Hiring.Camp

ISSM / Security Automation Engineer

Tyto Athene

·

Yesterday

Salary
$175k – $190k
Location
Remote, US
Workplace
Remote
Type
Full-time
Department
IT
Closing date
Today
Source
iCIMS

Description

Description

Quantum Sky is searching for a highly technical Information System Security Manager (ISSM) / Security Automation Engineer to lead cybersecurity risk management and security authorization activities while designing and developing automation that enables continuous security and compliance.

 

This is a hands-on engineering role for an individual who can operate effectively across cybersecurity governance, cloud security, DevSecOps, software automation, and NIST Risk Management Framework (RMF) environments. The successful candidate will own traditional ISSM responsibilities while also developing scripts, integrations, and automated workflows that reduce manual compliance activities and provide continuous visibility into system security posture.

 

The ideal candidate has previous software development or automation engineering experience and is comfortable working directly with source code, APIs, cloud services, CI/CD pipelines, Infrastructure as Code, security tooling, and machine-readable compliance data.The objective of this position is to move security programs away from periodic, document-driven compliance toward automated, continuous security assurance and Compliance as Code.

 

Responsibilities:

  • Lead RMF, Security Authorization & Continuous Assurance — Own NIST RMF implementation, system authorization and ongoing authorization activities, including SSPs, control implementation documentation, risk assessments, continuous monitoring artifacts, and coordination with system owners, assessors, ISSOs, engineers, and Authorizing Officials.
  • Engineer Security & Compliance Automation — Design, develop, and maintain production-quality automation using Python, PowerShell, Bash, APIs, and cloud-native technologies to automate control validation, evidence collection, compliance reporting, security assessments, and remediation workflows.
  • Implement Compliance as Code & Continuous Control Monitoring — Translate NIST SP 800-53 controls and organizational requirements into measurable technical requirements, machine-readable policies, automated validation procedures, and continuous control monitoring capabilities.
  • Embed Security into Cloud & DevSecOps Workflows — Partner with engineering and platform teams to integrate security into cloud architectures, Infrastructure as Code, CI/CD pipelines, containers, Kubernetes, and software delivery processes, including automated testing, policy validation, and security gates.
  • Integrate Security Platforms, Data & Tooling — Build integrations and reusable services connecting cloud platforms, vulnerability scanners, security tools, GRC platforms, ticketing systems, source-code repositories, and CI/CD systems using APIs and structured data such as JSON and YAML.
  • Manage Vulnerabilities, Findings & Cybersecurity Risk — Automate vulnerability and configuration finding ingestion, correlation, prioritization, assignment, tracking, and reporting; manage POA&Ms, exceptions, and remediation through closure; and evaluate system architectures and changes for cybersecurity risk.
  • Deliver Continuous Security Visibility & Improvement — Develop dashboards, metrics, and automated reporting that provide actionable visibility into vulnerabilities, configuration compliance, control status, POA&Ms, and organizational risk while identifying opportunities to replace manual security reviews with automated technical validation.

Qualifications

Required:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field, or equivalent professional experience.
  • Demonstrated experience as an ISSM, ISSO, Security Engineer, Cloud Security Engineer, DevSecOps Engineer, or similar technical cybersecurity professional.
  • Strong knowledge of NIST SP 800-53, NIST SP 800-37, RMF, security authorization, security control assessment, and continuous monitoring.
  • Demonstrated hands-on experience developing production-quality automation, scripts, integrations, or software.
  • Strong programming or scripting experience with Python and experience with one or more additional languages or scripting environments such as PowerShell, Bash, JavaScript, or Go.
  • Experience working with JSON and YAML.
  • Experience automating cybersecurity, infrastructure, compliance, or operational processes.
  • Experience with vulnerability scanning and vulnerability management technologies.
  • Experience with cloud platforms such as AWS, Azure or GCP.
  • Ability to understand cloud and enterprise system architectures and evaluate their security implications.
  • Ability to translate regulatory and cybersecurity requirements into technical engineering requirements.

Desired:

  • Experience developing automation against AWS, Azure or GCP API/SDKs
  • Experience with Infrastructure as Code technologies such as Terraform.
  • Experience with configuration management and automation technologies such as Ansible.
  • Experience with CI/CD platforms such as GitHub Actions, GitLab CI/CD, Jenkins, or Azure DevOps.
  • Experience with container and orchestration technologies such as Docker and Kubernetes.
  • Experience integrating vulnerability scanners, SIEM platforms, CSPM/CNAPP solutions, GRC platforms, and ticketing systems.
  • Experience developing security dashboards and data pipelines.
  • Experience with automated testing frameworks and software engineering practices.
  • Experience with serverless architectures and event-driven automation.
  • Experience transforming NIST controls and security documentation into structured, machine-readable data.
  • Experience with Compliance as Code and Policy as Code technologies such as Open Policy Agent (OPA).
  • Experience implementing automated security evidence collection and continuous control validation.

