ISSO Lead DoS CSS

OneZero Solutions

Washington (District of Columbia)

Remote

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off and holidays
Employee referral program
Educational assistance

Job summary

OneZero Solutions is seeking an ISSO Lead to serve as the program's senior technical authority and central ISSO for the DT/EA/CST portfolio. You will manage RMF artifacts, coordinate with ISSM, AO/AODR, and system owners, and lead a team of IA analysts and cloud engineers to ensure ongoing authorization and risk posture.

The role is remote with duties performed within the National Capital Region; a Secret clearance is required, and the candidate must meet core hours and travel within NCR as

Qualifications

  • Eight or more years of ISSO/AA experience with RMF and FISMA.
  • Active final SECRET clearance and U.S. citizenship.
  • Experience leading and reviewing work of other ISSOs/IA analysts.

Responsibilities

  • Maintain an up-to-date portfolio of all consular systems and ATO expirations.
  • Coordinate RMF artifacts and briefings for ISSM, AO/AODR, CST leadership.
  • Assign systems to ISSO staff and ensure RMF steps 1-6 are completed every three years.
  • Review risk-rating decisions, letters, and AODR information sheets before release.
  • Oversee security operations contractors to aid remediation and artifact production.
  • Lead quarterly FISMA metrics submissions and the annual review.
  • Standardize program-wide artifacts and governance artifacts.
  • Chair readiness reviews for independent security assessments.
  • Manage iPost risk scores and enforce remediation timelines.
  • Lead post-incident reviews and feed outcomes into risk assessments.

Skills

Eight+ years ISSO experience
Active SECRET clearance
CISSP or CISM certification

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity

Tools

GRC platforms (ArchAngel)
Tenable / Wiz vulnerability output
Visio data-flow & boundary diagrams

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position Title

ISSO Lead

Location

Remote; must reside within the National Capital Region (NCR).

Clearance

Secret

Work Schedule

Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. - 3:00 p.m. ET, Monday - Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type

Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The ISSO Lead is the senior technical authority for the program and the Government's central ISSO point of contact for the DT/EA/CST portfolio. The ISSO Lead maintains an accurate, current picture of every consular system's lifecycle stage, authorization status, and risk posture; leads a team of SME, Senior, and Information Assurance analysts serving as ISSOs of record; sets technical direction for the vulnerability management and cloud engineers; and interfaces daily with the Information Systems Security Manager (ISSM), Authorizing Official's Designated Representative (AODR), and system owners. This is a designated Key Personnel position.

Key Responsibilities
  • Maintain an accurate, up-to-date portfolio of all consular systems, including system lifecycle stage, authorization status and ATO expiration, and a high-level view of risk assessment and risk management activity.
  • Maintain version control of RMF artifacts and prepare briefings and reports for the ISSM, AO/AODR, and CST leadership.
  • Assign systems to ISSO staff and balance workloads so that every current and future CA system completes the full RMF (Steps 1-6) at least every three years and maintains its ATO.
  • Serve as senior escalation point for categorization, control tailoring, inherited-controls, and POA&M risk-rating decisions; review Security Plan Approval Recommendation Letters and AODR Information Sheets before release (RMF Steps 2 and 5).
  • Provide direction and oversight to system-specific security operations contractors (database, application, and platform security operations) to obtain evidence and drive remediation, ensuring they do not independently develop authoritative RMF artifacts.
  • Lead quarterly FISMA metrics submissions and support the Annual FISMA Review.
  • Standardize and govern program-wide artifacts: Evidence Index, Inherited Controls Matrix, System Boundary & Data Flow Package, Control Tailoring Rationale, and Audit and Data Call Response Package.
  • Chair Implementation Readiness Reviews prior to independent Security Control Assessments and oversee SCRM/demo preparation (RMF Steps 3-4).
  • Oversee iPost risk-score management, ensure findings open more than 30 days are tracked and reported, and enforce BOD remediation timelines across the portfolio (RMF Step 6).
  • Lead post-incident reviews for significant incidents and ensure outcomes flow into risk assessments, POA&M, SSPs, and control implementation statements.
  • Mentor, coach, and quality-review the work of SME, Senior, and Information Assurance analysts; set technical priorities for the Tenable, Wiz/cloud, and DevSecOps engineers.
  • Identify security requirements for new systems throughout the SDLC and DevSecOps pipelines; participate in the Risk Governance process.
Required Qualifications
  • Eight (8)+ years of experience as an ISSO or in a similar Assessment & Authorization role (RFQ §M, Factor 2).
  • Experience supporting 50 or more FISMA information systems.
  • Demonstrated expertise with the NIST Risk Management Framework and FISMA compliance (NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, SP 800-60, FIPS 199/200).
  • Current CISSP or CISM certification.
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience leading and quality-reviewing the work of other ISSOs or IA analysts.
  • Experience using an enterprise GRC tool to manage authorization packages and POA&Ms.
  • Available at the time of Call Order award and committed to the full base period of performance.
Preferred Qualifications
  • Master's degree in a related field.
  • Department of State experience (DT, CA, or CST), including ArchAngel and iPost.
  • CGRC/CAP, CISA, or CRISC certification in addition to CISSP/CISM.
  • Experience with High Value Asset (HVA) systems, cloud/hybrid authorization boundaries, FedRAMP inheritance, and zero-trust overlays.
  • Experience leading teams of 10 or more cybersecurity professionals.
Technical Skills
  • Expert: NIST SP 800-37, 800-53/53A/53B Rev. 5, 800-60, 800-34, 800-61, 800-63 (DIRA), FIPS 199/200; OMB A-130; CISA BODs.
  • GRC platforms (ArchAngel or equivalent), iPost or comparable continuous-monitoring scoring, POA&M lifecycle management.
  • Ability to interpret Tenable and Wiz vulnerability/compliance output, KEV and STIG results, and translate them into risk decisions.
  • SSP, SAR, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring; Visio data-flow and boundary diagrams.
Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field is required

Position Status

New Position, contingent upon Call Order award

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SME – Information Security Analyst DoS CSS
SME – Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+6
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 150,000
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 170,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Program Manager DoS CSS
Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 210,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Deputy Program Manager DoS CSS
Deputy Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
DHS Information Systems Security Officer (ISSO) Senior
DHS Information Systems Security Officer (ISSO) Senior

onezerollc • Washington

On-site
USD 180,000 - 230,000
Parking stipend/parking allowance
DHS Information Systems Security Officer (ISSO) Senior
DHS Information Systems Security Officer (ISSO) Senior

OneZero Solutions • Washington

On-site
USD 120,000 - 150,000
Health insurance
401K with company matching
PTO & paid holidays
+2
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Information System Security Officer Level II
Information System Security Officer Level II

onezerollc • Baltimore (MD)

On-site
USD 90,000 - 130,000
Health Insurance
Dental Insurance
Vision Insurance
+6
Information Systems Security Officer
Information Systems Security Officer

Kids for the Future • Foster (VA)

On-site
USD 120,000 - 185,000