Olympus supports the Department of the Treasury's Common Services Center in modernizing enterprise identity and access management: migrating from legacy SailPoint IdentityIQ to SailPoint Identity Security Cloud, standing up RadiantOne identity data management, and consolidating federation and privileged access services across Treasury bureaus. The environment spans 125,000+ identities, 1 million+ accounts, and 35,000+ roles.

You would own the security and compliance posture of that platform. Not as a paperwork function, but as the person who keeps the ATO current, keeps POA&Ms from aging out, and makes sure the SaaS shared responsibility boundary is documented well enough that nobody argues about it during an audit.

What you will do:

  • Serve as ISSO for the Treasury IAM platform: maintain the System Security Plan, security control implementation statements, and supporting RMF artifacts.
  • Obtain and maintain Authority to Operate at a TSSEC Moderate baseline with applicable overlays (privacy, PII), including additional controls identified through risk assessment.
  • Manage POA&M creation, remediation tracking, and closure using ServiceNow GRC.
    Document FedRAMP inheritance, control mapping, and shared responsibility matrices for SaaS components (SailPoint ISC) in coordination with the vendor and the Treasury ISSO.
  • Coordinate incident response and vulnerability management with Treasury Cybersecurity, TSSEC, and the SOC, including vendor and SaaS disclosure handling, patch and update monitoring, and stakeholder communications within federal notification timeframes.
  • Review and update program cybersecurity documentation on a quarterly cycle.
  • Advise the architecture and engineering teams on IAM security design: Zero Trust alignment per OMB M-22-09 and NIST 800-207, identity assurance per NIST 800-63, and federation controls across PingFederate, Entra ID, and SailPoint.
  • Support continuous monitoring, audit response, and control assessments across the bureaus onboarding to the shared service.

Required qualifications

  • Bachelor's degree and 5+ years in information system security and risk management.
  • Working expertise with NIST Risk Management Framework, FedRAMP, and Treasury TSSEC compliance requirements.
  • Hands-on experience using ServiceNow GRC for control management and POA&M tracking.
  • A current, relevant cybersecurity certification (CISSP, CISM, CAP/CGRC, Security+ CE, or equivalent).
  • Working knowledge of IAM system security, Zero Trust architecture, and federation controls across PingFederate, Entra ID, and SailPoint.
  • U.S. citizenship, and ability to pass IRS/Treasury suitability screening and hold a Moderate MBI.

Nice to have

  • Prior ISSO experience on a Treasury or IRS system.
  • Experience carrying a system through an initial ATO on a FedRAMP-authorized SaaS platform.
  • Familiarity with SailPoint IdentityIQ or Identity Security Cloud, RadiantOne, and CyberArk from a controls and audit perspective.
  • Experience supporting access certification campaigns or audit evidence collection (FISMA, A-123, GAO).