Sr. Principal Information Security Engineer (ISSO)

Clarityinnovates

Columbia (MD)

On-site

USD 100,000 - 330,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Clarity Innovations is seeking a Principal Information Security Specialist to lead compliance for a multi-tenant cloud platform spanning AWS, Azure, and on‑prem environments.

You will translate federal security frameworks into development requirements, own the ATO lifecycle, and oversee continuous monitoring, governance, and risk management to support government authorizations.

Qualifications

  • 5+ years guiding complex information systems through the RMF/SP 800-37 lifecycle to government authorizations.
  • Proven ability to author clear security policies, SOPs, control statements, and system narratives.
  • Experience administering system packages within federal governance frameworks (e.g., eMASS or XACTA).

Responsibilities

  • Own the ATO and all associated documentation, including SSPs, control statements, POA&Ms, boundary & interconnection agreements; maintain live-state accuracy.
  • Lead ConMon reporting, POA&M tracking, and SBOM/supply-chain representation; coordinate with engineers on required changes.
  • Draft, update, and manage system boundary mappings, site addendums, delta-SSPs, inheritance packages, and ISAs to streamline authorization.
  • Author and review security policies, SOPs, and Rules of Behavior; plan phasing Day-1 controls into automation.
  • Translate NIST 800-53 controls into backlog requirements; enable compliance with minimal bottlenecks.

Skills

RMF & NIST Mastery
Technical Writing & Policy Formulation
ATO Package Administration
Cross-Functional Collaboration
Cloud & Container Knowledge
Industry Certifications (CISSP/CISM/CC

Tools

eMASS
XACTA
SBOM tooling

Job description

Clarity Innovations is a trusted national security partner, dedicated to safeguarding our nation’s interests and delivering innovative solutions that empower the Intelligence Community (IC) and Department of Defense (DoD) to transform data into actionable intelligence, ensuring mission success in an evolving world.

Our mission-first software and data engineering platform modernizes data operations, utilizing advanced workflows, CI/CD, and secure DevSecOps practices. We focus on challenges in Information Warfare, Cyber Operations, Operational Security, and Data Structuring, enabling end-to-end solutions that drive operational impact.

We are committed to delivering cutting-edge tools and capabilities that address the most complex national security challenges, empowering our partners to stay ahead of emerging threats and ensuring the success of their critical missions. At Clarity, we are people-focused and set on being a destination employer for top talent, offering an environment where innovation thrives, careers grow, and individuals are valued. Join us as we continue to lead innovation and tackle the most pressing challenges in national security.

Principal Information Security Specialist

(Information System Security Officer)

Position Overview

The position is part of a team of software and platform engineers building a unified, multi-tenant control plane that abstracts away infrastructure differences across AWS, Azure, and on-premises environments. The platform allows application teams to provision secure, isolated Kubernetes clusters and workloads dynamically. The control plane runs Crossplane and Cluster API (CAPI).

As the Principal Information Security Specialist your primary responsibility is translating traditional federal and enterprise security frameworks (e.g., DoDI 8510.01, JSIG, NIST SP 800-37) into clear, prioritized requirements for the development and engineering teams. You will act as a compliance partner to the teams, guiding them on what guardrails need to exist while they handle the implementation. Additionally, you will own the entire Authorization to Operate (ATO) package lifecycle, specializing in writing governance policies, preparing and modifying site addendums, and executing continuous risk management processes to achieve authorizations across the full Information System (IS) boundary. Lastly, you will manage continuous monitoring (ConMon) reporting and documentation obligations.

The ideal candidate is highly independent, capable of navigating complex regulatory frameworks with minimal supervision, and possesses a deep engineering curiosity regarding containerization and cloud infrastructure.

