Information Systems Security Officer (remote)

CrowdStrike CrowdStrike · Enterprise · United States · Remote

This role focuses on engineering AI automation pipelines and autonomous AI agents to optimize GRC functions, control assessments, and compliance reporting within federal cloud environments (FedRAMP, IL-5). It involves translating security requirements into automated solutions, leveraging LLMs for documentation, and operationalizing AI compliance frameworks to accelerate ATO lifecycles. The role also includes continuous monitoring, vulnerability management, and cloud security architecture within regulated environments.

What you'd actually do

  1. Utilize deep proficiency in Python, JavaScript, C, or C++ to architect and implement advanced AI automation pipelines, optimizing critical GRC functions such as control assessments, POA&M management, and compliance reporting across federal authorization frameworks.
  2. Leverage professional-level cloud architecture expertise and experience in FedRAMP and IL-5 environments to engineer secure, GRC automation tools within GovCloud and high-security boundaries.
  3. Translate complex agency security requirements into automated solutions, employing LLM assistance for the rigorous drafting and versioning of SSPs and security narratives to meet evolving FedRAMP 20x mandates.
  4. Operationalize AI compliance frameworks and correlate vulnerability intelligence with NIST SP 800-53 controls, providing real-time audit readiness metrics and accelerating the ATO lifecycle.
  5. Design and deploy autonomous AI agents capable of executing multi-step GRC workflows — including control validation, evidence gathering, risk analysis, and remediation tracking — reducing manual compliance overhead and enabling continuous, intelligent oversight of federal security environments.

Skills

Required

  • Python, JavaScript, C, or C++
  • Cloud architecture expertise (FedRAMP, IL-5)
  • GRC automation
  • LLM assistance for documentation
  • AI compliance frameworks
  • NIST SP 800-53 controls
  • Autonomous AI agents for GRC workflows
  • Continuous Monitoring (ConMon)
  • Vulnerability intelligence analysis
  • Authorization to Operate (ATO) lifecycle management
  • Third-Party Assessment Organization (3PAO) audit coordination
  • POA&M management
  • Risk-based security impact analysis
  • Cloud security architecture
  • DevSecOps practices
  • Change Control Board (CCB) and SCR process management
  • System Security Plan (SSP) maintenance
  • Incident Response
  • Business Continuity
  • Disaster Recovery
  • Audit evidence collection
  • Access management and least privilege enforcement
  • DoD 8140/8570 IAM Level II Baseline Certification

Nice to have

  • Advanced degree in a relevant technical field

What the JD emphasized

  • stringent federal security requirements
  • Authorization to Operate (ATO) status
  • entire compliance lifecycle
  • highly regulated environment
  • FedRAMP
  • IL-5 environments
  • GovCloud
  • NIST SP 800-53 controls
  • continuous monitoring
  • Authorization to Operate (ATO) lifecycle
  • Third-Party Assessment Organization (3PAO) audits
  • POA&M process
  • cloud security architecture
  • DevSecOps practices
  • Change Control Board (CCB)
  • Significant Change Request (SCR)
  • System Security Plan (SSP)
  • incident response
  • business continuity
  • disaster recovery exercises
  • audit evidence collection
  • least privilege
  • DoD 8140/8570 IAM Level II Baseline Ce

Other signals

  • AI automation pipelines
  • LLM assistance
  • AI compliance frameworks
  • autonomous AI agents
  • multi-step GRC workflows