ISSM / Security Automation Engineer

Tyto Athene, LLC

Northern (KY)

Hybrid

USD 175,000 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health/Dental/Vision
401(k) match
Paid Time Off

Job summary

Tyto Athene, LLC is seeking an Information System Security Manager (ISSM) / Security Automation Engineer to lead RMF and continuous assurance while building automation to enable continuous security and compliance. The role blends governance with hands-on development across Python, APIs, cloud platforms, and DevSecOps practices.

Ideal candidates will have production automation experience, strong RMF/NIST knowledge, and the ability to translate complex regulatory requirements into technical

Qualifications

  • Bachelor's degree or equivalent professional experience in cybersecurity related field.
  • Hands-on ISSM/IR/DevSecOps experience with automation & compliance.
  • Strong knowledge of NIST SP 800-53/800-37, RMF, and continuous monitoring.
  • Experience developing production automation, scripts, integrations, or software.
  • Proficient in Python and at least one other scripting language; JSON/YAML experience.
  • Experience with cloud platforms (AWS, Azure or GCP) and vulnerability management.
  • Ability to translate regulatory requirements into technical engineering tasks.

Responsibilities

  • Lead RMF, Security Authorization & Continuous Assurance.
  • Engineer security and compliance automation using Python, PowerShell, Bash and APIs.
  • Translate controls into machine-readable policies and automated validation.
  • Embed security in Cloud & DevSecOps workflows with CI/CD and IaC.
  • Build integrations across cloud, security tools, and CI/CD systems.
  • Automate vulnerability ingestion, tracking, and remediation workflows.
  • Develop dashboards and reports for continuous security visibility.

Skills

RMF implementation
Python scripting
Cloud security
DevSecOps
Automation scripting
JSON & YAML
Vulnerability management
AWS/Azure/GCP
CI/CD pipelines
Security automation

Education

Bachelor's degree in Cybersecurity or related

Tools

Terraform
Ansible
GitHub Actions
Kubernetes
Jenkins
OPA

Job description

Description

Quantum Sky is searching for a highly technical Information System Security Manager (ISSM) / Security Automation Engineer to lead cybersecurity risk management and security authorization activities while designing and developing automation that enables continuous security and compliance.

This is a hands-on engineering role for an individual who can operate effectively across cybersecurity governance, cloud security, DevSecOps, software automation, and NIST Risk Management Framework (RMF) environments. The successful candidate will own traditional ISSM responsibilities while also developing scripts, integrations, and automated workflows that reduce manual compliance activities and provide continuous visibility into system security posture.

The ideal candidate has previous software development or automation engineering experience and is comfortable working directly with source code, APIs, cloud services, CI/CD pipelines, Infrastructure as Code, security tooling, and machine-readable compliance data.The objective of this position is to move security programs away from periodic, document-driven compliance toward automated, continuous security assurance and Compliance as Code.

Responsibilities:

  • Lead RMF, Security Authorization & Continuous Assurance — Own NIST RMF implementation, system authorization and ongoing authorization activities, including SSPs, control implementation documentation, risk assessments, continuous monitoring artifacts, and coordination with system owners, assessors, ISSOs, engineers, and Authorizing Officials.
  • Engineer Security & Compliance Automation — Design, develop, and maintain production-quality automation using Python, PowerShell, Bash, APIs, and cloud-native technologies to automate control validation, evidence collection, compliance reporting, security assessments, and remediation workflows.
  • Implement Compliance as Code & Continuous Control Monitoring — Translate NIST SP 800-53 controls and organizational requirements into measurable technical requirements, machine-readable policies, automated validation procedures, and continuous control monitoring capabilities.
  • Embed Security into Cloud & DevSecOps Workflows — Partner with engineering and platform teams to integrate security into cloud architectures, Infrastructure as Code, CI/CD pipelines, containers, Kubernetes, and software delivery processes, including automated testing, policy validation, and security gates.
  • Integrate Security Platforms, Data & Tooling — Build integrations and reusable services connecting cloud platforms, vulnerability scanners, security tools, GRC platforms, ticketing systems, source-code repositories, and CI/CD systems using APIs and structured data such as JSON and YAML.
  • Manage Vulnerabilities, Findings & Cybersecurity Risk — Automate vulnerability and configuration finding ingestion, correlation, prioritization, assignment, tracking, and reporting; manage POA&Ms, exceptions, and remediation through closure; and evaluate system architectures and changes for cybersecurity risk.
  • Deliver Continuous Security Visibility & Improvement — Develop dashboards, metrics, and automated reporting that provide actionable visibility into vulnerabilities, configuration compliance, control status, POA&Ms, and organizational risk while identifying opportunities to replace manual security reviews with automated technical validation.
Qualifications

Required:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field, or equivalent professional experience.
  • Demonstrated experience as an ISSM, ISSO, Security Engineer, Cloud Security Engineer, DevSecOps Engineer, or similar technical cybersecurity professional.
  • Strong knowledge of NIST SP 800-53, NIST SP 800-37, RMF, security authorization, security control assessment, and continuous monitoring.
  • Demonstrated hands-on experience developing production-quality automation, scripts, integrations, or software.
  • Strong programming or scripting experience with Python and experience with one or more additional languages or scripting environments such as PowerShell, Bash, JavaScript, or Go.
  • Experience working with JSON and YAML.
  • Experience automating cybersecurity, infrastructure, compliance, or operational processes.
  • Experience with vulnerability scanning and vulnerability management technologies.
  • Experience with cloud platforms such as AWS, Azure or GCP.
  • Ability to understand cloud and enterprise system architectures and evaluate their security implications.
  • Ability to translate regulatory and cybersecurity requirements into technical engineering requirements.

Desired:

  • Experience developing automation against AWS, Azure or GCP API/SDKs
  • Experience with Infrastructure as Code technologies such as Terraform.
  • Experience with configuration management and automation technologies such as Ansible.
  • Experience with CI/CD platforms such as GitHub Actions, GitLab CI/CD, Jenkins, or Azure DevOps.
  • Experience with container and orchestration technologies such as Docker and Kubernetes.
  • Experience integrating vulnerability scanners, SIEM platforms, CSPM/CNAPP solutions, GRC platforms, and ticketing systems.
  • Experience developing security dashboards and data pipelines.
  • Experience with automated testing frameworks and software engineering practices.
  • Experience with serverless architectures and event-driven automation.
  • Experience transforming NIST controls and security documentation into structured, machine-readable data.
  • Experience with Compliance as Code and Policy as Code technologies such as Open Policy Agent (OPA).
  • Experience implementing automated security evidence collection and continuous control validation.

Desired Federal Cybersecurity Experience:

  • Experience supporting FISMA, FedRAMP, DoD RMF, CMMC, or other federal cybersecurity programs.
  • Experience supporting systems through initial authorization and ongoing authorization processes.
  • Experience working with Security Control Assessors (SCAs), Third Party Assessment Organizations (3PAOs), or government Authorizing Officials.
  • Experience developing or maintaining SSPs, POA&Ms, Security Assessment Reports, continuous monitoring documentation, and supporting authorization artifacts.
  • Familiarity with federal security baselines, implementation guidance, and security assessment procedures.

Desired Certifications:

  • One or more of the following is preferred:
  • CISSP, CGRC, CISM, CCSP, Security+
  • AWS Solution Architect or Security Specialty
  • GCP Cloud Architect or Security Engineer
  • Certified Kubernetes Security Specialist (CKS)
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $175,000-$190,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid Time Off
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Tyto Athene, LLC • Washington

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid Time Off
+2
Cybersecurity Analyst - Journeyman
Cybersecurity Analyst - Journeyman

Quantum Sky • Colorado Springs (CO)

On-site
USD 80,000 - 95,000
Health/Dental/Vision
401(k) match
Flexible Time Off
+2
Engagement Manager
Engagement Manager

Quantum Sky • United States

Remote
USD 110,000 - 130,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Chief Engineer / Technical Director
Chief Engineer / Technical Director

Quantum Sky • Arlington (VA)

On-site
USD 200,000 - 240,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Quantum Sky • Arlington (VA)

On-site
USD 140,000 - 175,000
Cyber Security Analyst Level II
Cyber Security Analyst Level II

Quantum Sky • Warner Robins (GA)

On-site
USD 75,000 - 85,000
Cybersecurity Engineer
Cybersecurity Engineer

Quantum Sky • Virginia Beach (VA)

On-site
USD 100,000 - 112,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Enterprise ITSM & Continual Service Improvement (CSI) Lead
Enterprise ITSM & Continual Service Improvement (CSI) Lead

Quantum Sky • Arlington (VA)

On-site
USD 150,000 - 210,000
Tier 3 Incident Response Lead
Tier 3 Incident Response Lead

Quantum Sky • Washington

Hybrid
USD 170,000 - 180,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1