Key Responsibilities
  • ATO package and authorization documentation: Own the ATO and all associated documentation, including the SSP, control statements, POA&Ms, boundary and interconnection agreements. Keep all documents accurate to the live state of the system, with authority as the final word on documentation completeness.
  • Continuous monitoring and risk management: Own ConMon reporting, POA&M tracking, and SBOM/supply-chain representation. Coordinate with engineers on anything requiring technical changes.
  • System boundary coordination: Draft, update, and manage the system's formal boundary mappings, site addendums, delta-SSPs, inheritance packages, and ISAs that streamline the path to authorization.
  • Policy generation and governance: Author and review system security policies, SOPs, and Rules of Behavior. Develop a pragmatic plan for phasing manual Day-1 controls into automation over time.
  • Compliance-to-engineering translation: Turn NIST 800-53 controls into clear backlog requirements and evidence standards, working as a compliance enabler rather than a bottleneck.
Qualifications
Skills & Experience
  • RMF & NIST Mastery: 5+ years of experience guiding complex information systems through the NIST SP 800-37 Risk Management Framework (RMF), DoDI 8510.01, or JSIG lifecycles to achieve government authorizations.
  • Technical Writing & Policy Formulation: Proven track record of authoring clear, concise, and unassailable security policies, SOPs, control statements, and system configuration narratives.
  • ATO Package Administration: Expert proficiency managing system packages within federal governance frameworks and data tools of record like eMASS or XACTA.
  • Cross-Functional Collaboration: Demonstrated success partnering with software developers, cloud engineers, or SREs, serving as a proactive compliance enabler rather than an operational bottleneck.
  • Conceptual Tech Literacy: A strong conceptual understanding of cloud environments (AWS/Azure) and core container concepts (Kubernetes). You do not need to build, code, or configure these tools, but you must be able to understand an architecture diagram and discuss security requirements intelligently with engineers.
  • Active industry certifications (e.g., CISSP, CISM, CCSP)
Soft Skills & Engineering Mindset
  • Agile & Pragmatic Risk Management: Experience working in sprint-based engineering environments where security documentation is treated as a living artifact; comfortable leveraging manual controls on Day 1 while driving toward automation.
  • Clear Communicator: Strong capability to translate rigid compliance terminology and policy expectations into actionable tasks for developers, and conversely, translating complex cloud-native architectures into risk-management language for traditional auditors.
  • Extreme Ownership: Takes absolute accountability for the accuracy, completeness, and on-time delivery of the compliance packages, site addendums, and system security files to government stakeholders.
Preferred Qualifications
  • Hands-on experience using automated governance tools or GitOps-driven compliance engines.
  • Prior experience working directly with Authorizing Officials (AOs) to transition highly dynamic or ephemereal cloud infrastructures to a continuous authorization state.

Salary Range: $100,000 - $330,000

We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Principal Information Security Engineer (ISSO)
Sr. Principal Information Security Engineer (ISSO)

Clarity Innovations • Columbia (MD)

On-site
Senior Principal InfoSec Engineer – RMF/ATO Lead
Senior Principal InfoSec Engineer – RMF/ATO Lead

Clarity Innovations • Herndon (VA), Columbia (MD)

On-site
Principal Information Security Engineer
Principal Information Security Engineer

Clarity Innovations • Fort Meade (MD)

On-site
USD 117,000 - 292,000
Principal Information Security Engineer
Principal Information Security Engineer

Clarityinnovates • Fort Meade (MD)

On-site
USD 117,000 - 292,000
Sr. Principal Mission Engineer
Sr. Principal Mission Engineer

Clarityinnovates • Columbia (MD)

On-site
USD 100,000 - 330,000
Senior Principal Information System Security Officer - Big Data
Senior Principal Information System Security Officer - Big Data

Socket.dev • Herndon (VA)

On-site
USD 100,000 - 270,000
Senior Principal Information System Security Officer - Big Data
Senior Principal Information System Security Officer - Big Data

Clarityinnovates • Herndon (VA)

On-site
USD 100,000 - 270,000
Sr. Principal Mission Engineer
Sr. Principal Mission Engineer

Socket.dev • Columbia (MD)

On-site
USD 100,000 - 330,000
Sr. Principal Platform Engineer
Sr. Principal Platform Engineer

Clarityinnovates • Herndon (VA)

Hybrid
USD 120,000 - 150,000
Sr. Principal Platform Engineer
Sr. Principal Platform Engineer

Clarity Innovations • Herndon (VA)

Hybrid
USD 100,000 - 130,000