AppGate is a leading cybersecurity company and pioneer in the Zero Trust Network Access (ZTNA) market focused on providing cutting-edge solutions that protect organizations from evolving threats. Our mission is to support the warfighter, the national security community, and critical infrastructure by providing trusted access that ensures mission success.
Federal Security Officer
Location
United States
Posted
1 day ago
Salary
$90K - $115K / year
Seniority
Mid Level
Job Description
Federal Security Officer
AppGate Cybersecurity, Inc.
Role Description The Federal Security Officer (FSO) is AppGate's primary point of accountability for industrial security across our programs. You will manage personnel security, facility clearance (FCL) compliance, classified information handling, and security education — ensuring AppGate meets all contractual and regulatory obligations while supporting a fast-moving software engineering and delivery organization. Key Responsibilities - Personnel Security - Own the full lifecycle of personnel security clearances — initiations, sponsorships, reinvestigations, and terminations — using DISS/NBIS. - Serve as the primary liaison with DCSA (Defense Counterintelligence and Security Agency) and other cognizant security authorities. - Conduct security briefings, debriefings, foreign travel briefings, and annual security awareness training for cleared staff. - Maintain accurate records of cleared employees, visitor certifications, and foreign national contacts. - Facility Clearance & Physical Security - Manage and maintain AppGate's Facility Clearance (FCL) in accordance with DCSA guidance and NISPOM (32 CFR Part 117). - Oversee physical security controls including access management, classified storage, open storage areas, and classified destruction procedures. - Conduct and document periodic self-inspections; develop and track corrective action plans. - Manage classified visit certifications and coordinate cleared personnel access to government and contractor facilities. - Information Security & Program Support - Ensure proper handling, transmission, storage, and disposition of classified information and Controlled Unclassified Information (CUI). - Support program managers in reviewing DD Form 254s (Contract Security Classification Specifications) for new and existing contracts. - Partner with AppGate's IT and DevSecOps teams to ensure classified and sensitive program environments meet applicable security requirements. - Interface with government Program Security Officers (PSOs) on program-specific security requirements and deliverables. - Compliance, Policy & Incident Management - Maintain compliance with NISPOM, ITAR, EAR, and relevant federal security directives across all cleared programs. - Develop and enforce security policies, procedures, and SOPs tailored to a software product company environment. - Investigate and report security incidents and violations to DCSA and appropriate authorities; drive root cause analysis and remediation. - Support CMMC assessments, government inspections, and contract-driven security audits. - Stay current on evolving federal security regulations and proactively update AppGate's security program accordingly. Qualifications - Active Secret clearance; TS or TS/SCI strongly preferred. - 5+ years of industrial security / FSO experience with a cleared defense contractor or government entity. - Deep working knowledge of NISPOM (32 CFR Part 117) and DCSA processes. - Hands-on experience with DISS, NBIS, or equivalent personnel security systems. - Experience managing an FCL and conducting DCSA self-inspections. - FSO Certification through DCSA's Center for Development of Security Excellence (CDSE) or equivalent. - Excellent communication skills — able to translate complex security requirements for non-security audiences including software engineers and executives. - Bachelor's degree in security management, information assurance, cybersecurity, or a related field — or equivalent professional experience. Preferred Qualifications - Prior FSO or security management experience at a software, SaaS, or cybersecurity company. - Familiarity with CMMC (Cybersecurity Maturity Model Certification) Level 2/3 requirements and C3PAO assessment processes. - Understanding of cloud security environments (AWS GovCloud, Azure Government) in the context of classified or CUI-handling programs. - Experience with ITAR/EAR export control compliance, including technology control plans (TCPs). - OPSEC Coordinator certification or Special Access Program (SAP) security experience. - Professional certifications: CPP (Certified Protection Professional), PSP, or SAPPC. - Familiarity with Zero Trust concepts and how they intersect with federal security program requirements — a plus given AppGate's mission. Compensation - Base salary range: 90-115k Company Description AppGate secures and protects the most valuable assets for the Department of War (DoW) and various Federal Agencies with its high performance Zero Trust Network Access (ZTNA) solution. AppGate is the only direct-routed ZTNA solution purpose-built to support DoW mission requirements by enforcing least privilege access across distributed, global, and disconnected environments. AppGate is fully operational across many DOD branches, including the Marine Corps, Navy, Air Force and Space Force.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Account Manager – Technology, Information Security
Fraga Assessoria Coaching & HeadhunterDesde 2007 conectando os melhores profissionais às melhores oportunidades
• Focus exclusively on new business: identify, prospect, and develop new sales opportunities • Manage the full B2B consultative sales cycle, from prospecting through closing • Build and maintain a robust, healthy, and predictable pipeline • Conduct consultative engagements to understand business pain points, operational risks, and customer needs • Navigate enterprise sales, engaging with stakeholders at multiple levels including C-level, IT, Information Security, Compliance, and other strategic areas • Lead complex and strategic negotiations • Partner with technical teams, pre-sales, and delivery to design customer-aligned solutions • Represent the company at events, networking activities, and demand-generation initiatives • Exceed aggressive commercial targets with a strong focus on performance and revenue expansion
Director of Information Security
CivixCivix is a leading provider of services & software for government, transportation, and grants.
• Responsible for leading Civix's enterprise information security program across corporate systems, cloud infrastructure, SaaS products, and customer-facing security initiatives. • Partner closely with Engineering, Product Management, Cloud Operations, Compliance, Customer Success, and Executive Leadership to ensure security is embedded throughout the software development lifecycle. • Own the strategic direction, governance, and operational execution of the company's security program, including compliance initiatives, security operations, product security, security awareness, and incident response. • Lead a team of security professionals while serving as the primary security advisor for customers, auditors, vendors, and executive leadership. • Develop and execute the company's enterprise information security strategy. Establish security policies, standards, procedures, and governance practices. • Build and mentor a high-performing Information Security team.
Senior Product Security Consultant
ALTASNETCibersegurança . Redes . Data Center & Cloud . Automação de processos
• Participate in architecture and design reviews across the AMI product stack — metering devices, RF/cellular modules, gateways, cloud pipelines and SaaS portals — providing security guidance from the early stages of the development lifecycle. • Perform threat modeling (STRIDE, PASTA) across the AMI architecture, identifying attack surfaces and trust boundaries from the meter to the cloud. • Support firmware security standards and coordinate security testing of metering hardware, including firmware extraction/analysis and review of supply chain components. • Work with Cloud and DevOps teams to embed security controls into Infrastructure as Code (IaC) templates and CI/CD pipelines. • Execute or coordinate SAST, DAST and SCA testing in the CI/CD pipelines of NTG’s utility management applications and consumer portals. • Assess authentication, authorization and API security in multi-tenant SaaS portals intended for utility administrators, end customers and integration partners. • Serve as the primary point of contact between Security & Compliance and Product Development, ensuring requirements are implemented in practice — not just documented — and supporting evidence collection for audits across firmware, cloud and SaaS. • Provide technical support during product security incidents and post-incident reviews, converting findings into architectural improvements or engineering backlog items.
Cloud Security Consultant
ALTASNETCibersegurança . Redes . Data Center & Cloud . Automação de processos
• Assist in designing and reviewing secure cloud architectures, landing zones, and guardrails in AWS and Azure environments. • Assess and recommend reference architectures and reusable security patterns aligned with standards and the risk posture. • Support the implementation and configuration of native cloud and third-party security controls, including IAM, CSPM, logging, and security posture management. • Assist in translating regulatory and internal security requirements into applicable technical controls within AWS and Azure environments. • Review logs, telemetry, and CSPM tool findings to identify issues that require remediation or architectural adjustments. • Assist in audit preparation by producing architectural artifacts, control evidence, and technical explanations. • Provide technical support during cloud-related security incidents, including scoping, investigation, and containment guidance.


