Job Summary (List Format) Principal ISSO (DevSecOps & Governance)
- Serve as the strategic cybersecurity leader and advisor for large-scale Agile Release Trains (ARTs) and business portfolios. - Integrate robust security-by-design and DevSecOps principles throughout the system development lifecycle. - Lead comprehensive risk assessments and security architecture/design reviews across cloud, application, and network environments. - Enforce enterprise security standards and policies aligned with NIST RMF, NIST CSF, CIS Controls, and regulatory requirements. - Act as the primary cybersecurity representative during Agile Program Increment (PI) Planning, embedding security requirements into backlogs. - Review and prioritize vulnerability scan and penetration test results; guide teams on remediation and incident response efforts. - Collaborate with solution architects, product managers, release train engineers (RTEs), and executive leadership to communicate security posture. - Author and maintain key governance documentation (e.g., SSPs, SDDs, risk assessments) to support audits and compliance activities. - Evaluate security exception requests and facilitate executive-level risk acceptance decisions. - Utilize enterprise security tools (e.g., Nessus, Qualys, Checkmarx) for threat/vulnerability management. - Translate complex security risks into actionable guidance for both technical and non-technical stakeholders. - Required: 10+ years of progressive cybersecurity experience, active CISSP certification, and proven experience supporting Agile delivery and DevSecOps integration. - Preferred: Additional security certifications; experience with automated security gates and supporting public sector/federal programs.
Numbers & Facts
Location
Washington, DC
Skills
Agile Programming Methodologiesunmatched
Architectural Designunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Applicationsunmatched
Computer Securityunmatched
Documentationunmatched
Enterprise Protectionunmatched
Establish Prioritiesunmatched
Governmentunmatched
Incident Responseunmatched
Internet Securityunmatched
Leadershipunmatched
Nessusunmatched
Penetration Testingunmatched
Regulatory Requirementsunmatched
Riskunmatched
Risk Analysisunmatched
Security Analysisunmatched
Security Architectureunmatched
Security Designunmatched
Software Development Lifecycle (SDLC)unmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Vulnerability Scannersunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.