Cybersecurity - Lead ISSO

Securepro Inc

Arlington (VA)

On-site

USD 120,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401(k)
401(k) matching
Dental insurance
Health insurance

Job summary

SecurePro is seeking experienced Lead and Senior Information System Security Officers to support a federal cybersecurity program in Washington, DC. The role covers RMF, POA&M, continuous monitoring, vulnerability management, and audit support across ~32 FISMA Moderate systems.

Roles include Lead ISSO responsibilities such as directing workstreams, ensuring deliverable quality, and briefing Authorizing Officials. On-site five days a week; U.S.

Qualifications

  • U.S. citizenship required and ability to obtain Tier 4 High Risk Public Trust.
  • Hands-on experience with CSAM supporting federal authorization and RMF activities.
  • Experience executing NIST SP 800-37 Rev. 2 RMF for FISMA Moderate systems.
  • Hands-on ownership of the POA&M lifecycle through validated closure.
  • Proven ability to work on-site in Washington, DC, five days per week.

Responsibilities

  • Execute the RMF lifecycle for FISMA Moderate systems.
  • Develop and quality-control authorization packages (SSPs, SARs, RARs, POA&Ms).
  • Manage POA&Ms from identification to closure.
  • Perform continuous monitoring and vulnerability analysis.
  • Verify security logging and audit coverage using Splunk.
  • Maintain CSAM data as the authoritative GRC platform.
  • Coordinate with ISSMs, CISOs, AO, and System Owners.
  • Lead responses to audits, IG reviews, and independent assessments.

Skills

NIST RMF
CSAM
Splunk
ServiceNow
POA&M lifecycle
FISMA Moderate
Audit coordination
Security documentation
Incidence coordination
RMF lifecycle

Tools

CSAM
Splunk
ServiceNow

Job description

Benefits:
  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
Position Overview

SecurePro is seeking experienced Lead and Senior Information System Security Officers (ISSOs) to support a federal cybersecurity program in Washington, DC. The team will provide ISSO support across a portfolio of approximately 32 FISMA Moderate information systems, including Risk Management Framework (RMF) and authorization activities, continuous monitoring, vulnerability management, POA&M execution, security documentation, security impact analysis, incident coordination, and audit support.

This is a hands-on, on-site position supporting a federal environment. Candidates will be considered for either the Lead ISSO or Senior ISSO role based on experience and qualifications.

Key Responsibilities
  • Execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA Moderate systems.
  • Develop, maintain, review, and quality-control authorization packages including SSPs, SARs, RARs, POA&Ms, security controls, and assessment evidence.
  • Manage POA&Ms from finding identification through validated closure.
  • Perform continuous monitoring and vulnerability analysis.
  • Verify security logging and audit coverage using Splunk.
  • Maintain authorization and compliance information in CSAM as the authoritative GRC platform.
  • Maintain ticket-to-POA&M traceability using ServiceNow.
  • Perform Security Impact Analyses for system and infrastructure changes.
  • Coordinate cybersecurity incident response activities and corrective actions.
  • Support FISMA audits, Inspector General reviews, independent assessments, and evidence requests.
  • Review inherited and common controls for AWS and Azure environments.
  • Participate in Change Advisory Boards, Change Control Boards, Enterprise Review Boards, and cybersecurity governance forums.
  • Coordinate with federal ISSMs, CISOs, Authorizing Officials, System Owners, and other cybersecurity stakeholders.
Lead ISSO Responsibilities

The Lead ISSO will serve as the primary technical lead for the engagement and will:

