Principal ISSO (DevSecOps & Governance)

Zuven technologies Inc
  • Washington, DC
  • Quick Apply
3 days ago

Job Description

Randstad is seeking a high-caliber Principal ISSO (DevSecOps & Governance) to serve as a strategic cybersecurity leader and trusted advisor for our client in the Washington, D.C. area. In this high-visibility role, you will embed cybersecurity into large-scale Agile Release Trains (ARTs) and business portfolios, ensuring robust security-by-design and DevSecOps principles are integrated throughout the system development lifecycle. You will lead risk assessments, conduct security architecture reviews, enforce enterprise security standards aligned with NIST frameworks, and serve as the vital bridge between technology teams, product owners, and executive leadership.

Key Responsibilities
  • Agile & DevSecOps Governance: Serve as the primary cybersecurity representative within Agile Release Trains (ARTs); participate in Program Increment (PI) Planning to ensure security requirements, risks, and remediation items are embedded directly into team backlogs.
  • Security Architecture & Design Reviews: Conduct comprehensive threat modeling, risk assessments, and design reviews across cloud, application, network, and emerging tech environments to identify gaps and recommend compensating controls.
  • Risk Management & Compliance: Develop, maintain, and enforce enterprise security baselines and policies aligned with NIST RMF, NIST CSF, CIS Controls, and regulatory obligations; evaluate exception requests and facilitate executive risk-acceptance decisions.
  • Vulnerability & Incident Management: Review vulnerability scan and penetration test results, prioritize remediation with development/infrastructure teams, track corrective actions, and provide expert guidance during incident response and containment efforts.
  • Stakeholder & Audit Collaboration: Partner closely with Solution Architects, Product Managers, RTEs, and executive leaders to communicate security postures; author and maintain key governance artifacts (SSPs, SDDs, risk assessments) to support internal, external, and federal audits.
Required Qualifications
  • Experience: 10+ years of progressive cybersecurity experience across security architecture, risk management, engineering, and compliance in large-scale enterprise environments.
  • Framework Mastery: Deep, hands-on knowledge of cybersecurity governance frameworks, specifically NIST RMF, NIST CSF, CIS Controls, and UCF.
  • Agile & Technical Integration: Proven track record supporting Agile delivery methodologies (ARTs, PI Planning) and integrating security toolchains into modern DevSecOps pipelines.
  • Certification: Active CISSP certification is required.
  • Technical Tooling: Experience evaluating vulnerabilities and threat data using enterprise security tools (e.g., Nessus, Checkmarx, Qualys, Tenable, Burp Suite, or Nmap).
  • Communication: Exceptional written and verbal communication skills with a proven ability to translate complex security risks into actionable guidance for both technical engineering teams and C-suite stakeholders.
Preferred Qualifications
  • Additional industry-standard security certifications (e.g., CISM, CRISC, CISA, CASP+, or Security+).
  • Experience implementing automated security gates within Enterprise DevSecOps toolchains.
  • Prior experience supporting large-scale enterprise or public sector/federal programs in the D.C. metro area.

Required Skills :

Basic Qualification :

Additional Skills :

Background Check : No

Drug Screen : No

Numbers & Facts

LocationWashington, DC

Skills

  • Agile Programming Methodologiesunmatched
  • Background Investigationunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Applicationsunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Corrective Actionunmatched
  • D Programming Languageunmatched
  • Embedded Systemsunmatched
  • Emerging Technologyunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • External Auditunmatched
  • Governmentunmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Machine Toolunmatched
  • NMapunmatched
  • Nessusunmatched
  • Penetration Testingunmatched
  • Presentation/Verbal Skillsunmatched
  • Regulationsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Designunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • System Integration (SI)unmatched
  • Threat Modelingunmatched
  • Threat and risk analysis (TRA)unmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vulnerability Scannersunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder