Hiring.Camp

Sr. Principal Information Security Engineer (ISSO)

Clarity Innovations

·

Today

Salary
$100k – $330k
Location
Columbia, MD; Herndon, VA · Columbia, Maryland, United States · Herndon, Virginia, United States
Department
Information Security
Seniority
Lead
Experience
5+ years
Source
Greenhouse

Description

Clarity Innovations is a trusted national security partner, dedicated to safeguarding our nation’s interests and delivering innovative solutions that empower the Intelligence Community (IC) and Department of Defense (DoD) to transform data into actionable intelligence, ensuring mission success in an evolving world.

Our mission-first software and data engineering platform modernizes data operations, utilizing advanced workflows, CI/CD, and secure DevSecOps practices. We focus on challenges in Information Warfare, Cyber Operations, Operational Security, and Data Structuring, enabling end-to-end solutions that drive operational impact.

We are committed to delivering cutting-edge tools and capabilities that address the most complex national security challenges, empowering our partners to stay ahead of emerging threats and ensuring the success of their critical missions. At Clarity, we are people-focused and set on being a destination employer for top talent, offering an environment where innovation thrives, careers grow, and individuals are valued. Join us as we continue to lead innovation and tackle the most pressing challenges in national security.

Principal Information Security Specialist

(Information System Security Officer)

Position Overview

The position is part of a team of software and platform engineers building a unified, multi-tenant control plane that abstracts away infrastructure differences across AWS, Azure, and on-premises environments. The platform allows application teams to provision secure, isolated Kubernetes clusters and workloads dynamically. The control plane runs Crossplane and Cluster API (CAPI).

As the Principal Information Security Specialist your primary responsibility is translating traditional federal and enterprise security frameworks (e.g., DoDI 8510.01, JSIG, NIST SP 800-37) into clear, prioritized requirements for the development and engineering teams. You will act as a compliance partner to the teams, guiding them on what guardrails need to exist while they handle the implementation. Additionally, you will own the entire Authorization to Operate (ATO) package lifecycle, specializing in writing governance policies, preparing and modifying site addendums, and executing continuous risk management processes to achieve authorizations across the full Information System (IS) boundary. Lastly, you will manage continuous monitoring (ConMon) reporting and documentation obligations.

The ideal candidate is highly independent, capable of navigating complex regulatory frameworks with minimal supervision, and possesses a deep engineering curiosity regarding containerization and cloud infrastructure.

Key Responsibilities

  • ATO package and authorization documentation: Own the ATO and all associated documentation, including the SSP, control statements, POA&Ms, boundary and interconnection agreements. Keep all documents accurate to the live state of the system, with authority as the final word on documentation completeness.
  • Continuous monitoring and risk management: Own ConMon reporting, POA&M tracking, and SBOM/supply-chain representation. Coordinate with engineers on anything requiring technical changes.
  • System boundary coordination: Draft, update, and manage the system's formal boundary mappings, site addendums, delta-SSPs, inheritance packages, and ISAs that streamline the path to authorization.
  • Policy generation and governance: Author and review system security policies, SOPs, and Rules of Behavior. Develop a pragmatic plan for phasing manual Day-1 controls into automation over time.
  • Compliance-to-engineering translation: Turn NIST 800-53 controls into clear backlog requirements and evidence standards, working as a compliance enabler rather than a bottleneck.

Qualifications

Skills & Experience

  • RMF & NIST Mastery: 5+ years of experience guiding complex information systems through the NIST SP 800-37 Risk Management Framework (RMF), DoDI 8510.01, or JSIG lifecycles to achieve government authorizations.
  • Technical Writing & Policy Formulation: Proven track record of authoring clear, concise, and unassailable security policies, SOPs, control statements, and system configuration narratives.
  • ATO Package Administration: Expert proficiency managing system packages within federal governance frameworks and data tools of record like eMASS or XACTA.
  • Cross-Functional Collaboration: Demonstrated success partnering with software developers, cloud engineers, or SREs, serving as a proactive compliance enabler rather than an operational bottleneck.
  • Conceptual Tech Literacy: A strong conceptual understanding of cloud environments (AWS/Azure) and core container concepts (Kubernetes). You do not need to build, code, or configure these tools, but you must be able to understand an architecture diagram and discuss security requirements intelligently with engineers.
  • Active industry certifications (e.g., CISSP, CISM, CCSP)

Soft Skills & Engineering Mindset

  • Agile & Pragmatic Risk Management: Experience working in sprint-based engineering environments where security documentation is treated as a living artifact; comfortable leveraging manual controls on Day 1 while driving toward automation.
  • Clear Communicator: Strong capability to translate rigid compliance terminology and policy expectations into actionable tasks for developers, and conversely, translating complex cloud-native architectures into risk-management language for traditional auditors.
  • Extreme Ownership: Takes absolute accountability for the accuracy, completeness, and on-time delivery of the compliance packages, site addendums, and system security files to government stakeholders.

Preferred Qualifications

  • Hands-on experience using automated governance tools or GitOps-driven compliance engines.
  • Prior experience working directly with Authorizing Officials (AOs) to transition highly dynamic or ephemeral cloud infrastructures to a continuous authorization state.

Salary Range: $100,000 - $330,000

We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Skills

AWSAzureKubernetesCI/CDData EngineeringAgileRisk ManagementComplianceTechnical WritingCISSP

Similar Jobs

3

Sentinel - Sr. Principal Information Assurance Engineer - 13059-1

Northrop Grumman · UTRO01, United States of America

2 months ago

Sentinel - Sr. Principal Information Assurance Engineer - 13059-1

Northrop Grumman · Roy, UT,US, US

2 months ago

Sr. Principal, IT Information System & Solution Architecture

Alcon · Bangalore - AGS, India

2 weeks ago