What are the responsibilities and job description for the Cloud Information Systems Security Officer position at TDI (Tetrad Digital Integrity)?
Tetrad Digital Integrity (TDI) is a 25 year old cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect.
We are looking for an exceptional DoW Cloud ISSO to support RMF and security execution for a mission-critical cloud-hosted defense system. This is a high-visibility engagement with frequent change, heavy stakeholder involvement, and a system treated as a high-value target. This is not a template compliance role. We need a team player who is a mission-focused operator who can execute with urgency, drive progress through ambiguity, and deliver customer excellence under pressure while partnering tightly with the Cybersecurity Program Lead.
Overview:
We are hiring two Cloud ISSOs to support a high-visibility DoD program moving toward IL7. This is not a paperwork-only ISSO role — we are looking for operators who can validate controls in real environments, support continuous monitoring, and work directly with engineering teams in cloud-native systems.
If you’re someone who only writes SSPs and updates eMASS, this will not be the right fit. If you understand how controls actually work in AWS/GCP and can prove they’re effective, this is the type of environment where you’ll stand out.
What You’ll Do:
- Validate and assess security controls in cloud environments (AWS/GCP)
- Support continuous monitoring (ConMon) and ongoing ATO sustainment
- Develop and maintain audit-ready evidence tied to real system behavior
- Work directly with engineers and system owners to implement and validate controls
- Analyze vulnerabilities, validate remediation, and manage POA&Ms with real closure rigor
- Reduce manual compliance work through automation and repeatable processes
What We’re Looking For:
- Strong experience with RMF (NIST 800-53 / DoD / FedRAMP)
- Hands-on experience supporting cloud environments (AWS or GCP)
- Ability to validate controls technically, not just document them
- Experience with eMASS or similar GRC tools
- Exposure to vulnerability scanning (ACAS, Nessus, etc.)
- Ability to clearly explain how controls are implemented and evidenced
Strongly Preferred:
- Experience with cloud-native logging / monitoring (CloudTrail, SIEM, etc.)
- Exposure to containers / Kubernetes environments
- Experience reducing manual evidence collection through automation or tooling
- Prior DoD / IC environment experience
Clearance: Active DoD clearance required (Secret or higher preferred)
Why This Role:
This program is mission-critical and evolving quickly. The team is intentionally small and needs high performers who can operate independently, solve problems, and contribute immediately — not candidates who require heavy oversight.
OVERALL MATCH:
If you are looking for a template-driven RMF job, stable requirements, or work where someone else keeps the artifacts/evidence aligned to reality, this will not be a fit. If you can execute RMF with urgency, run disciplined POA&M and evidence management, keep pace with CCB-driven change, and deliver customer-ready outputs with minimal oversight, we want to meet you.