Senior Information Systems Security Manager (ISSM)

Virtualitics, IncDistrict of Columbia, DC
Remote

About The Position

Virtualitics is a leader in AI-native readiness applications for defense, government, and critical infrastructure. Founded on Caltech research, the company is driven by a mission to solve complex, mission-critical challenges with AI. Their Readiness AI solutions provide operational certainty by identifying risks, diagnosing causes, and recommending actions with explainable AI. Virtualitics emphasizes innovation, holding 15+ U.S. patents and pioneering agent-driven readiness. The company culture is results-oriented, transparent, and compassionate towards the mission and its people. This role is for individuals motivated by impact, technical depth, and building impactful AI. The Senior Information Systems Security Manager (ISSM) role is critical for managing federal authorizations and enabling company growth. With recent IL6 ATO and upcoming IL5 authorization, the ISSM will own the end-to-end authorization process for new customers, ensuring reciprocity and reducing the need to rebuild authorization packages from scratch. This is a cloud and product authorization role, distinct from traditional SCIF ISSM positions. The role requires the ability to work quickly, automate processes, and effectively translate between compliance requirements and engineering realities. The position is remote with the possibility of travel to a SCIF when requested.

Requirements

  • Personal ownership of a DoD IL4/IL5/IL6, FedRAMP Moderate/High, or agency ATO package taken end to end.
  • Deep working knowledge of NIST 800-53, NIST 800-37 (RMF), and the DoD Cloud Computing SRG, with the ability to tailor controls.
  • Proven ability to evaluate cloud technical architectures (e.g., Terraform, CI/CD pipelines, Kubernetes deployments) and determine regulatory compliance.
  • Proficiency with AI-native workflows and agentic tools (e.g., Claude Code), with an understanding of current AI capabilities in assurance.
  • Assessor-grade writing skills for control narratives and security documentation.
  • Experience directly engaging with AOs, 3PAOs, or external assessors.
  • U.S. citizenship required.
  • IAM Level II or III certification (CISSP, CISM, or CASP+) per DoD 8140, held or obtainable within six months of hire.

Nice To Haves

  • Experience with a government hosting or authorization partner (Palantir FedStart, Second Front Game Warden, or similar) and understanding inherited controls.
  • Experience with OSCAL or other machine-readable control documentation, and GRC/evidence automation platforms (RegScale, Xacta, Drata, or eMASS).
  • CMMC scoping or assessment experience on a CUI boundary; CCP or CCA designation.
  • Experience with CNAPP and container scanning in a compliance context (Wiz, Trivy, Anchore, Tenable), including triaging findings and defending risk acceptances.
  • Familiarity with cloud-native technologies common in software startups: Okta, Zscaler, GitHub, JIRA, Slack.
  • Experience scaling Series C / Series D startups.

Responsibilities

  • Own IL5 and IL6 packages end to end as Virtualitics' named ISSM, including SSPs, control narratives, POA&Ms, significant change reviews, continuous monitoring, and annual assessments.
  • Build the playbook, artifacts, and evidence pipeline to expedite time-to-ATO for new customers, serving as the primary technical contact for sponsor AOs, 3PAOs, and customer security reviewers.
  • Manage the CUI boundary, encompassing scoping, control implementation, deficiency tracking, and assessment readiness.
  • Oversee commercial assurance processes, including FedRAMP alignment, SOC 2, and managing the customer security questionnaire and due diligence pipeline for enterprise and federal deals.
  • Automate evidence collection by writing Python, Bash, SQL, and API scripts to ensure continuous control evidence rather than manual assembly before assessments.
  • Collaborate with engineers to translate controls into acceptance criteria for system design, integrating requirements into the system rather than relying solely on procedures.

Benefits

  • Highly competitive compensation
  • Meaningful equity participation
  • Fully paid medical, dental, and vision coverage for you and your dependents
  • Unlimited PTO
  • Flexible work arrangements
  • Remote flexibility
  • Hybrid options for team members based in the Los Angeles or Washington, DC areas
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service