Desired Federal Cybersecurity Experience:

  • Experience supporting FISMA, FedRAMP, DoD RMF, CMMC, or other federal cybersecurity programs.
  • Experience supporting systems through initial authorization and ongoing authorization processes.
  • Experience working with Security Control Assessors (SCAs), Third Party Assessment Organizations (3PAOs), or government Authorizing Officials.
  • Experience developing or maintaining SSPs, POA&Ms, Security Assessment Reports, continuous monitoring documentation, and supporting authorization artifacts.
  • Familiarity with federal security baselines, implementation guidance, and security assessment procedures.

Desired Certifications:

  • One or more of the following is preferred:
  • CISSP, CGRC, CISM, CCSP, Security+
  • AWS Solution Architect or Security Specialty
  • GCP Cloud Architect or Security Engineer
  • Certified Kubernetes Security Specialist (CKS)

About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $175,000-$190,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it. 

 

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky? 

 

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

 

Skills

PythonJavaScriptAWSAzureGCPDockerKubernetesTerraformAnsibleJenkinsCI/CDGitHubGitLabCybersecuritySIEMDevOpsRisk ManagementComplianceCISSP

Similar Jobs

30

Information Systems Security Manager (ISSM)

Gdms · Pittsfield, MA, US

Yesterday

Program Information Systems Security Manager (ISSM) - Tucson, AZ

RTX · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site), United States of America · Onsite

Yesterday

Information Systems Security Manager (ISSM)

KBR Careers · USA, Orange Park, 320 Corporate Way, Florida, United States of America

2 days ago

Information System Security Manager (ISSM)

Game Plan Tech · United States Remote +1 · Remote

5 days ago

Information Systems Security Manager (ISSM)

Employment Opportunities · Washington, DC (DC Metro Area), United States of America

1 week ago

Information System Security Manager (ISSM)

Leidos · 10493 Lorton VA, United States of America +1 · Remote, Onsite

1 week ago

Information System Security Manager (ISSM)

RTX · US-CA-ANAHEIM-406 ~ 160 N Riverview Dr ~ BLDG 406, Ste 150, United States of America · Onsite

1 week ago

Information Systems Security Manager ISSM

KMS Solutions · Alexandria, VA

1 week ago

Information Systems Security Manager (ISSM)

Accenturefederalservices · Tampa, FL +1 · Onsite

1 week ago

Information Systems Security Manager (ISSM)

Anavationllc · San Antonio, TX · Onsite

1 week ago

Information Systems Security Manager (ISSM) II

Gdit · USA FL Fort Walton Beach - Customer Proprietary (FLC134), United States of America +7

2 weeks ago

Information Systems Security Manager (ISSM) II

GDIT · USA FL Fort Walton Beach - Customer Proprietary (FLC134), United States of America +7

2 weeks ago

Program Information Systems Security Manager (ISSM) - Tucson, AZ

RTX · US-AZ-TUCSON-842 ~ 1151 E Hermans Rd ~ BLDG 842, United States of America · Onsite

2 weeks ago

Information Systems Security Manager (ISSM)

Gdms · Pittsfield, MA, US

2 weeks ago

Information Systems Security Manager (ISSM)

Gdms · Pittsfield, MA, US

2 weeks ago

USAF - Information Systems Security Manager (ISSM)

cFocus Software Incorporated · Ellsworth, SD · Onsite

2 weeks ago

Information Systems Security Manager (ISSM) III

GDIT · USA FL Fort Walton Beach - Customer Proprietary (FLC134), United States of America +7

3 weeks ago

Information Systems Security Manager (ISSM) I

Gdit · USA TX San Antonio - Customer Proprietary (TXC153), United States of America

3 weeks ago

Information Systems Security Manager (ISSM) III

Gdit · USA FL Fort Walton Beach - Customer Proprietary (FLC134), United States of America +7

3 weeks ago

Information Systems Security Manager (ISSM) I

GDIT · USA TX San Antonio - Customer Proprietary (TXC153), United States of America

3 weeks ago

Information System Security Manager (ISSM)

RTX · US-CT-EAST HARTFORD-RTRC A ~ 411 Silver Ln ~ RTRC A, United States of America · Onsite

1 month ago

(704) Cybersecurity Information System Security Manager (ISSM)

Arlosolutionsllc · Orlando FL · Onsite

1 month ago

Cybersecurity Lead - Information System Security Manager (ISSM)

Sphinxdefense · Chantilly, VA +1

1 month ago

Cybersecurity Lead - Information System Security Manager (ISSM)

Sphinxdefense · Colorado Springs, CO +1

1 month ago

Information Systems Security Manager (ISSM)

Gdms · Boise, ID, US

1 month ago

Information Systems Security Manager (ISSM)

Aalyria · Washington, DC · Remote, Hybrid, Onsite

1 month ago

Information Systems Security Management (ISSM) - TS/SCI w/Polygraph

GDIT · USA VA McLean - Customer Proprietary (VAC393), United States of America

1 month ago

Information Systems Security Management (ISSM) - TS/SCI w/Polygraph

Gdit · USA VA McLean - Customer Proprietary (VAC393), United States of America

1 month ago

Information Systems Security Manager (ISSM)

Toyon Research Corporation · Goleta, CA

2 months ago

Information System Security Manager (ISSM)

"ZTI Solutions, LLC" · Fort Meade, Maryland, US · Remote, Onsite

2 months ago