Xacta SaaS Information System Owner (ISO)

Telos Corp.

Ashburn (VA)

On-site

USD 105,000 - 130,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid time off
Medical, dental, vision
Tuition reimbursement
401k

Job summary

Telos Corporation in Ashburn, VA seeks an experienced Information System Owner (ISO) to lead security, risk, compliance, and authorization for a FedRAMP‑authorized cloud offering. You will oversee SSP alignment, monitoring, and evidence, coordinating across engineering, security, and compliance teams.

The role requires translating regulatory requirements into practical controls, automating compliance where possible, and managing FedRAMP activities and risk decisions. U.S. citizenship is required.

Qualifications

  • US Citizen with security certifications such as CISSP/CISM/CCSP.
  • 5–7+ years in cybersecurity, cloud security, or related fields.
  • Experience supporting FedRAMP, RMF, FISMA, or similar.
  • Ability to translate regulatory requirements into operational controls.

Responsibilities

  • Serve as the ISO for a FedRAMP CSO and maintain authorization posture.
  • Coordinate FedRAMP continuous monitoring and POA&M activities.
  • Align SSP, security controls, and evidence with NIST requirements.
  • Collaborate with DevSecOps and engineering on secure cloud architectures.
  • Coordinate responses to 3PAO assessments and government reviews.

Skills

FedRAMP
RMF
CISSP/CISM/CCSP
DevSecOps
3PAO coordination

Education

Bachelor's degree in Cybersecurity/IS/CS/Engineering

Tools

Xacta
GRC platforms

Job description

Job Title

Xacta SaaS Information System Owner (ISO)

Job Description

The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our solutions and the integrity of our people. Explore what you can bring to our solutions in the areas of cyber, cloud and enterprise security.

Be a part of the Telos culture and see what sets us apart! Telos offers an excellent compensation package with benefits that include generous paid time off, medical, dental, vision, tuition reimbursement, and 401k. The salary range for this position is $105K - $130K. Our employees enjoy more than just a great work environment!

This position will be based at Ashburn, VA

We are seeking an experienced Information System Owner (ISO) to provide security, risk, compliance, and authorization leadership for a FedRAMP-authorized Cloud Service Offering (CSO). The ISO will serve as the accountable operational owner for maintaining the system's availability, security and authorization/certification posture, ensuring that the production environment remain aligned with applicable FedRAMP and NIST requirements.

This role requires a combination of cybersecurity expertise, cloud and DevSecOps knowledge, risk-management judgment, and the ability to coordinate activities across engineering, operations, security, compliance, product, and executive stakeholders. The successful candidate will be able to translate regulatory requirements into practical operational controls while identifying opportunities to automate compliance activities and reduce the cost and effort required to maintain authorization.

Responsibilities
  • Serve as the primary operational owner for the CSO's FedRAMP Certification and operational posture.
  • Maintain alignment among the production environment, authorization boundary, System Security Plan (SSP), security controls, architecture documentation, inventories, policies, procedures, and supporting evidence.
  • Coordinate FedRAMP continuous monitoring activities and required recurring deliverables.
  • Oversee availability, vulnerability management, remediation tracking, POA&M activities, deviations, exceptions, and risk-acceptance processes.
  • Evaluate infrastructure, application, architecture, and configuration changes for security, compliance, and authorization impact.
  • Coordinate control owners and technical teams to ensure NIST SP 800-53 security requirements are appropriately implemented and evidenced.
  • Partner with DevSecOps and engineering teams on secure cloud architecture, CI/CD processes, configuration management, IAM, logging, encryption, vulnerability management, and related security capabilities.
  • Coordinate responses to 3PAO assessments, annual assessments, penetration testing, government reviews, customer inquiries, and evidence requests.
  • Evaluate findings and security issues based on technical severity, operational impact, regulatory requirements, and overall system risk.
  • Escalate significant risks, compliance deficiencies, and authorization concerns to appropriate technical and executive stakeholders.
  • Support incident response, contingency planning, system recovery, and related FedRAMP operational security requirements.
  • Identify opportunities to automate security and compliance activities, including control evidence collection, asset reconciliation, vulnerability workflows, compliance telemetry, and recurring reporting.
  • Develop security and risk metrics that provide leadership with visibility into the CSO's operational and authorization posture.
  • Promote continuous improvement of security, compliance, and DevSecOps processes.
Job Requirements

Required Qualifications:

