Logo for Dragonfli Group

Information System Security Officer

Role overview

Qualifications

  • Bachelor's degree in a related field or four additional years of relevant experience in lieu of a degree
  • Demonstrated experience managing security assessments across multiple applications, systems, or domains
  • Hands-on experience implementing security controls, performing risk assessments, and documenting compliance measures
  • Ability to obtain and maintain a Public Trust security clearance

Responsibilities

  • Manage security assessments across a range of applications, systems, and domains, including cloud computing environments
  • Implement security controls, conduct risk assessments, and document compliance measures in alignment with NIST RMF and ISO standards
  • Evaluate and support documentation, validation, and accreditation processes to ensure IT systems meet security requirements
  • Serve as a subject matter expert (SME) for the AA process, providing guidance to stakeholders and business units

About the company

Dragonfli Group logo

Dragonfli Group

Cybersecurity

The Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting. Dragonfli transforms its clients’ businesses by leveraging high impact strategic planning and technology solutions coupled with our deep expertise in infrastructure, corporate strategy and operations. The Dragonfli Group's passionate and experienced consultants take a collaborative approach to provide strategic planning and information security solutions to organizations looking to increase profitability, streamline operations, manage risk, meet regulatory demands and build market share.

Company details

Company typeTPE
IndustryCybersecurity
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.


Dragonfli Group is seeking an experienced Information System Security Officer to support a large federal agency's Assessment and Authorization (A&A) program. In this role, you will lead security assessments across a variety of applications and domains, including cloud computing environments, and apply NIST Risk Management Framework (RMF) and ISO standards to guide risk treatment and compliance decisions. You will play a central role in validating and accrediting information technology systems, use GRC tooling to manage documentation and approvals, and serve as a subject matter expert, advising stakeholders, business units, and newer A&A team members throughout the process. This is a strong opportunity for a security professional who enjoys ownership over complex, high-visibility initiatives and wants to make a lasting impact on a mission-critical federal program.


Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.



Responsibilities:


  • Manage security assessments across a range of applications, systems, and domains, including cloud computing environments, for projects and initiatives of significant size and complexity
  • Implement security controls, conduct risk assessments, and document compliance measures in alignment with NIST RMF and ISO standards
  • Evaluate and support documentation, validation, and accreditation processes to ensure new and existing IT systems meet information assurance (IA) and security requirements
  • Ensure appropriate treatment of risk, compliance, and assurance from both internal and external perspectives
  • Support development of security blueprints, principles, models, designs, and standards that keep enterprise IT architecture consistent, usable, secure, and aligned with business needs
  • Use network and vulnerability scanning tools and technologies to assess system configuration and status
  • Apply security architecture principles and best practices to design, implement, and maintain secure IT infrastructure in alignment with A&A policies
  • Use Governance, Risk, and Compliance (GRC) tools to manage Assessment and Authorization (A&A) processes
  • Serve as a subject matter expert (SME) for the A&A process, providing guidance to stakeholders, business units, and new A&A resources
  • Build and maintain schedules and step-by-step action plans to keep initiatives on track
  • Communicate and collaborate with cross-functional teams, business units, stakeholders, and IT professionals, including briefing executives


Requirements

Must-Have:

  • Bachelor's degree in a related field (information security, computer science, information technology, or similar), or four additional years of relevant experience in lieu of a degree
  • Demonstrated experience managing security assessments across multiple applications, systems, or domains, including cloud computing environments
  • Hands-on experience implementing security controls, performing risk assessments, and documenting compliance measures aligned to NIST RMF and ISO standards
  • Experience supporting Assessment and Authorization (A&A) or Certification and Accreditation (C&A) documentation, validation, and accreditation activities
  • Experience using Governance, Risk, and Compliance (GRC) tools to manage A&A processes
  • Experience with network and vulnerability scanning tools and technologies
  • Strong understanding of security architecture principles and secure infrastructure design
  • U.S. Citizenship or Permanent Residency
  • Ability to obtain and maintain a Public Trust security clearance, including successful completion of a background investigation
  • Ability to perform all work within the continental United States


Preferred / Nice-to-Have:

  • Previous experience supporting a federal agency contract, ideally on a large, multi-year program
  • Relevant industry certification such as CISSP, CAP, CISM, or Security+
  • Experience mentoring or onboarding junior A&A staff
  • Experience briefing senior stakeholders or executives on risk and compliance posture
  • Familiarity with named GRC platforms such as eMASS, Xacta, or RSA Archer
  • Cloud security certification (AWS, Azure, or similar)



Skill(s)

Technical Skills:

  • NIST Risk Management Framework (RMF)
  • ISO 27001 / ISO security standards
  • Assessment and Authorization (A&A) / Certification and Accreditation (C&A)
  • GRC tools (e.g., eMASS, Xacta, RSA Archer)
  • Vulnerability and network scanning tools (e.g., Nessus, Tenable)
  • Cloud security (AWS, Azure, or similar)
  • Security architecture and secure system design
  • Risk assessment methodologies


Soft Skills:

  • Executive-level briefing and communication
  • Cross-functional collaboration
  • Mentoring and knowledge transfer
  • Organizational planning and schedule management
  • Stakeholder management
  • Independent judgment and problem-solving


Benefits

  • Medical - Multiple POS health plan options including an HSA-compatible plan
  • Dental - PPO coverage for preventive, basic, and major services Vision - Annual exam, frames, lenses, and contact lens allowance
  • 401(k) - Employer match up to 5% of eligible compensation
  • Long-Term Disability - 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D - 100% employer-paid coverage valued at $10,000 each
  • PTO - 15-25 days annually based on tenure
  • Paid Federal Holidays - All 11 federal holidays observed


Travel


Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Information Security Analyst Related jobs

Other jobs at Dragonfli Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.