Job Description
Veteran Firm Seeking a Sr. Director - Information Security for a Remote Assignment in McLean, VA
\n
\n
My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize in Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense agencies.
\n
\n
At HRUCKUS, we support fellow Veteran-Owned businesses by helping them recruit for positions across organizations such as the VA, SBA, HHS, DARPA, and other leading-edge R&D-focused defense agencies.
\n
\n
We seek to fill a Sr. Director - Information Security role in McLean, VA.
\n
\n
The ideal candidate is a McLean resident with 7+ years of cybersecurity or information security experience, strong ATO, A&A, SSP, and NIST 800-53 experience, and federal ISSO, ISSM, or Security Manager experience. Nice-to-have skills include a CISSP, CGRC, or similar certification, and experience with GRC platforms such as eMASS, CSAM, or CFACTS.
\n
\n
If you’re interested, I'll gladly provide more details about the role and further discuss your qualifications.
\n
\n
Thanks,
\n
Stephen M Hrutka
\n
Principal Consultant
\n
\n
\n
Executive Summary: HRUCKUS is looking for an experienced Sr. Director - Information Security to support a federal program and serve as the primary security and compliance point of contact, focusing heavily on Authority to Operate (ATO), System Security Plans (SSPs), continuous monitoring, and federal cybersecurity compliance.
\n
\n
Position Description: The Information Systems Security Officer (ISSO) will own security documentation, support Authority to Operate (ATO) requirements, and oversee continuous monitoring and risk management. This role involves developing and maintaining SSPs and authorization artifacts, managing POA&Ms, coordinating control owners, supporting assessments, and communicating risks and remediation needs.
\n
\n
Position Responsibilities:
\n
- \n
- Own and maintain SSPs and supporting ATO and A&A documentation
- Ensure compliance with NIST 800-53 Rev. 5, FISMA, FIPS, FAR, and other federal security requirements
- Manage POA&Ms, risk assessments, security controls, audits, and continuous monitoring activities
- Partner with system owners, security teams, control owners, and federal stakeholders
- Support vulnerability management, incident response, STIG compliance, and remote workforce security
\n
\n
\n
\n
\n
\n
\n
Required Qualifications:
\n
- \n
- 7+ years of cybersecurity / information security experience, with substantial federal security/compliance experience
- Familiarity with Executive Order 14028 and OMB M-26-14.
- Federal ISSO, ISSM, Security Manager, or similar experience
- Strong ATO, A&A, SSP, and NIST 800-53 experience
- Experience with Tenable, Qualys, STIGs, continuous monitoring, and vulnerability management
\n
\n
\n
\n
\n
\n
\n
Desired Qualifications:
\n
- \n
- Experience with GRC tools such as eMASS, CSAM, or CFACTS
- CISSP, CGRC, or similar certification
- Experience supporting large federal programs, FedRAMP and cloud security, SIEM, Title 13 data, or large remote workforces
\n
\n
\n
\n
\n
Details:
\n
Job Title: Sr. Director - Information Security
\n
Location: McLean, VA, Remote
\n
Salary Range: $150,400 - $188,000 annually
\n
