We are seeking a highly experienced Senior GRC Engineer / Information System Security Officer (ISSO) to support a long-term federal cybersecurity program.
This is not a traditional, documentation-only ISSO or checkbox-compliance position. The ideal candidate will operate at the intersection of governance, risk, and compliance, cloud security, and enterprise engineering.
The Senior GRC Engineer / ISSO will apply deep knowledge of the Risk Management Framework, FedRAMP, and NIST security requirements while partnering with cloud, platform, security, and engineering teams to turn regulatory requirements into practical, scalable security controls.
The successful candidate will help accelerate Authority to Operate activities, improve continuous monitoring, reduce audit friction, and embed security into cloud platforms and enterprise technology environments.
Key Responsibilities
- Serve as a senior cybersecurity and compliance advisor to system owners, engineers, technical teams, and federal stakeholders.
- Lead and support Risk Management Framework activities throughout the system development lifecycle.
- Translate NIST, FedRAMP, and federal security requirements into practical technical guidance, cloud security guardrails, and repeatable implementation patterns.
- Support the development, review, and maintenance of security authorization documentation, including System Security Plans, Security Assessment Reports, Plans of Action and Milestones, control implementation statements, and supporting evidence.
- Help accelerate ATO and ongoing authorization efforts by identifying security requirements and implementation gaps early in the development process.
- Partner with Azure, Microsoft 365, platform engineering, cloud security, and DevSecOps teams to design secure and compliant solutions.
- Evaluate the implementation and effectiveness of security and privacy controls.
- Support continuous monitoring through automated evidence collection, vulnerability management, metrics, dashboards, and control validation.
- Analyze control inheritance, shared-service dependencies, and cloud shared-responsibility models.
- Prepare teams for independent security assessments, audits, and regulatory reviews.
- Track cybersecurity risks, vulnerabilities, findings, and remediation activities.
- Provide clear status updates, risk assessments, and recommendations to technical and nontechnical stakeholders.
- Manage multiple priorities, deadlines, and client requirements in a fast-paced federal consulting environment.
- Identify opportunities to improve GRC, ATO, continuous monitoring, and security engineering processes.
Required Qualifications
- 7–10 or more years of experience in cybersecurity, governance, risk, compliance, security engineering, information assurance, or ISSO functions.