Senior Information Systems Security Manager (ISSM)
Virtualitics, IncAbout Virtualitics
Virtualitics is the category leader in AI-native readiness applications for defense, government, and critical infrastructure. Founded on a decade of Caltech research in partnership with NASA/JPL, we are led by scientists, strategists, and servicemembers united by a single mission: to solve the world’s most complex, mission-critical challenges with AI.
Our Readiness AI solutions deliver operational certainty — giving leaders and operators a clear picture of what’s ready, what’s at risk, and what to do next. By identifying risks early, diagnosing root causes, and recommending prioritized actions with transparent, explainable AI, we help organizations move from data complexity to decision advantage.
Behind that impact is relentless innovation. Inventors at heart, we hold 15+ U.S. patents and are leading the shift toward agent-driven readiness. But what truly sets us apart is our culture — relentless about results, grounded in transparency, and driven by compassion for the mission and the people it serves.
If you’re motivated by impact, inspired by technical depth, and ready to build AI that performs where it matters most — you’ll find your mission here.
What you will be doing:
● Authorization Ownership: Own our IL5 and IL6 packages end to end as Virtualitics' named ISSM — SSPs, control narratives, POA&Ms, significant change reviews, continuous monitoring, and annual assessments.
● Reciprocity at Scale: Build the playbook, artifacts, and evidence pipeline that cut time-to-ATO for every new customer, and act as the front-line technical contact for sponsor AOs, 3PAOs, and customer security reviewers.
● CMMC and CUI: Own our CUI boundary from scoping and control implementation through deficiency tracking and assessment readiness.
● Commercial Assurance: Run FedRAMP alignment, SOC 2, and the customer security questionnaire and due diligence pipeline that shows up in every enterprise and federal deal.
● Evidence Automation: Replace manual evidence collection with automation, writing the Python, Bash, SQL, and API glue that keeps control evidence continuous rather than assembled the week before an assessment.
● Engineering Interface: Partner with engineers to turn controls into acceptance criteria they can build against, designing requirements into the system rather than papering over gaps with procedure.
What we are Looking for:
● Personal ownership of a DoD IL4/IL5/IL6, FedRAMP Moderate/High, or agency ATO package taken end to end — not supported from the side.
● Deep working knowledge of NIST 800-53, NIST 800-37 (RMF), and the DoD Cloud Computing SRG, with the judgment to tailor controls rather than apply them literally. ● Proven ability to evaluate cloud technical architectures and determine whether they
satisfy regulatory objectives: you can read Terraform, follow a CI/CD pipeline end to end, understand a Kubernetes deployment, and challenge an engineer's design on its technical merits.
● Proficiency with AI-native workflows and agentic tools (e.g., Claude Code), with grounded views on which assurance workflows AI can run reliably today and which still need a human in the loop.
● Assessor-grade writing — control narratives and security documentation a reviewer can act on without a follow-up call.
● Experience facing AOs, 3PAOs, or external assessors directly, with the credibility to hold the room.
● U.S. citizenship required. Active Secret clearance preferred; we will sponsor the right candidate.
● IAM Level II or III certification (CISSP, CISM, or CASP+) per DoD 8140, held or obtainable within six months of hire.
What are our Preferred requirements:
● Experience with a government hosting or authorization partner (Palantir FedStart, Second Front Game Warden, or similar) and how inherited controls change your package. ● OSCAL or other machine-readable control documentation, and GRC / evidence automation platforms such as RegScale, Xacta, Drata, or eMASS.
● CMMC scoping or assessment experience on a CUI boundary; CCP or CCA designation is a great addition.
● CNAPP and container scanning in a compliance context (Wiz, Trivy, Anchore, Tenable), including triaging findings and defending risk acceptances.
● Familiarity with the cloud native technologies common in software startups: Okta, Zscaler, GitHub, JIRA, Slack.
● Experience scaling Series C / Series D startups.
What are some Valued skills:
● High-agency
● AI fluent
● Diplomatic
What we offer you
At Virtualitics, you’ll join a high-performance team of scientists, strategists, and servicemembers building AI that operates in the world’s most demanding environments. The problems we solve matter — and so does the opportunity to grow while solving them.
You’ll have meaningful ownership from day one, with the ability to accelerate your career alongside a company scaling rapidly in national security and critical infrastructure.
We offer highly competitive compensation, meaningful equity participation, and fully paid medical, dental, and vision coverage for you and your dependents. Our benefits also include unlimited PTO and flexible work arrangements, with remote flexibility and hybrid options for team members based in the Los Angeles or Washington, DC areas.