Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
IBSS Corp. seeks a Lead Information System Security Officer (ISSO) to oversee cybersecurity risk management, authorization, and continuous monitoring for a federal information system.
This senior role includes mentoring ISSOs and providing hands-on analysis across RMF, A&A, and FedRAMP. The position requires CISSP certification, a relevant bachelor’s degree, and extensive federal cybersecurity experience across RMF, NIST SP 800-37/53, and cloud security.
Job Title: Lead Information System Security Officer (ISSO) - CISSP
Location: Silver Spring, MD (downtown)
Clearance Required: Must be able to obtain a Public Trust Clearance
Salary Range: $140K-$150K (based on experience)
Application Deadline: October 31, 2026
The Lead Information System Security Officer (Lead ISSO) provides senior-level cybersecurity risk management, security authorization, assessment, and continuous monitoring support for a complex federal information system. The Lead ISSO serves as a senior cybersecurity advisor while remaining directly responsible for cybersecurity activities and work products associated with assigned system responsibilities.
The Lead ISSO also serves as a senior technical point of contact for the ISSO team, providing guidance on complex or unfamiliar cybersecurity matters and mentoring less-experienced ISSOs. This is a hands‑on cybersecurity role requiring the ability to independently perform complex security analysis while providing technical guidance to other team members as needed.
The environment is geographically distributed and includes maritime and aviation platforms, land‑based facilities, remotely deployed technologies, networked sensors and computing devices, public‑facing applications, on‑premises infrastructure, and FedRAMP‑authorized Microsoft Azure services. The system is categorized as FIPS 199 Moderate and processes multiple forms of sensitive information.
Bachelor's degree in cybersecurity, information technology, computer science, information systems, engineering, or a related discipline, or an equivalent combination of education and relevant professional experience.
Certified Information Systems Security Professional (CISSP) certification.
Significant experience performing cybersecurity risk management, assessment, compliance, or authorization activities for federal information systems, including experience in a senior ISSO, senior cybersecurity, or comparable technical GRC capacity.
Advanced knowledge and practical experience with FISMA, the NIST Risk Management Framework, federal A&A processes, NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FIPS 199/200, POA&M management, and continuous monitoring.
Demonstrated FedRAMP knowledge and experience, including security requirements, authorization concepts, control inheritance, shared security responsibilities, cloud authorization documentation, and continuous monitoring.
Experience supporting federal information systems that use FedRAMP-authorized cloud services and evaluating cloud services and inherited controls within a system authorization boundary.
Experience assessing security controls and independently evaluating technical and non‑technical evidence for sufficiency, credibility, implementation, and effectiveness.
Experience developing and maintaining federal cybersecurity authorization documentation and using JCAM/CSAM or comparable federal cybersecurity governance, risk, and compliance platforms.
Experience performing and analyzing vulnerability and configuration assessments, coordinating remediation, and validating corrective actions.
Working knowledge of cloud and network security, ICAM, PKI and cryptography, vulnerability management, configuration management, security monitoring, incident response, Zero Trust principles, and Cybersecurity Supply Chain Risk Management (C‑SCRM).
Experience providing technical guidance to cybersecurity personnel and mentoring less‑experienced cybersecurity professionals.
Ability to analyze complex or ambiguous cybersecurity issues, translate requirements into actionable technical and operational requirements, and communicate risk effectively to technical personnel, system owners, management, assessors, and other stakeholders.
Experience supporting FIPS 199 Moderate federal information systems and geographically distributed or remotely deployed environments.
Experience with Microsoft Azure, FedRAMP-authorized cloud services, hybrid cloud environments, FedRAMP authorization packages, continuous monitoring information, and security control inheritance.
Experience with enterprise identity and security technologies, including Microsoft Active Directory, CAC/PIV, multi‑factor authentication, PKI, digital certificates, SIEM, Endpoint Detection and Response (EDR), and centralized security monitoring.
Experience with vulnerability scanning, SCAP-compatible assessment technologies, secure configuration assessment, and remediation validation.
Experience with network security technologies and concepts, including segmentation, VLANs, firewalls, remote connectivity, and system interconnections.
Experience with FIPS‑validated encryption, databases, web applications, and protection of PII and other sensitive federal information.
Experience with third‑party risk management and Cybersecurity Supply Chain Risk Management.
Experience supporting maritime, aviation, scientific, sensor, or comparable operational environments.
CompTIA Security+, Certified Information Security Manager (CISM), cloud security, Microsoft Azure security, or other relevant cybersecurity, cloud security, security assessment, or risk‑management certifications.
Since 1992, IBSS, a woman‑owned small business, has provided transformational consulting services to the Federal defense, civilian, and commercial sectors. Our services include cybersecurity and enterprise information technology, environmental science and engineering (including oceans, coasts, climate, and weather), and professional management services.
Our approach is to serve our employees by investing in their growth and development. As a result, our employees bring greater capabilities and provide exceptional service to our clients. In addition to creating career development opportunities for our employees, IBSS is passionate about giving back to the community and serving the environment. We strive to leave something better behind for the next generation.
We measure our success by the positive impact we have on our employees, clients, partners, and the communities we serve. Our tagline, Powered by Excellence, is a recognition of the employees that make up IBSS and ensures we deliver results with quality, applying industry best practices and certifications.
IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company‑paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex‑Spending (FSA)/Dependent Care Account (DCA) options.
IBSS is an affirmative action and equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Click https://www.eeoc.gov/poster to see that the EEO is the law. Please direct any inquiries to the HR Department email at HR@ibsscorp.com.
If you require reasonable accommodation in completing this application, interviewing, completing any pre‑employment testing, or otherwise participating in the employee selection process, please direct your inquiries to the Talent Acquisition Department at Recruiting@ibsscorp.com.