ISSO/ISCM Lead

K2United, LLC.

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

K2United, LLC. in Washington, DC is seeking an experienced information security professional to lead RMF and A&A activities for enterprise systems, ensuring persistent authorization and compliance across all environments.

You will coordinate with Security Engineers to track configuration data, perform security control assessments, manage POA&M lifecycles, support FISMA and FedRAMP audits, and act as the liaison for accreditation interviews and risk acceptance with the CISO.

Qualifications

  • Bachelor's degree or equivalent experience in information security fields.
  • 8+ years in federal or federally regulated information security compliance.
  • Experience with RMF and A&A lifecycle activities under NIST SP 800-37.

Responsibilities

  • Manage the RMF and A&A lifecycle activities for enterprise systems.
  • Maintain and update SSPs, CMPs, and contingency plans.
  • Support new/reauthorization and identify compliance gaps with risk-informed recommendations.
  • Perform Security Control Assessments and testing for FedRAMP SaaS offerings using NIST SP800-53A.
  • Own POA&M tracking, evidence collection, and aging risk reporting.
  • Collaborate with Security Engineers to track configuration data within the GRC system.
  • Conduct security impact analyses for deviations and coordinate risk acceptance with the CISO.
  • Serve as liaison during audits; drive artifact collection and ensure completeness.
  • Participate in accreditation interviews and provide incident response insights.
  • Facilitate weekly security meetings between client units and OCISO.
  • Review audit logs, patching status, and policy gap analyses against federal requirements.

Skills

RMF lifecycle ownership
A&A lifecycle management
NIST SP 800-37 familiarity
NIST SP 800-53 Rev.5 knowledge
FedRAMP/FISMA experience
Auditing liaison
GRC tool experience

Education

Bachelor's degree in information systems or related field

Tools

Xacta
eMASS
CSAM
RSA Archer
ServiceNow IRM

Job description

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.

Our four core values define how we show up every day:

  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.

Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.

Key Responsibilities
  • Manage the ISCM program and perform internal controls testing to sustain persistent authorization and compliance across all enterprise systems.
  • Maintain and update A&A packages — System Security Plans, Configuration Management Plans, and Contingency and Disaster Recovery Plans — conforming to NIST SP 800-18 and USAC standards.
  • Support systems undergoing new authorization, reauthorization, and ongoing authorization; identify compliance gaps and prepare risk-informed recommendations for management review.
  • Execute internal Security Control Assessments and controls testing for minor systems, interim authorizations, and FedRAMP SaaS offerings using NIST SP800-53A as a guide, as directed.
  • Own POA&M tracking, analysis, and reporting: document findings, monitor due dates and milestone dates, collect and validate closure evidence, and report on open, overdue, closed, and risk-accepted items with aging trend analysis.
  • Collaborate with Security Engineers to ensure all configuration data — failed settings, technical deviations, and accepted risk decisions — is explicitly tracked within the system authorization boundary in the GRC system of record (e.g., Xacta).
  • Perform Security Impact Analyses for requested deviations and facilitate the risk acceptance process with the USAC CISO and ISSM; ensure all approved deviations are reviewed annually for continued necessity.
  • Serve as primary technical support and point of contact for all internal and external audits and assessments; drive artifact collection including logs, system configurations, and access lists, and validate evidence for completeness, accuracy, and oversight quality.
  • Participate in accreditation interviews and audit meetings, providing technical insight into incident response and monitoring activities.
  • Act as liaison between the client business units and the OCISO; facilitate weekly security meetings and manage inquiries on system modifications, implementation initiatives, and problem resolution.
  • Conduct routine reviews of audit logs, patching status, access lists, and incident response testing; perform annual policy and procedure gap analyses against federal requirements.

Requirements

  • Bachelor's degree in information systems, cybersecurity, computer science, or a related field. Equivalent experience considered in lieu of degree.
  • Eight or more years in federal or federally regulated information security compliance, including at least three years in an ISSO, ISSM, or continuous monitoring lead capacity.
  • Demonstrated hands-on ownership of RMF and A&A lifecycle activities under NIST SP 800-37, including authorship and maintenance of SSPs, CMPs, and contingency plans.
  • Direct experience supporting FISMA audits (OIG, IG, or independent assessor) as artifact owner or primary technical liaison.
  • Working proficiency with NIST SP 800-53 Rev. 5, SP 800-53A, SP 800-137, and SP 800-18.
  • Demonstrated experience administering a GRC or authorization tool of record — Xacta, eMASS, CSAM, RSA Archer, ServiceNow IRM, or equivalent.
  • Experience managing POA&M lifecycles at enterprise scale, including risk acceptance workflows with a CISO or authorizing official.
Preferred Qualifications
  • Experience in a FISMA-adjacent non-agency environment — a federally chartered corporation, USF administrator, or similar entity where federal standards apply by memorandum of understanding rather than direct statute.
  • Familiarity with FedRAMP authorization packages and SaaS control inheritance.
  • Experience supporting Privacy Act systems of records and PII control implementation under OMB M-17-12.
Required Certifications

CISSP, or an equivalent information security governance and risk certification demonstrating substantially similar competency and approved by USAC (for example CISM or CGRC/CAP). CISSP is strongly preferred for evaluation positioning.

Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process.

The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.

K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.

This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Manager (TS/SCI)
Information Systems Security Manager (TS/SCI)

K2Spacecorporation • Los Angeles (CA)

On-site
USD 160,000 - 200,000
Equity in the company
Comprehensive benefits package
Paid parental leave
Information Systems Security Manager (TS/SCI)
Information Systems Security Manager (TS/SCI)

K2 Space • Los Angeles (CA)

On-site
USD 160,000 - 200,000
Paid time off
Medical/dental/vision coverage
Life insurance
+2
Information System Security Engineer
Information System Security Engineer

CACI International Inc • Leesburg (VA)

On-site
USD 120,000 - 180,000
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Information Systems Security Manager
Information Systems Security Manager

Kranze Technology Solutions, Inc. • Des Plaines (IL)

On-site
USD 100,000 - 150,000
Paid Time Off
Health Care package
401(k) retirement plan
+2
Senior ISSO, RMF and Authorization / Alternate Lead
Senior ISSO, RMF and Authorization / Alternate Lead

chameleonintegratedservices • Washington

Hybrid
USD 140,000 - 170,000
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

Hybrid
USD 110,000 - 170,000
INFORMATION SYSTEMS AUDITOR
INFORMATION SYSTEMS AUDITOR

K2 Group, Inc. • Arlington (VA)

On-site
USD 85,000 - 110,000
Medical/ Dental/ Vision Insurance
401(k) & ROTH 401(k) plans
Tuition Reimbursement
+1
(691) Mid Information Systems Security Officer
(691) Mid Information Systems Security Officer

Arlosolutionsllc • Washington

On-site
USD 80,000 - 100,000
Information System Security Officer Sr. (Cloud)
Information System Security Officer Sr. (Cloud)

ECS • Washington

On-site
USD 120,000 - 150,000