Information System Security Officer at Dragonfli Group
United States
<p>Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.</p><p><br></p><p>Dragonfli Group is seeking an experienced Information System Security Officer to support a large federal agency's Assessment and Authorization (A&A) program. In this role, you will lead security assessments across a variety of applications and domains, including cloud computing environments, and apply NIST Risk Management Framework (RMF) and ISO standards to guide risk treatment and compliance decisions. You will play a central role in validating and accrediting information technology systems, use GRC tooling to manage documentation and approvals, and serve as a subject matter expert, advising stakeholders, business units, and newer A&A team members throughout the process. This is a strong opportunity for a security professional who enjoys ownership over complex, high-visibility initiatives and wants to make a lasting impact on a mission-critical federal program.</p><p><br></p><p>Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.</p><p><br></p><p><br></p><p>Responsibilities:</p><p><br></p><ul><li>Manage security assessments across a range of applications, systems, and domains, including cloud computing environments, for projects and initiatives of significant size and complexity</li><li>Implement security controls, conduct risk assessments, and document compliance measures in alignment with NIST RMF and ISO standards</li><li>Evaluate and support documentation, validation, and accreditation processes to ensure new and existing IT systems meet information assurance (IA) and security requirements</li><li>Ensure appropriate treatment of risk, compliance, and assurance from both internal and external perspectives</li><li>Support development of security blueprints, principles, models, designs, and standards that keep enterprise IT architecture consistent, usable, secure, and aligned with business needs</li><li>Use network and vulnerability scanning tools and technologies to assess system configuration and status</li><li>Apply security architecture principles and best practices to design, implement, and maintain secure IT infrastructure in alignment with A&A policies</li><li>Use Governance, Risk, and Compliance (GRC) tools to manage Assessment and Authorization (A&A) processes</li><li>Serve as a subject matter expert (SME) for the A&A process, providing guidance to stakeholders, business units, and new A&A resources</li><li>Build and maintain schedules and step-by-step action plans to keep initiatives on track</li><li>Communicate and collaborate with cross-functional teams, business units, stakeholders, and IT professionals, including briefing executives</li></ul> <br><h3>Requirements</h3> <p><strong>Must-Have:</strong></p><ul><li>Bachelor's degree in a related field (information security, computer science, information technology, or similar), or four additional years of relevant experience in lieu of a degree</li><li>Demonstrated experience managing security assessments across multiple applications, systems, or domains, including cloud computing environments</li><li>Hands-on experience implementing security controls, performing risk assessments, and documenting compliance measures aligned to NIST RMF and ISO standards</li><li>Experience supporting Assessment and Authorization (A&A) or Certification and Accreditation (C&A) documentation, validation, and accreditation activities</li><li>Experience using Governance, Risk, and Compliance (GRC) tools to manage A&A processes</li><li>Experience with network and vulnerability scanning tools and technologies</li><li>Strong understanding of security architecture principles and secure infrastructure design</li><li>U.S. Citizenship or Permanent Residency</li><li>Ability to obtain and maintain a Public Trust security clearance, including successful completion of a background investigation</li><li>Ability to perform all work within the continental United States</li></ul><p><br></p><p><strong>Preferred / Nice-to-Have:</strong></p><ul><li>Previous experience supporting a federal agency contract, ideally on a large, multi-year program</li><li>Relevant industry certification such as CISSP, CAP, CISM, or Security+</li><li>Experience mentoring or onboarding junior A&A staff</li><li>Experience briefing senior stakeholders or executives on risk and compliance posture</li><li>Familiarity with named GRC platforms such as eMASS, Xacta, or RSA Archer</li><li>Cloud security certification (AWS, Azure, or similar)</li></ul><p><br></p> <br><h3>Skill(s)</h3> <p><strong>Technical Skills:</strong></p><ul><li>NIST Risk Management Framework (RMF)</li><li>ISO 27001 / ISO security standards</li><li>Assessment and Authorization (A&A) / Certification and Accreditation (C&A)</li><li>GRC tools (e.g., eMASS, Xacta, RSA Archer)</li><li>Vulnerability and network scanning tools (e.g., Nessus, Tenable)</li><li>Cloud security (AWS, Azure, or similar)</li><li>Security architecture and secure system design</li><li>Risk assessment methodologies</li></ul><p><br></p><p><strong>Soft Skills:</strong></p><ul><li>Executive-level briefing and communication</li><li>Cross-functional collaboration</li><li>Mentoring and knowledge transfer</li><li>Organizational planning and schedule management</li><li>Stakeholder management</li><li>Independent judgment and problem-solving</li></ul> <br><h3>Benefits</h3> <ul><li>Medical - Multiple POS health plan options including an HSA-compatible plan </li><li>Dental - PPO coverage for preventive, basic, and major services Vision - Annual exam, frames, lenses, and contact lens allowance </li><li>401(k) - Employer match up to 5% of eligible compensation </li><li>Long-Term Disability - 100% employer-paid coverage at 50% of pre-disability earnings </li><li>Life Insurance & AD&D - 100% employer-paid coverage valued at $10,000 each </li><li>PTO - 15-25 days annually based on tenure</li><li>Paid Federal Holidays - All 11 federal holidays observed</li></ul> <br><h3>Travel</h3> null
Apply Now