Senior Cloud ISSO (Cloud)
The Senior Information Systems Security Officer (ISSO) - Cloud is responsible for overseeing cybersecurity compliance, risk management, and security operations for cloud-based and hybrid federal information systems within a cleared environment. This role supports the implementation and maintenance of secure cloud architectures while ensuring compliance with RMF, NIST, and federal cybersecurity requirements.
Responsibilities
- Serve as the Senior ISSO for cloud-based and hybrid information systems in classified and enterprise environments.
- Support implementation and maintenance of RMF cybersecurity processes and authorization activities for cloud systems.
- Conduct continuous monitoring, vulnerability management, and security compliance activities across cloud platforms.
- Assess cloud security risks and coordinate remediation efforts with technical and engineering teams.
- Maintain cybersecurity documentation including SSPs, POA&Ms, security assessments, and authorization artifacts.
- Utilize enterprise security tools to identify, analyze, and mitigate cybersecurity vulnerabilities and threats.
- Support security assessments, audits, inspections, and compliance reviews.
- Coordinate with government stakeholders, system owners, and cloud engineers to ensure adherence to federal cybersecurity standards.
- Monitor cloud environments for security events, suspicious activity, and configuration compliance issues.
- Provide technical guidance on cloud security best practices, architecture, and risk mitigation strategies.
- Support incident response and remediation activities involving cloud infrastructure and applications.
- Track and report cybersecurity risks, findings, and remediation status to leadership.
Education and Experience
- Minimum of 9 years of experience in cybersecurity, information assurance, computer science, or related IT fields.
- At least 7 years of experience serving as an ISSO within a cleared or classified environment.
- Experience supporting cloud-based systems and cloud security operations in AWS, Azure, or GCP environments.
- Bachelor's degree in computer science, Cybersecurity, Information Technology, Business Management, or related discipline preferred.
- Advanced degree in a related field preferred.
- Experience supporting RMF, NIST cybersecurity frameworks, and federal compliance programs required.
Required Skills
- Strong understanding of RMF, NIST standards, and federal cybersecurity compliance frameworks.
- Experience securing cloud environments and supporting cloud authorization activities.
- Familiarity with enterprise cybersecurity and vulnerability management tools including Tenable Nessus/Security Center, Splunk, IBM Guardium, HP Webinspect, NMAP and similar cybersecurity monitoring and assessment tools.
- Strong knowledge of cloud security principles, architecture, and secure configuration management.
- Experience with continuous monitoring, vulnerability remediation, and risk analysis.
- Strong analytical, troubleshooting, and problem‑solving skills.
- Ability to support multiple systems and priorities in fast‑paced environments.
- Excellent written and verbal communication skills.
- Strong organizational and leadership capabilities.
Certifications
- CISSP (Certified Information Systems Security Professional)
- GISP (Global Information Security Professional)
- CASP+ (CompTIA Advanced Security Practitioner)
- Or equivalent certification meeting DoD 8570 IAM Level III requirements
Additional Cloud Certifications
- AWS Certified Security – Specialty
- CCSP ((ISC) Certified Cloud Security Professional)
- AWS Certified Solutions Architect – Associate
- Microsoft Certified: Azure Security Engineer Associate (AZ‑500)
- Google Professional Cloud Security Engineer
Security Clearance
- Active Top‑Secret clearance required.
- SCI eligibility may be required depending on assignment.
Benefits and Programs
B&A is proud to offer three robust individual and family medical plans to full‑time employees, including a Health Savings Account (HSA) option, as well as two tiers of dental coverage, vision, life & AD&D, disability, accident, hospital indemnity, and critical illness insurance. Employees enjoy paid time off, B&A sponsored trainings and certifications, pet insurance benefits, commuter transit benefits, and a free subscription to a virtual exercise platform (NEOU). B&A's 401(k) plan is available to all employees and includes a company matching contribution.
B&A has launched several programs to focus on employee engagement, wellness, and assistance, including the B&A Cares program, a formal mentorship program, job shadowing and cross‑training opportunities, a brand ambassador program, an Employee Assistance Program (EAP) providing counseling, legal guidance, and financial planning resources, monthly teambuilding events, and B&A Annual Wellness Challenges.
EEO
B&A provides equal employment opportunities (EEO) to all employees and applicants for employment in accordance with applicable federal, state, and local laws. B&A complies with applicable state and local laws governing non‑discrimination in employment in every location where the company has facilities. This policy covers conduct at B&A's offices and other workplaces, including client sites.