Onsite Requirement: Minimum 2 days per week onsite at 1100 New York Ave NW
Employment Type: Full-time, Permanent
Clearance Requirement: Tier 4 (High-Risk Public Trust) eligibility required or higher
Position Overview
We are seeking a highly experienced Lead Senior Information Systems Security Officer (ISSO) to serve as the senior technical lead for cybersecurity and Risk Management Framework (RMF) support across a portfolio of 32 FISMA Moderate information systems.
This is a hands-on senior technical leadership position responsible for directing ISSO activities, ensuring the quality and timeliness of authorization package deliverables, managing cybersecurity risks, and serving as the primary technical interface with federal cybersecurity leadership, system owners, and other stakeholders.
The successful candidate will have extensive federal cybersecurity and RMF experience, strong expertise in authorization packages, and the ability to lead ISSO teams while remaining actively engaged in technical execution. This role is not solely an administrative management position.
Key Responsibilities
- Direct all contractor ISSO activities and ensure consistent execution across the supported portfolio.
- Serve as the primary technical interface with the federal ISSM, CISO, AO/AODR, System Owners, and Common Control Providers.
- Oversee the development, review, quality control, and submission of all authorization-package artifacts maintained natively in CSAM.
- Chair internal quality reviews of ISSO deliverables prior to Government submission.
- Manage the contractor risk and issue register; escalation risks and issues to Government leadership as appropriate.
- Represent the contractor in governance forums, including:
- Change Control Board
- Cybersecurity Steering Committee
- Privacy Working Group
- Lead the daily 15-minute cybersecurity stand-up, weekly ISSO sync, and monthly service review.
- Support quarterly executive reviews and provide cybersecurity status updates to senior stakeholders.
- Own performance against contract service levels, including:
- Monthly deliverable timeliness: ≥98%
- Coordinate with corporate program management on invoicing, staffing, and contract-level reporting.
- Maintain personal hands‑on proficiency in CSAM, Splunk, and ServiceNow.
- Ensure consistent, high-quality ISSO execution across all supported information systems.
Required Qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field. Four additional years of directly relevant experience may substitute for the degree.
- 10+ years of cybersecurity experience, including 7+ years performing ISSO or equivalent duties for federal information systems.
- 3+ years of experience leading or supervising a team of ISSOs or security analysts.
- Demonstrated ownership of at least three complete RMF authorization packages through Authorizing Official (AO) decision for FISMA Moderate systems.
- Working expertise in the following standards, frameworks, and regulations:
- NIST SP 800-53A
- NIST SP 800-137
- NIST SP 800-18
- FIPS 199
- FISMA reporting obligations
- Hands‑on experience with a federal Governance, Risk, and Compliance (GRC) platform used as the authoritative authorization system of record.
- Active CISSP or CGRC (formerly CAP) certification. Equivalent senior certification may be considered.
- Demonstrated experience briefing federal senior officials, including CISO, AO, or equivalent leadership, on risk posture and authorization decisions.
- Strong written and verbal communication skills with the ability to coordinate across technical teams, Government stakeholders, and senior leadership.
Strongly Preferred Qualifications
- Direct, hands‑on CSAM experience, including:
- Package workflow advancement
- POA&M module
- Control inheritance records
- Current, in-scope Tier 4 or higher federal background investigation.
- Experience supporting a small or micro federal agency where the ISSO team covers the full portfolio rather than a single system.
- Experience reconciling POA&M ledgers between a ticketing platform and a GRC platform.
- Splunk proficiency sufficient to verify log ingestion completeness and anchor incident timelines.
- FedRAMP inherited-control and Customer Responsibility Matrix reconciliation experience.
- Experience supporting FISMA IG audits, GAO audits, or independent security control assessments.
- Experience working directly with federal Authorizing Officials, ISSMs, CISOs, and System Owners.
- Strong understanding of federal cybersecurity governance and authorization processes.