Olympus supports the Department of the Treasury's Common Services Center in modernizing enterprise identity and access management: migrating from legacy SailPoint IdentityIQ to SailPoint Identity Security Cloud, standing up RadiantOne identity data management, and consolidating federation and privileged access services across Treasury bureaus. The environment spans 125,000+ identities, 1 million+ accounts, and 35,000+ roles. You would own the security and compliance posture of that platform. Not as a paperwork function, but as the person who keeps the ATO current, keeps POA&Ms from aging out, and makes sure the SaaS shared responsibility boundary is documented well enough that nobody argues about it during an audit. What you will do: Serve as ISSO for the Treasury IAM platform: maintain the System Security Plan, security control implementation statements, and supporting RMF artifacts. Obtain and maintain Authority to Operate at a TSSEC Moderate baseline with applicable overlays (privacy, PII), including additional controls identified through risk assessment. Manage POA&M creation, remediation tracking, and closure using ServiceNow GRC. Document FedRAMP inheritance, control mapping, and shared responsibility matrices for SaaS components (SailPoint ISC) in coordination with the vendor and the Treasury ISSO. Coordinate incident response and vulnerability management with Treasury Cybersecurity, TSSEC, and the SOC, including vendor and SaaS disclosure handling, patch and update monitoring, and stakeholder communications within federal notification timeframes. Review and update program cybersecurity documentation on a quarterly cycle. Advise the architecture and engineering teams on IAM security design: Zero Trust alignment per OMB M-22-09 and NIST 800-207, identity assurance per NIST 800-63, and federation controls across PingFederate, Entra ID, and SailPoint. Support continuous monitoring, audit response, and control assessments across the bureaus onboarding to the shared service. Required qualifications Bachelor's degree and 5+ years in information system security and risk management. Working expertise with NIST Risk Management Framework, FedRAMP, and Treasury TSSEC compliance requirements. Hands-on experience using ServiceNow GRC for control management and POA&M tracking. A current, relevant cybersecurity certification (CISSP, CISM, CAP/CGRC, Security+ CE, or equivalent). Working knowledge of IAM system security, Zero Trust architecture, and federation controls across PingFederate, Entra ID, and SailPoint. U.S. citizenship, and ability to pass IRS/Treasury suitability screening and hold a Moderate MBI. Nice to have Prior ISSO experience on a Treasury or IRS system. Experience carrying a system through an initial ATO on a FedRAMP-authorized SaaS platform. Familiarity with SailPoint IdentityIQ or Identity Security Cloud, RadiantOne, and CyberArk from a controls and audit perspective. Experience supporting access certification campaigns or audit evidence collection (FISMA, A-123, GAO).
Product Compliance Lead (Global Apparel)
Polaris
Director - Independent Compliance Testing; Operations Lead
American Express
Analytics Lead, Strategic Insights (Compliance)
Affirm
Operations & Compliance Audit Leader
OpenAI
Lead Security & Compliance Analyst
Parachute Health
Security Compliance Lead
TSTC