  • US Citizen
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related discipline, or equivalent combination of education and relevant professional experience.
  • One or more relevant professional certifications such as CISSP, CISM, CCSP, CGRC, comparable cybersecurity credentials.
  • Approximately 5 - 7 years or more of progressive experience in cybersecurity, information assurance, cloud security, security operations, or related disciplines.
  • Demonstrated experience supporting FedRAMP, NIST Risk Management Framework (RMF), FISMA, or comparable federal security authorization environments.
  • System Security Plans, Plans of Action and Milestones (POA&M's), continuous monitoring, vulnerability management, security control assessments, control evidence collection, and risk-management activities.
  • Experience with Xacta or other GRC platforms
  • Experience operating or securing enterprise cloud or SaaS environments.
  • Working knowledge of cloud security concepts including identity and access management, network security, encryption, logging and monitoring, vulnerability scanning, configuration management, and incident response.
  • Ability to interpret technical vulnerability, configuration, and security data and translate findings into remediation priorities and risk decisions.
  • Experience coordinating security activities across engineering, operations, cybersecurity, and compliance teams.
  • Experience supporting security assessments, audits, or independent third-party assessments.
  • Strong analytical, written, verbal, and executive communication skills.
  • Ability to communicate technical and regulatory issues effectively to both technical and non-technical stakeholders.

Preferred Qualifications:

  • Direct experience supporting or maintaining a FedRAMP CSO environment.
  • AWS certification; or related cloud security certification
  • Working knowledge and use of Artificial Intelligence (AI) Tools, prompt engineering and agentic workflows
  • Experience interacting directly with 3PAOs, government assessors, or authorizing organizations.
  • Experience with DevSecOps environments, CI/CD pipelines, containers, Kubernetes, infrastructure as code, and automated security tooling.
  • Experience with API Security, automated evidence collection, and continuous control monitoring.
  • Familiarity with FedRAMP 20x and machine-readable security and compliance standards like OSCAL.
  • Experience integrating security telemetry from vulnerability scanners, cloud platforms, SIEM systems, CI/CD pipelines, and related security tools.
  • Experience supporting federal government customers or regulated cloud environments.

The successful candidate must meet eligibility requirements to access sensitive information, which requires US citizenship.

Telos maintains a drug-free workplace and will conduct drug testing on all applicants who have accepted an offer of employment.

Telos Corporation participates in the E-Verify program. Therefore, any employment with Telos will also be contingent upon confirmation from the Social Security Administration ("SSA") and/or the Department of Homeland Security ("DHS") of your authorization to work in the United States. Telos offers excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future.

Telos Corporation and its subsidiaries are committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. Telos Corporation will make reasonable accommodations for known physical or mental limitations of otherwise qualified employees and applicants with disabilities unless the accommodation would impose an undue hardship on the operation of our business. If you are interested in applying for an employment opportunity and feel you need a reasonable accommodation pursuant to the ADA, please contact us at 1-800-283-1911. If you require relay service assistance, please click on the following link to review information on your state's relay service: https://www.fcc.gov/accessibility.

Telos Corporation is an EEO/AA employer.

Job Type

Full-Time

Location

Ashburn, VA 20147 US (Primary)

Telos offers an excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future. Telos and its subsidiaries are an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Engineer
System Engineer

hackajob • Herndon (VA)

On-site
USD 80,000 - 110,000
Generous paid time off
Medical, dental, and vision benefits
Tuition reimbursement
+1
Senior Information Assurance/Security Engineer
Senior Information Assurance/Security Engineer

Telos Corp. • Reston (VA)

On-site
USD 160,000 - 180,000
Paid time off
Medical insurance
Dental insurance
+3
Senior Information Assurance Security Engineer
Senior Information Assurance Security Engineer

Telos Corp. • Washington

On-site
USD 160,000 - 190,000
Medical
Dental
Vision
+3
Cybersecurity Lead - C
Cybersecurity Lead - C

Telos Corp. • Ashburn (VA)

Hybrid
USD 104,000 - 156,000
Paid time off
Medical insurance
Dental insurance
+3
Senior Cybersecurity Auditor
Senior Cybersecurity Auditor

Telos Corp. • San Antonio (TX)

On-site
USD 120,000 - 150,000
Paid time off
Medical insurance
Dental insurance
+3
Cybersecurity Authorization Support Analyst
Cybersecurity Authorization Support Analyst

Telos Corp. • San Antonio (TX)

On-site
USD 70,000 - 100,000
Paid time off
Medical insurance
Dental insurance
+3
Cybersecurity Auditor
Cybersecurity Auditor

Telos Corp. • San Antonio (TX)

On-site
USD 90,000 - 130,000
Generous PTO
Medical
Dental
+3
Sr. Project Manager - C
Sr. Project Manager - C

Telos Corp. • Ashburn (VA)

Hybrid
USD 104,000 - 156,000
Senior Network Engineer
Senior Network Engineer

Telos Corp. • Ashburn (VA)

On-site
USD 90,000 - 140,000
Paid time off
Medical insurance
Dental insurance
+3
ConMon Security Engineer
ConMon Security Engineer

Telos Corp. • Tysons (VA)

On-site
USD 135,000 - 155,000
Paid time off
Medical insurance
Dental
+3