Principal ISSO (DevSecOps & Governance)
Contract Corp To Corp
Contract Independent
Contract W2
11 Months
No Travel Required
On-site
$59/hr


HyrUS Inc.
Fitment
Dice Job Match Score™
📊 Calculating match score...
Job Details
Skills
- security architecture
- risk management
- NIST RMF
- NIST CSF
- CIS Controls
- UCF
- DevSecOps
Summary
Key Responsibilities
- Agile & DevSecOps Governance: Serve as the primary cybersecurity representative within Agile Release Trains (ARTs); participate in Program Increment (PI) Planning to ensure security requirements, risks, and remediation items are embedded directly into team backlogs.
- Security Architecture & Design Reviews: Conduct comprehensive threat modeling, risk assessments, and design reviews across cloud, application, network, and emerging tech environments to identify gaps and recommend compensating controls.
- Risk Management & Compliance: Develop, maintain, and enforce enterprise security baselines and policies aligned with NIST RMF, NIST CSF, CIS Controls, and regulatory obligations; evaluate exception requests and facilitate executive risk-acceptance decisions.
- Vulnerability & Incident Management: Review vulnerability scan and penetration test results, prioritize remediation with development/infrastructure teams, track corrective actions, and provide expert guidance during incident response and containment efforts.
- Stakeholder & Audit Collaboration: Partner closely with Solution Architects, Product Managers, RTEs, and executive leaders to communicate security postures; author and maintain key governance artifacts (SSPs, SDDs, risk assessments) to support internal, external, and federal audits.
Required Qualifications
- Experience: 10+ years of progressive cybersecurity experience across security architecture, risk management, engineering, and compliance in large-scale enterprise environments.
- Framework Mastery: Deep, hands-on knowledge of cybersecurity governance frameworks, specifically NIST RMF, NIST CSF, CIS Controls, and UCF.
- Agile & Technical Integration: Proven track record supporting Agile delivery methodologies (ARTs, PI Planning) and integrating security toolchains into modern DevSecOps pipelines.
- Certification: Active CISSP certification is required.
- Technical Tooling: Experience evaluating vulnerabilities and threat data using enterprise security tools (e.g., Nessus, Checkmarx, Qualys, Tenable, Burp Suite, or Nmap).
- Communication: Exceptional written and verbal communication skills with a proven ability to translate complex security risks into actionable guidance for both technical engineering teams and C-suite stakeholders.
Preferred Qualifications
- Additional industry-standard security certifications (e.g., CISM, CRISC, CISA, CASP+, or Security+).
- Experience implementing automated security gates within Enterprise DevSecOps toolchains.
- Prior experience supporting large-scale enterprise or public sector/federal programs in the D.C. metro area.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 91175618
- Position Id: 143535
- Posted 8 hours ago
Company Info
About HyrUS Inc.
For over a decade, HyrUS has connected exceptional talent with America's leading enterprises. We're not just a staffing agency — we're a workforce partner obsessed with getting the match right.
We Build the Teams That Build America.
Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs