Information System Security Officer (ISSO) – TS/SCI
Strategic Business Systems (SBS)About the role
Location: Arlington, VA , onsite
Clearance Required: Active TS/SCI
Employment Type: Full-Time
Security Clearance: Active Top Secret/SCI clearance
ABOUT SBS
Strategic Business Systems, Inc. (SBS) delivers AWS-aligned mission-critical cloud, cybersecurity, software engineering, and data modernization solutions to the U.S. Department of Defense, the Intelligence Community, and federal civilian agencies.
We hire engineers, architects, and consultants who want to do hands-on work on high-impact national-security programs while collaborating directly with AWS Professional Services. Our culture is technical, lean, and clearance-friendly: we invest in certifications, retain talent through long-duration prime engagements, and provide a comprehensive benefits package.
Position Overview
SBS is seeking experienced Information System Security Officers (ISSOs) to support Amazon Web Services (AWS) Federal customers operating within highly secure, classified cloud environments. This position is responsible for leading Risk Management Framework (RMF) activities, maintaining Authorization to Operate (ATO) packages, implementing continuous monitoring strategies, and ensuring compliance with NIST and DoD cybersecurity requirements across multiple security domains.
The ideal candidate possesses a strong background in RMF, cloud security, and AWS-native security services while partnering with engineering teams to maintain secure cloud environments supporting Department of Defense and Intelligence Community missions.
Risk Management Framework (RMF)
- Develop, maintain, and update RMF documentation supporting IATT and ATO packages.
- Author and maintain:
- System Security Plans (SSPs)
- Security Control Family Plans (AC, IA, SC, SI, etc.)
- POA&Ms
- Control implementation statements
- Continuous Monitoring documentation
- Support the full RMF lifecycle in accordance with DoDI 8510.01 and NIST SP 800-53 Rev. 5.
- Monitor security posture across AWS environments supporting IL2, IL4, Secret, and TS workloads.
- Assess cloud environments against NIST 800-53 security controls.
- Configure and monitor AWS security services including:
- GuardDuty
- Security Hub
- AWS Config
- IAM
- AWS Organizations / SCPs
- Assist engineering teams in implementing secure cloud architectures.
- Review vulnerability findings and support remediation efforts.
- Maintain POA&Ms and continuous monitoring activities.
- Work with third-party security tools including:
- Palo Alto
- ACAS
- Elastic
- Ensure compliance with customer cybersecurity policies and accreditation requirements.
- Partner with cloud engineers, ISSOs, ISSEs, architects, and customer security teams.
- Participate in security assessments and authorization reviews.
- Provide guidance during audits and compliance activities.
- Support ongoing improvements to cloud security posture and automation.
- Active TS/SCI Clearance.
- 5+ years of Information Assurance, Cybersecurity, or Information System Security experience.
- Minimum 2 years supporting RMF and NIST SP 800-53.
- Minimum 1 year supporting AWS cloud security environments.
- Experience creating and maintaining complete ATO packages.
- Experience with SSPs, POA&Ms, Continuous Monitoring, and Contro
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s