Jobs and Careers
SK

Chief Information Security Officer (CISO)

Skylight
United States, United StatesRemotefull_timeVerifiedPosted 8 Nov 2025
💰 $240,000/yr($170,000/yr$240,000/yr)

About the role

About Skylight

Skylight is a digital consultancy using design and technology to help government agencies deliver better public services. We’re at the forefront of a civic movement to reinvent how all levels of government serve families, patients, and many others in today's digital world.

If you want to play a part in driving this critical movement forward, we’d love for you to join our growing team of public interest technologists. The work we do matters.

About the job

As Skylight’s Chief Information Security Officer (CISO), you’ll lead Skylight’s security, compliance, and policy efforts, ensuring they align with Skylight’s business, technical, and regulatory requirements. As a trusted advisor and partner across the organization, you’ll balance deep technical understanding with clear communication and strong relationship-building skills.

Because Skylight supports multiple federal clients, our work must comply with CMMC Level 2, NIST 800-171, and, potentially, HIPAA. You’ll play a pivotal role in maintaining compliance with these regulations by developing organizational readiness, guiding engineering teams, and ensuring secure, compliant operations across all systems.

In this role, you’ll report directly to the Chief Information Officer (CIO). This is a hands-on, collaborative leadership role where you’ll partner closely with the CIO on priorities, decisions, and direction. You’ll also collaborate with the CIO on key aspects of Skylight’s IT infrastructure, including onboarding/offboarding, account management, and role-based access controls. While you don’t need to be an expert administrator for every tool we use, your partnership in this area is essential to maintaining both operational integrity and regulatory compliance.

What you’ll do

  • Lead the design, implementation, and day-to-day operation of Skylight’s information security and compliance efforts
  • Maintain and continuously improve compliance with Skylight’s regulatory requirements, including NIST 800-171, CMMC Level 2, and HIPAA
  • Represent Skylight externally for security audits, risk assessments, and communication with external assessors
  • Collaborate with the Chief Operating Officer (COO) and CIO to achieve and maintain Skylight’s facility security clearance (FCL) 
  • Administer and enforce identity and access management across Skylight’s IT infrastructure, including AWS, Azure, Google Cloud Platform (GCP), Google Workspace, and Slack
  • Partner with project and delivery teams to integrate security and compliance into project planning, delivery, and client communications
  • Lead periodic risk assessments and report findings to the CIO and leadership team to inform decision-making
  • Develop and maintain internal security and IT policies, ensuring they’re accessible, practical, and actionable
  • Deliver annual security awareness training across the organization
  • Collaborate with the CIO to align security priorities with company strategy and resource planning
  • Stay current on evolving security practices, technologies, and emerging threats

What we're looking for

Minimum qualifications

  • An active security clearance or the eligibility to obtain one
  • Hands-on experience with identity and access management (IAM), role-based access control (RBAC), and related concepts in AWS, Azure, and GCP
  • Demonstrated success leading security audits or compliance assessments
  • Excellent communication and documentation skills, with the ability to explain technical and regulatory concepts in plain language
  • Experience enumerating and mitigating organizational vulnerabilities
  • Experience mitigating security risks in the software development life cycle at the organizational level
  • Ability to interpret and translate non-technical material, such as regulations, into business and technical requirements
  • Deep understanding of and achieving compliance with NIST 800-171
  • Proven ability to foster trust and collaboration across technical and non-technical teams
  • Ability to work successfully within a professional services environment (e.g., can communicate effectively with clients)
  • A passion for creating better public outcomes through great government services
  • A mindset and work approach that aligns with our core values
  • Ability to travel for work from time to time

Nice-to-have qualifications

  • Expertise in other relevant regulatory frameworks like CMMC, HIPAA, or FISMA
  • Hands-on experience administering Google Workspace
  • Professional development experience in at least one programming language
  • Professional experience working with infr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Skylight

View company profile →