DEV Community

Cover image for AWS SAA to Security Clearance: My Path to Federal ISSO Roles
Joshua Michael Hall
Joshua Michael Hall

Posted on

AWS SAA to Security Clearance: My Path to Federal ISSO Roles

Just passed AWS Solutions Architect Associate on my first attempt. But this isn't another "I passed!" post - it's about leveraging cloud security expertise for federal defense contracting ISSO roles in Huntsville.
Why AWS SAA Matters for Federal Work
Federal contractors need professionals who understand:

Compliance frameworks (NIST 800-171, CMMC, RMF)
Security-first architecture
Cost optimization for government contracts
Multi-account strategies for classified/unclassified separation

The AWS SAA provides the foundation, but federal work demands more.
My Path: MSP → Cloud Security → Defense
I founded and scaled an MSP to $160K revenue with zero ransomware incidents across all fully managed clients. Production security isn't theoretical - it's operational excellence under pressure.
Over 3.25 years I managed 100+ endpoints, deployed 11 enterprise firewalls, and stabilized compromised environments others couldn't handle.
That experience translates directly to federal requirements:

HIPAA compliance → NIST 800-171 understanding
MSP infrastructure → Multi-tenant security
24/7 operations → Mission-critical mindset

The Federal Credential Stack I'm Building
Completed:

AWS Solutions Architect Associate (Nov 2025)
CompTIA Security+ (Nov 2025) - DoD 8570 IAT Level II
CMMC Certified Professional (Dec 2025)

Next:

CMMC Registered Practitioner (Jan 2026)
AWS Security Specialty (Q1 2026)
CISSP (Q4 2026)

Federal Cloud Resume: joshuahall.tech
Here's what makes a Federal Cloud Resume different:
Standard Cloud Resume:

  • S3 static website
  • CloudFront CDN
  • Lambda visitor counter

Federal Cloud Resume adds:

  • NIST 800-53 control mapping
  • CloudTrail logging with integrity validation
  • IAM least privilege documented
  • Encryption at rest and in transit Why ISSO Roles Information System Security Officers bridge technical implementation and compliance frameworks. With 3.25 years of hands-on security operations and zero ransomware incidents across fully managed clients, I have the operational foundation. CMMC enforcement began November 2025. The Defense Industrial Base has 350,000+ companies, roughly 70,000 needing Level 2 certification, and only about 450 currently certified. Security professionals who understand both cloud architecture and compliance frameworks are in demand. Connecting at AWS re:Invent I'll be at re:Invent (Dec 1-6) targeting defense contractors with Huntsville presence:

Torch Technologies
Leidos/Dynetics
SAIC
Northrop Grumman
Booz Allen Hamilton

If you're in defense contracting, let's connect.
The Plan

February 2026: Start ISSO role in Huntsville
Q4 2026: CISSP certification
Long-term: Build RMF/ATO expertise for CMMC consulting

While others chase FAANG, I'm focused on protecting national security infrastructure in Huntsville's defense ecosystem.

Current status: AWS SAA, Security+, CMMC CCP. 3.25 years security experience. Zero ransomware incidents across all fully managed clients. Relocating to Huntsville February 2026.
Let's connect on LinkedIn.

Top comments (0)