True Zero Technologies is a veteran-owned small business that enables people and technology to deliver top-tier cybersecurity services. With a people-first approach, the company has been recognized as a Best Places to Work honoree and made the Inc. 5000 list, reflecting a culture of driven and passionate individuals.

US 24w maternity 24w paternity

  • Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
  • Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
  • Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.

Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.