Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Sr. Principal Information Security Engineer (ISSO)

Clarity Innovations
CompanyClarity Innovations
CategoryUncategorised
LocationColumbia
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted31 Jul 2026
Last verified6 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Clarity Innovations is a trusted national security partner, dedicated to safeguarding our nation’s interests and delivering innovative solutions that empower the Intelligence Community (IC) and Department of Defense (DoD) to transform data into actionable intelligence, ensuring mission success in an evolving world. Our mission-first software and data engineering platform modernizes data operations, utilizing advanced workflows, CI/CD, and secure DevSecOps practices. We focus on challenges in Information Warfare, Cyber Operations, Operational Security, and Data Structuring, enabling end-to-end solutions that drive operational impact. We are committed to delivering cutting-edge tools and capabilities that address the most complex national security challenges, empowering our partners to stay ahead of emerging threats and ensuring the success of their critical missions. At Clarity, we are people-focused and set on being a destination employer for top talent, offering an environment where innovation thrives, careers grow, and individuals are valued. Join us as we continue to lead innovation and tackle the most pressing challenges in national security. Principal Information Security Specialist (Information System Security Officer) Position Overview The position is part of a team of software and platform engineers building a unified, multi-tenant control plane that abstracts away infrastructure differences across AWS, Azure, and on-premises environments. The platform allows application teams to provision secure, isolated Kubernetes clusters and workloads dynamically. The control plane runs Crossplane and Cluster API (CAPI). As the Principal Information Security Specialist your primary responsibility is translating traditional federal and enterprise security frameworks (e.g., DoDI 8510.01, JSIG, NIST SP 800-37) into clear, prioritized requirements for the development and engineering teams. You will act as a compliance partner to the teams, guiding them on what guardrails need to exist while they handle the implementation. Additionally, you will own the entire Authorization to Operate (ATO) package lifecycle, specializing in writing governance policies, preparing and modifying site addendums, and executing continuous risk management processes to achieve authorizations across the full Information System (IS) boundary. Lastly, you will manage continuous monitoring (ConMon) reporting and documentation obligations. The ideal candidate is highly independent, capable of navigating complex regulatory frameworks with minimal supervision, and possesses a deep engineering curiosity regarding containerization and cloud infrastructure. Key Responsibilities ATO package and authorization documentation: Own the ATO and all associated documentation, including the SSP, control statements, POA&Ms, boundary and interconnection agreements. Keep all documents accurate to the live state of the system, with authority as the final word on documentation completeness. Continuous monitoring and risk management: Own ConMon reporting, POA&M tracking, and SBOM/supply-chain representation. Coordinate with engineers on anything requiring technical changes. System boundary coordination: Draft, update, and manage the system's formal boundary mappings, site addendums, delta-SSPs, inheritance packages, and ISAs that streamline the path to authorization. Policy generation and governance: Author and review system security policies, SOPs, and Rules of Behavior. Develop a pragmatic plan for phasing manual Day-1 controls into automation over time. Compliance-to-engineering translation: Turn NIST 800-53 controls into clear backlog requirements and evidence standards, working as a compliance enabler rather than a bottleneck. Qualifications Skills & Experience RMF & NIST Mastery: 5+ years of experience guiding complex information systems through the NIST SP 800-37 Risk Management Framework (RMF), DoDI 8510.01,