SECTION I · THE BRIEF
Brief #28246Updated 14 SEP 2026WASHINGTON, DCLeverSOFTWARE COMPANIES
Employbl Company Profile

Senior Information Systems Security Manager (ISSM)

Virtualitics, LLC operates as a data visualization company. The Company merges artificial intelligence, big data, and virtual augmented reality to gain insights from big and complex data sets. Virtualitics serves…

Location
Washington, DC
Company size
100–200
Posted
2d ago
Via
Lever
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Senior Information Systems Security Manager (ISSM)

Virtualitics· District of ColumbiaView company profile


Job title
Senior Information Systems Security Manager (ISSM)
Job location
District of Columbia
Job description

About Virtualitics

Virtualitics is the category leader in AI-native readiness applications for defense, government, and critical infrastructure. Founded on a decade of Caltech research in partnership with NASA/JPL, we are led by scientists, strategists, and servicemembers united by a single mission: to solve the world’s most complex, mission-critical challenges with AI.

Our Readiness AI solutions deliver operational certainty — giving leaders and operators a clear picture of what’s ready, what’s at risk, and what to do next. By identifying risks early, diagnosing root causes, and recommending prioritized actions with transparent, explainable AI, we help organizations move from data complexity to decision advantage.

Behind that impact is relentless innovation. Inventors at heart, we hold 15+ U.S. patents and are leading the shift toward agent-driven readiness. But what truly sets us apart is our culture — relentless about results, grounded in transparency, and driven by compassion for the mission and the people it serves.

If you’re motivated by impact, inspired by technical depth, and ready to build AI that performs where it matters most — you’ll find your mission here.


Role: Senior Information Systems Security Manager (ISSM)
We just earned our IL6 ATO and our IL5 authorization is close behind. Every new customer we win needs their own Authorizing Official to issue an ATO, and that reciprocity work has become the constraint on how fast we can grow. Our team is looking for a Senior ISSM to own it — running federal authorizations end to end as our named ISSM of record, so that each new customer ATO becomes a package we pull and tailor rather than a project we rebuild from scratch. This is a cloud and product authorization role rather than a closed-area or SCIF ISSM position; our El Segundo SIPR space is provided and accredited by Nooks. Ability to work quickly, automate relentlessly, and translate between compliance language and engineering reality will be key.
This position is remote with ability to travel to a SCIF when requested by the company.
What you will be doing:

Authorization Ownership: Own our IL5 and IL6 packages end to end as Virtualitics' named ISSM — SSPs, control narratives, POA&Ms, significant change reviews, continuous monitoring, and annual assessments.

Reciprocity at Scale: Build the playbook, artifacts, and evidence pipeline that cut time-to-ATO for every new customer, and act as the front-line technical contact for sponsor AOs, 3PAOs, and customer security reviewers.

CMMC and CUI: Own our CUI boundary from scoping and control implementation through deficiency tracking and assessment readiness.

Commercial Assurance: Run FedRAMP alignment, SOC 2, and the customer security questionnaire and due diligence pipeline that shows up in every enterprise and federal deal.

Evidence Automation: Replace manual evidence collection with automation, writing the Python, Bash, SQL, and API glue that keeps control evidence continuous rather than assembled the week before an assessment.

Engineering Interface: Partner with engineers to turn controls into acceptance criteria they can build against, designing requirements into the system rather than papering over gaps with procedure.

What we are Looking for:

● Personal ownership of a DoD IL4/IL5/IL6, FedRAMP Moderate/High, or agency ATO package taken end to end — not supported from the side.

● Deep working knowledge of NIST 800-53, NIST 800-37 (RMF), and the DoD Cloud Computing SRG, with the judgment to tailor controls rather than apply them literally. ● Proven ability to evaluate cloud technical architectures and determine whether they

satisfy regulatory objectives: you can read Terraform, follow a CI/CD pipeline end to end, understand a Kubernetes deployment, and challenge an engineer's design on its technical merits.

● Proficiency with AI-native workflows and agentic tools (e.g., Claude Code), with grounded views on which assurance workflows AI can run reliably today and which still need a human in the loop.

● Assessor-grade writing — control narratives and security documentation a reviewer can act on without a follow-up call.

● Experience facing AOs, 3PAOs, or external assessors directly, with the credibility to hold the room.

● U.S. citizenship required. Active Secret clearance preferred; we will sponsor the right candidate.

● IAM Level II or III certification (CISSP, CISM, or CASP+) per DoD 8140, held or obtainable within six months of hire.

What are our Preferred requirements:

● Experience with a government hosting or authorization partner (Palantir FedStart, Second Front Game Warden, or similar) and how inherited controls change your package. ● OSCAL or other machine-readable control documentation, and GRC / evidence automation platforms such as RegScale, Xacta, Drata, or eMASS.

● CMMC scoping or assessment experience on a CUI boundary; CCP or CCA designation is a great addition.

● CNAPP and container scanning in a compliance context (Wiz, Trivy, Anchore, Tenable), including triaging findings and defending risk acceptances.

● Familiarity with the cloud native technologies common in software startups: Okta, Zscaler, GitHub, JIRA, Slack.

● Experience scaling Series C / Series D startups.

What are some Valued skills:

● High-agency

● AI fluent

● Diplomatic

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Virtualitics headquarters

Pasadena, CA

Company size

100200 employees

Founded

2015

Total raised

$103,902,378

View company profile ↗

Funding rounds