Information System Security Officer (ISSO) Manager

Deloitte France

Arlington (VA)

On-site

USD 138,000 - 278,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Deloitte Government & Public Services (GPS) seeks an experienced ISSO to manage security authorizations for designated systems in a DoD/Federal context. You will maintain SSPs and lead RMF-based activities, collaborating with stakeholders to implement and monitor controls.

This role requires TS/SCI eligibility and onsite work in Washington, D.C. You will coordinate vulnerability assessments, drive remediation, and report risk and compliance status to leadership.

Qualifications

  • Bachelor’s degree is required.
  • Active Top Secret (SCI Eligibility) security clearance required.
  • Must be able to work onsite, 5 Days a week, at the client site in Washington, D.C.
  • 7+ years of experience as an ISSO for DoD or Federal government information systems.
  • Experience with Security Assessment and Authorization (SA&A) and RMF.
  • Experience with vulnerability scanning using Nessus and reviewing results.
  • Experience developing and maintaining security policies and standards.
  • Experience supporting governance processes and leveraging GRC tools such as JCAM/OpenRMF.

Responsibilities

  • Serve as the ISSO for designated information systems and maintain SSPs.
  • Lead ATO activities including control implementation and continuous monitoring.
  • Coordinate vulnerability and compliance assessments and track remediation.
  • Monitor security controls and system integrity for assessments.
  • Coordinate security incident response and governance communications.

Skills

ISSO experience
NIST RMF
NIST SP 800-53
GRC tools JCAM
OpenRMF
Cloud & on-premises
Communication skills
Project leadership
Multi-tasking

Education

Bachelor’s degree

Tools

Nessus
JCAM
OpenRMF

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever‑changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Work You’ll Do
  • Serve as the ISSO for designated information systems, maintaining System Security Plans (SSPs) and authorization documentation
  • Lead ATO activities including, system categorization, security documentation development, control implementation, compliance, remediation action tracking, continuous monitoring, and security maturity activities
  • Coordinate vulnerability and compliance assessments, review findings, and track remediation activities with system owners and technical stakeholders
  • Monitor security control implementation, system integrity and prepare systems for assessments.
  • Coordinate security incident response activities, communicate risk and compliance status, and support security governance and awareness efforts
A successful candidate would possess these skills:
  • Strong technical skills and experience with IT and Operational Technology, both on‑premise and in the cloud including FedRAMP
  • Advanced experience with all steps within the NIST Risk Management Framework (RMF).
  • Extensive experience with selecting, tailoring, implementing, assessing, and monitoring NIST SP 800-53 controls
  • Advanced experience with governance, risk and compliance (GRC) solutions such as JCAM and OpenRMF
  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast‑paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others
The Team

Deloitte’s Government & Public Services (GPS) practice – our people, ideas, technology and outcomes – is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery‑focused professionals.

Qualifications

Required:

  • Bachelor’s degree
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
  • Active Top Secret (SCI Eligibility) security clearance required
  • Must be able to work onsite, 5 Days a week, at the client site in Washington, D.C.
  • 7+ Years of Experience with the following:
    • Serving as an Information System Security Officer (ISSO) supporting U.S. Department of Defense (DoD) or Federal Government information systems
    • Performing security and compliance activities, including Security Assessment and Authorization (SA&A) activities and application of the NIST RMF
    • Using Nessus to perform vulnerability and compliance scanning and review vulnerability results
    • Developing, implementing and maintaining security policies, procedures, and standards
    • Experience supporting security governance processes and leveraging GRC solutions such as JCAM and OpenRMF
  • One of the following certifications:
    • Certified Information Systems Security Professional (CISSP) certification
    • Certified in Risk and Information Systems Control (CRISC) certification
Preferred:
  • Experience supporting operational mission systems
  • Experience preparing risk reports and security dashboards

For individuals assigned and/or hired to work in Virginia, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to Virginia and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $137,500 to $278,300.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Engineer (ISSE) Manager
Information System Security Engineer (ISSE) Manager

Deloitte France • Arlington (VA)

On-site
USD 138,000 - 278,000
Analyst/ ISSO Senior Consultant
Analyst/ ISSO Senior Consultant

Deloitte France • Washington

On-site
USD 108,000 - 180,000
Information Systems Security Officer
Information Systems Security Officer

Leidos • Laurel (MD)

On-site
USD 131,000 - 237,000
Competitive benefits
On-site environment
Paid holidays
ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering • Maryland

On-site
USD 110,000 - 145,000
11 paid holidays
3 weeks PTO
Group medical plan
ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering, Inc. • Maryland

On-site
USD 110,000 - 145,000
11 paid holidays
3 weeks PTO
Group medical plan
+4
Information System Security Officer
Information System Security Officer

Jacobs • Chantilly (VA)

On-site
USD 110,000 - 180,000
Training and certification support
401(k) plan with company stock purchase option
Competitive salary and benefits package
Information Systems Security Officer
Information Systems Security Officer

Leidos Inc • Laurel (MD)

On-site
USD 131,000 - 237,000
Paid Time Off
11 paid holidays
401(k) with 6% company match
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

TDI (Tetrad Digital Integrity) • Washington

Hybrid
USD 110,000 - 135,000
Hybrid work arrangement
Senior Information System Security Officer
Senior Information System Security Officer

Leidos • United States

On-site
USD 131,300 - 237,350