  • Direct Senior ISSO workstreams and authorization schedules.
  • Perform quality reviews before cybersecurity deliverables are submitted to the Government.
  • Own cybersecurity risk and issue tracking and escalation.
  • Prepare Authorizing Official decision briefings.
  • Lead responses to audits, IG reviews, and independent assessments.
  • Provide technical direction to other ISSOs while maintaining responsibility for an assigned system portfolio.
Required Qualifications — All Candidates
  • U.S. citizenship required.
  • Ability to obtain and maintain a Tier 4 High Risk Public Trust.
  • Hands-on experience with CSAM supporting federal authorization and RMF activities.
  • Experience executing NIST SP 800-37 Rev. 2 RMF for FISMA Moderate systems.
  • Hands-on ownership of the POA&M lifecycle through validated closure.
  • Working proficiency with Splunk and ServiceNow.
  • Experience developing and maintaining federal cybersecurity documentation.
  • Ability to work on-site in Washington, DC, five days per week.
  • Knowledge of NIST SP 800-53 security controls and federal cybersecurity requirements.
Lead ISSO Qualifications
  • 10+ years of federal cybersecurity experience.
  • 8+ years of federal ISSO, RMF, or Assessment & Authorization experience.
  • 5+ years providing technical direction to other ISSOs.
  • Demonstrated experience working directly with federal ISSMs, CISOs, Authorizing Officials, or AODRs.
  • Experience reviewing and approving SSPs, SARs, RARs, POA&Ms, and assessment evidence.
  • Experience leading FISMA audits, Inspector General reviews, or independent security assessments.
  • Working knowledge of CSAM System Inventory, A&A/ATO, SSP/Security Controls, Assessments, Common Control/Inheritance, POA&M, and Continuous Monitoring modules.
  • At least one active certification: CISM, CISSP, or CISA.
Senior ISSO Qualifications
  • 6–8+ years of federal cybersecurity experience, depending on position level.
  • 4–5+ years of ISSO, RMF, or federal authorization experience.
  • Experience with continuous monitoring, vulnerability management, security documentation, incident coordination, or Security Impact Analysis.
  • Experience with vulnerability platforms such as Tenable Nessus, Qualys, or ACAS.
  • Experience validating Splunk log-source coverage, retention, and audit-trail completeness.
  • Experience authoring SSPs, control implementation statements, system boundary/data-flow documentation, and control inheritance records.
  • At least one active certification such as CISM, CISSP, CISA, or CASP+.
  • Candidates considered for the Alternate Lead role must have experience assuming lead responsibilities, including briefings, prioritization, and artifact approval.
Preferred Qualifications
  • Active federal Public Trust or security clearance.
  • CISA certification.
  • AWS or Azure cloud certification.
  • AWS GovCloud or Azure Government experience.
  • FedRAMP shared-responsibility and control-inheritance experience.
  • NIST SP 800-53 Rev. 4 to Rev. 5 transition experience.
  • Microsoft Defender, Intune, BigFix, Palo Alto, Zscaler, Okta, or Entra ID experience.
  • CyberScope and federal FISMA reporting experience.
  • NIST SP 800-128 Security Impact Analysis experience.
  • Container, Kubernetes, or DevSecOps exposure.
  • Experience supporting federal audit, penetration testing, or Inspector General activities.
Work Environment

The engagement supports a hybrid federal technology environment that may include Azure Government, Microsoft 365 GCC/GCC High, Entra ID, Okta, Palo Alto, Zscaler, Tenable or Qualys, Microsoft Defender, Intune, BigFix, Splunk, ServiceNow, and CSAM.

This position is on-site in Washington, DC and is not remote or hybrid.

SecurePro is an equal opportunity employer. Employment for these positions is contingent upon contract award and successful completion of applicable federal suitability and onboarding requirements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Team Lead Information System Security Officer (Lead ISSO)
Team Lead Information System Security Officer (Lead ISSO)

PD Inc • Washington

On-site
USD 115,000 - 193,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

PD Inc • Washington

On-site
USD 120,000 - 170,000
Lead Senior Information Systems Security Officer (ISSO)
Lead Senior Information Systems Security Officer (ISSO)

Dynamic Solutions Technology LLC • Washington

On-site
USD 140,000 - 180,000
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering • Washington

On-site
USD 150,000 - 190,000
11 paid holidays
3 weeks PTO
Company-sponsored health plan
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

8 Consulting LLC • Washington

Hybrid
USD 110,000 - 170,000
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 150,000 - 210,000
11 paid holidays
3 weeks PTO (min)
Medical plan
+4
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

On-site
USD 140,000 - 220,000
Paid holidays
PTO
Group medical plan
+4
Lead Information System Security Officer (ISSO)
Lead Information System Security Officer (ISSO)

Ortman Consulting LLC • Washington

On-site
USD 140,000 - 190,000
Entry Level- Information System Security Officer (ISSO) -
Entry Level- Information System Security Officer (ISSO) -

PD Inc • United States

On-site
USD 63,000 - 120,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 110,000 - 140,000