Senior Information System Security Officer (ISSO)

C3EL
  • Washington
    Today

    Job Description

    **CONTINGENT UPON CONTRACT AWARD**

    Overview:

    Job Title: Senior Information System Security Officer (ISSO)

    Security Clearance: Ability to Obtain Tier 4 High-Risk Public Trust

    Location: Washington, D.C.

    (Due to the nature of the work and contract requirements, U.S. Citizenship is required.)

     

    Description:

    C3EL is seeking a Senior Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract. This role will serve as Operational Specialist for Splunk, ServiceNow, ConMon, vulnerability management, POA&M, and incident and change coordination, as well as being workstream lead and secondary backup for Lead ISSO duties. 

    Responsibilities will include, but not be limited to:

    • Provide on-site cybersecurity and RMF sustainment support.
    • Maintain traceability between ServiceNow remediation tickets and CSAM POA&M records.
    • Analyze findings, validate false positives, and prioritize remediation using CVSS, CISA KEV, exposure, exploitability, and mission impact.
    • Support notification, triage, CSAM context retrieval, Splunk verification, SitReps, RCA, corrective actions, and post-incident updates.
    • Support CAB/CCB/ERB reviews, security impact analysis, artifact updates, and post-change verification.
    • Track audit, penetration-test, and assessment findings through corrective action and evidence-supported closure.
    • Maintain incident-response plans and support tabletop or functional exercises.
    • Produce accurate, concise, and audit-ready Government cybersecurity documentation.
    • Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.

     

     Minimum Qualifications:

    • U.S. Citizenship.
    • Eligibility to obtain a Tier 4 High-Risk Public Trust.
    • Minimum seven (7) years of cybersecurity.
    • Minimum five (5) years in federal ISSO, ConMon, vulnerability, security operations, or compliance work.
    • Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.
    • Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms.
    • Direct experience with Splunk searches, dashboards, ingestion verification, log coverage, and incident timeline support.
    • Direct experience with ServiceNow incidents, problems, changes, remediation tickets, and reporting.
    • Direct experience with Tenable Nessus, Qualys, ACAS, or comparable Government-approved scanners.
    • Experience with Defender, Intune, BigFix, or equivalent endpoint and configuration platforms.

     

    Preferred Qualifications:

    • At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.

     

    Education:

    • Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)

    Numbers & Facts

    LocationWashington

    Skills

    • Analysis Skillsunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Change Controlunmatched
    • Cloud Computingunmatched
    • CompTIA Security+unmatched
    • Computer Securityunmatched
    • Corrective Actionunmatched
    • Documentationunmatched
    • Establish Prioritiesunmatched
    • FIPS (Federal Information Processing Standards) 199unmatched
    • FISMA - Federal Information Security Management Actunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Governmentunmatched
    • IT Service Management (ITSM)unmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Nessusunmatched
    • Penetration Testingunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Clearanceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • ServiceNowunmatched
    • Splunkunmatched
    • Systems Administration/Managementunmatched
    • Traceabilityunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder