Information Systems Security Officer
This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S.
Who we are:
Raft (https://TeamRaft.com) is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a leader in autonomous data fusion and Agentic AI, with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development. With headquarters in McLean, VA, our range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem. We build digital solutions that impact the lives of millions of Americans.
About the role:
As an Information Systems Security Officer and Manager, you will manage security and compliance activities supporting Raft's cloud-native products and customer environments. You will work closely with engineering and program teams to apply the Risk Management Framework, maintain accurate authorization documentation, assess security risk, and support IATT and ATO efforts across systems at different stages of authorization.
This role requires strong working knowledge of RMF and NIST guidance and experience applying security controls in Kubernetes, containerized workloads, and other cloud-native environments.
What you will do
- Provide ISSO oversight across Raft's product contracts, applying consistent RMF practices while accounting for each customer's system boundary and authorization requirements.
- Develop and maintain mature RMF authorization packages, including System Security Plans, security control traceability matrices, Ports Protocols and Services Management artifacts, architecture and data-flow diagrams, POA&Ms, and bodies of evidence.
- Translate system architectures and operational processes into accurate control implementation statements, policies, procedures, and supporting evidence aligned with applicable security control baselines.
- Coordinate control owners, engineers, system administrators, and program stakeholders to collect evidence, address gaps, prepare for assessments, and maintain authorization readiness across supported environments.
- Partner with engineering teams to make evidence collection and recurring compliance reporting more automated, repeatable, reusable across systems, and traceable to authoritative sources.
- Conduct ongoing security risk assessments using findings from cloud and Kubernetes posture reviews, vulnerability and CVE analysis, DISA STIG scans, network monitoring, software-supply-chain reviews, configuration-drift detection, and endpoint protection tools.
- Manage POA&Ms from identification through validated closure, including risk prioritization, owners, milestones, due dates, remediation evidence, and status reporting.
- Evaluate proposed architecture, configuration, boundary, and deployment changes for security-control and authorization impact.
- Conduct continuous monitoring, configuration reviews, control assessments, and readiness reviews; embed security requirements early and help technical teams select practical mitigations.
What we are looking for:
- At least four years of experience in ISSO, ISSM, cybersecurity compliance, information assurance, or a closely related role.
- Strong understanding of the Risk Management Framework and applicable NIST guidance, including NIST SP 800-37, NIST SP 800-53 Revision 5, and NIST SP 800-60.
- Demonstrated experience applying RMF and NIST security controls in cloud-native environments, including Kubernetes and containerized workloads.
- Experience developing and maintaining RMF artifacts such as SSPs, control implementation statements, traceability matrices, PPSM packages, POA&Ms, risk assessments, assessment plans and reports, vulnerability results, and supporting evidence.
- Experience with continuous monitoring, vulnerability management, DISA STIG compliance, security assessments, and remediation tracking in federal or DoD environments.
- Ability to organize and prioritize security activities, evidence, risks, and authorization milestones across multiple systems and customer environments.
- Ability to understand technical architectures and findings, connect them to security controls and mission risk, and communicate clearly with engineers, program leaders, and security stakeholders.
- Security+ or another qualifying DoD 8140 or contract-required certification at hire, or the ability to obtain it within six months of employment with Raft.
Highly preferred:
- Bachelor's degree in cybersecurity, information assurance, information technology, or a related field.
- CISSP, CISM, CISA, CGRC, or another relevant advanced cybersecurity certification.
- Experience with eMASS or a similar governance, risk, and compliance tool.
- Experience supporting or completing an IATT or ATO process.
- Experience securing Kubernetes-based DevSecOps platforms or software factories, particularly within Platform One or a comparable DoD environment.
- Experience implementing or assessing FIPS requirements.
- Experience writing and reviewing RMF control implementation statements, security policies, and procedures.
- Experience communicating security risk and authorization status to program or executive leadership.
Clearance Requirements:
-
Active Secret security clearance with the ability to obtain and maintain a Top Secret security clearance.
Salary Range: $150,000.00 - $190,000.00
Work Type:
-
The selected candidate will work onsite in Honolulu, Hawaii; Hanscom Air Force Base, Massachusetts; Tampa, Florida; Colorado Springs, CO; or the National Capital Region.
The position may require up to 35 percent travel to CONUS and OCONUS locations. Candidates must possess a valid, active U.S. passport with at least six months of validity beyond the intended travel period.
What we will offer you:
- Highly competitive salary
- Fully covered healthcare, dental, and vision coverage
- 401(k) and company match
- Take as you need PTO + 11 paid holidays
- Education & training benefits
- Generous Referral Bonuses
- And More!
Our Vision Statement:
We bridge the gap between humans and data through radical transparency and our obsession with the mission.
Our Customer Obsession:
We will approach every deliverable like it's a product. We will adopt a customer-obsessed mentality. As we grow, and our footprint becomes larger, teams and employees will treat each other not only as teammates but customers. We must live the customer-obsessed mindset, always. This will help us scale and it will translate to the interactions that our Rafters have with their clients and other product teams that they integrate with. Our culture will enable our success and set us apart from other companies.
How do we get there?
Public-sector modernization is critical for us to live in a better world. We, at Raft, want to innovate and solve complex problems. And, if we are successful, our generation and the ones that follow us will live in a delightful, efficient, and accessible world where out-of-box thinking, and collaboration is a norm.
Raft’s core philosophy is Ubuntu: I Am, Because We are. We support our “nadi” by elevating the other Rafters. We work as a hyper collaborative team where each team member brings a unique perspective, adding value that did not exist before. People make Raft special. We celebrate each other and our cognitive and cultural diversity. We are devoted to our practice of innovation and collaboration.
We’re an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Create a Job Alert
Interested in building your career at Raft Company Website? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field
