Information Systems Security Officer

Raft•Colorado Springs, CO
•Onsite

About The Position

This is a U.S. based position. All of the programs we support require U.S. citizenship to be eligible for employment. All work must be conducted within the continental U.S. Raft is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a leader in autonomous data fusion and Agentic AI, with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development. With headquarters in McLean, VA, our range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem. We build digital solutions that impact the lives of millions of Americans. As an Information Systems Security Officer and Manager, you will manage security and compliance activities supporting Raft's cloud-native products and customer environments. You will work closely with engineering and program teams to apply the Risk Management Framework, maintain accurate authorization documentation, assess security risk, and support IATT and ATO efforts across systems at different stages of authorization. This role requires strong working knowledge of RMF and NIST guidance and experience applying security controls in Kubernetes, containerized workloads, and other cloud-native environments.

Requirements

  • At least four years of experience in ISSO, ISSM, cybersecurity compliance, information assurance, or a closely related role.
  • Strong understanding of the Risk Management Framework and applicable NIST guidance, including NIST SP 800-37, NIST SP 800-53 Revision 5, and NIST SP 800-60.
  • Demonstrated experience applying RMF and NIST security controls in cloud-native environments, including Kubernetes and containerized workloads.
  • Experience developing and maintaining RMF artifacts such as SSPs, control implementation statements, traceability matrices, PPSM packages, POA&Ms, risk assessments, assessment plans and reports, vulnerability results, and supporting evidence.
  • Experience with continuous monitoring, vulnerability management, DISA STIG compliance, security assessments, and remediation tracking in federal or DoD environments.
  • Ability to organize and prioritize security activities, evidence, risks, and authorization milestones across multiple systems and customer environments.
  • Ability to understand technical architectures and findings, connect them to security controls and mission risk, and communicate clearly with engineers, program leaders, and security stakeholders.
  • Security+ or another qualifying DoD 8140 or contract-required certification at hire, or the ability to obtain it within six months of employment with Raft.

Nice To Haves

  • Bachelor's degree in cybersecurity, information assurance, information technology, or a related field.
  • CISSP, CISM, CISA, CGRC, or another relevant advanced cybersecurity certification.
  • Experience with eMASS or a similar governance, risk, and compliance tool.
  • Experience supporting or completing an IATT or ATO process.
  • Experience securing Kubernetes-based DevSecOps platforms or software factories, particularly within Platform One or a comparable DoD environment.
  • Experience implementing or assessing FIPS requirements.
  • Experience writing and reviewing RMF control implementation statements, security policies, and procedures.
  • Experience communicating security risk and authorization status to program or executive leadership.

Responsibilities

  • Provide ISSO oversight across Raft's product contracts, applying consistent RMF practices while accounting for each customer's system boundary and authorization requirements.
  • Develop and maintain mature RMF authorization packages, including System Security Plans, security control traceability matrices, Ports Protocols and Services Management artifacts, architecture and data-flow diagrams, POA&Ms, and bodies of evidence.
  • Translate system architectures and operational processes into accurate control implementation statements, policies, procedures, and supporting evidence aligned with applicable security control baselines.
  • Coordinate control owners, engineers, system administrators, and program stakeholders to collect evidence, address gaps, prepare for assessments, and maintain authorization readiness across supported environments.
  • Partner with engineering teams to make evidence collection and recurring compliance reporting more automated, repeatable, reusable across systems, and traceable to authoritative sources.
  • Conduct ongoing security risk assessments using findings from cloud and Kubernetes posture reviews, vulnerability and CVE analysis, DISA STIG scans, network monitoring, software-supply-chain reviews, configuration-drift detection, and endpoint protection tools.
  • Manage POA&Ms from identification through validated closure, including risk prioritization, owners, milestones, due dates, remediation evidence, and status reporting.
  • Evaluate proposed architecture, configuration, boundary, and deployment changes for security-control and authorization impact.
  • Conduct continuous monitoring, configuration reviews, control assessments, and readiness reviews; embed security requirements early and help technical teams select practical mitigations.

Benefits

  • Fully covered healthcare, dental, and vision coverage
  • 401(k) and company match
  • Take as you need PTO + 11 paid holidays
  • Education & training benefits
  • Generous Referral Bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service