Seeking a highly experienced Lead Information System Security Officer (Lead ISSO) to support a Federal cybersecurity program responsible for authorization support, continuous monitoring, cybersecurity governance, audit readiness, and security compliance activities across a complex hybrid-cloud environment
The Lead ISSO serves as the primary technical and operational cybersecurity lead responsible for coordinating Risk Management Framework (RMF) activities, supporting Authorization to Operate (ATO) efforts, maintaining cybersecurity artifacts, facilitating governance activities, and providing cybersecurity decision support to Federal stakeholders
This position requires significant experience leading cybersecurity compliance, governance, risk management, and continuous monitoring activities within Federal environments
Primary Responsibilities
Lead execution of RMF activities across the system lifecycle
Support ATO, reauthorization, and ongoing authorization activities
Develop, maintain, and review System Security Plans (SSPs), POA&Ms, SARs, SAPs, and supporting authorization artifacts
Coordinate with ISSMs, System Owners, Authorizing Officials, assessors, and program stakeholders
Lead continuous monitoring and cybersecurity posture management activities
Support cybersecurity governance boards, change-control activities, and security reviews
Oversee vulnerability management reporting, remediation tracking, and POA&M governance
Develop executive-level briefings, dashboards, metrics, and cybersecurity status reports
Support audits, assessments, FISMA reviews, and compliance reporting activities
Ensure cybersecurity artifacts remain accurate, current, auditable, and traceable
Lead risk identification, issue management, corrective actions, and escalation activities
Maintain audit-ready evidence repositories and documentation
Required Qualifications
U.S. Citizenship required.
Ability to obtain and maintain a Tier 4 High-Risk Public Trust.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field.
10+ years of cybersecurity experience
5+ years supporting Federal RMF programs
Experience supporting FISMA Moderate or High environments
Experience supporting ATO and continuous authorization efforts
Experience managing POA&M programs and vulnerability remediation tracking
Experience supporting cybersecurity audits and assessment activities
Experience developing SSPs and authorization package documentation
Experience briefing senior leadership and governance boards
Desired Qualifications
One or more of the following:
CISSP
CISM
GSLC
CASP+
Security+
CGRC (formerly CAP)
Desired technical experience:
CSAM
ServiceNow
Splunk
Tenable
Qualys
Microsoft Azure
Microsoft 365
Entra ID
Zero Trust initiatives
Exempt hourly position. 11 paid holidays, minimum of 3 weeks PTO, company sponsored group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is dependent upon the candidate’s experience and qualifications.
Numbers & Facts
Location
Washington
Skills
Access Authorizationunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
CompTIA Security+unmatched
Computer Scienceunmatched
Computer Securityunmatched
Corrective Actionunmatched
Decision Supportunmatched
Documentationunmatched
FISMA - Federal Information Security Management Actunmatched