About the role

About the Rolei Adeptive Technologies is seeking a senior, hands-on ISSO/Cloud Security & Dev Sec Ops Engineer to lead the security authorization for a FedRAMP High environment supporting a federal health agency. Proven ISSO/ATO experience is the primary requirement: this position owns the authorization package and drives the system through authorization on an accelerated timeline. The role works as part of the cloud team, sharing the same backlog, standups, and pipeline as the engineers, and requires strong AWS and Dev Sec Ops skills. Security is implemented directly in the platform and the CI/CD pipeline rather than managed from a separate compliance function. Beyond the program, this is a key corporate security role. The position sets the direction for iAdeptive’s enterprise zero-trust and cybersecurity posture, providing strategy, standards, and oversight across the organization. The role therefore requires genuine depth in security authorization and cloud engineering, combined with the judgment to lead security at a corporate level. How We Work Security Is Embedded, Not Siloed — This position works as part of the cloud team, sharing the same backlog, standups, and pipeline as the engineers, and embeds security controls into the build rather than reviewing them afterward. Authorization-Led and Hands-On — The ATO is the anchor of the role — attaining and sustaining the authorization boundary on an accelerated timeline — while remaining hands-on in AWS and the pipeline throughout. Corporate Security Leadership — Alongside program delivery, the role owns the direction of the company’s zero-trust and cybersecurity posture, setting standards and providing oversight that protect the organization as a whole.
What You Will Do: ISSO / Authorization (Primary)Serve as ISSO for a FedRAMP High environment, owning the authorization package and driving it through attainment and ongoing authorization on an accelerated timeline. Author and maintain the System Security Plan (SSP), control narratives, and supporting artifacts against NIST 800-53 and agency security baselines. Manage Plans of Action and Milestones (POA&Ms), track remediation to closure, and maintain audit-ready evidence. Lead Assessment and Authorization (A&A) activities and serve as the security point of contact for assessors and oversight. Establish and operate continuous monitoring, including vulnerability scanning, configuration compliance, and security event review. Cloud Security & Dev Sec Ops (Required)Operate as an embedded member of the cloud and platform team, participating in the backlog, standups, and pipeline alongside the engineering staff. Implement and validate security controls in AWS Gov Cloud, including IAM, logging, encryption, network security, and configuration compliance. Build and harden the CI/CD pipeline, embedding security gates, scanning, and automated evidence collection through policy-as-code. Author and review infrastructure-as-code to enforce secure configuration by default. Automate compliance and monitoring to support continuous authorization and efficient post-ATO sustainment. Corporate Cybersecurity & Zero Trust (Strategy & Oversight)Set the direction for the company’s enterprise zero-trust and cybersecurity strategy, standards, and policies. Provide security oversight across the organization, including identity, access, endpoint, and network security posture. Guide the adoption of security best practices company-wide and advise leadership on cyber risk.
What We’re Looking For: Primary Requirement Direct, hands-on ISSO experience in a federal environment, including at least one system taken through Assessment and Authorization (A&A) to an ATO.Strong command of NIST 800-53, the RMF, FedRAMP, and FISMA, with the ability to author control narratives accepted by assessors. Experience managing POA&Ms, continuous monitoring, and audit-ready evidence.
Required: Cloud & Dev Sec Ops Hands-on AWS engineering experience, including IAM, encryption, networking, and configuration compliance (Gov Cloud preferred).Hands-on Dev Sec Ops experience building and securing CI/CD pipelines, infrastructure-as-code, and security automation. A track record of working within an engineering team and delivering implementation work, not solely security review. Clear technical writing and the ability to communicate effectively with both engineers and assessors. Corporate Security Leadership Experience defining zero-trust or enterprise security strategy, standards, and policy at an organizational level. Ability to advise leadership on cyber risk and drive security best practices across a company.
Bonus Points: Security certification such as CISSP, CISM, CAP, or AWS Security – Specialty. AWS certification (Solutions Architect, Sys Ops, or Dev Ops Engineer).Experience with container security, Terraform, and federal compliance or authorization tracking tooling. Familiarity with ISO/IEC 42001 or AI risk frameworks where AI systems fall within the authorization boundary.
Core Competencies: Competency What It Looks Like Here Authorization Ownership Drives an A&A package through to ATO and sustains it — the primary anchor of the role. Embedded Security Works within the cloud team, integrating controls into the build. Hands-On AWSImplements and validates security controls directly in AWS.Dev Sec Ops Builds and secures the CI/CD pipeline using policy-as-code and IaC.Corporate Zero Trust Sets enterprise security strategy, standards, and oversight company-wide. Communication Writes assessor-ready narratives and advises leadership on cyber risk. Why iAdeptivei Adeptive Technologies is an 8(a) small business that delivers modern data, cloud, and AI engineering to federal mission programs. We are engineers first. We win work by building systems that hold up under audit and scale under real load — not by selling slideware. You will work alongside architects and engineers who write the code they design, ship into FedRAMP-authorized environments, and treat governance and security as part of the build rather than paperwork bolted on at the end. Small enough that your work is visible; serious enough that it matters Details
Location: Remote (U.S.); Maryland-area candidates preferred for occasional on-site collaboration
Employment Type: Full-time, W-2. Eligibility to work in the U.S. required; this role supports federal programs and may require the ability to obtain a Public Trust or higher background determination
Education: Bachelor’s degree in computer science, information security, a related field, or equivalent professional experience
Experience: 7+ years across information security and cloud/Dev Sec Ops, including hands-on ISSO experience with a system taken through A&A to ATO
Benefits: Health, dental, and vision coverage; 401(k) with company contribution; paid time off and federal holidays; training and certification support

Matching similar jobs

JOB OVERVIEW

Experience level

Lead

Location

Columbia, MD

Occupation

Information Security Engineers

Industry

Computer Systems Design Services

Posted

2 days ago

Tired of running searches?

Rank the roles you'd take once, and matches like these arrive on their own.

CREATE PROFILE