Senior ISSO

chameleonintegratedservices

Washington (District of Columbia)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Vision plan
401K match
Life insurance
Disability insurance
Training allowance
PTO

Job summary

Chameleon Integrated Services seeks an experienced Senior ISSO for continuous monitoring and vulnerability management across assigned systems. You will lead security posture reporting, POA&M execution, Splunk validation, and ISSO-level incident coordination to maintain authorization stability in federal environments.

Responsibilities include reconciling findings among scanners, ServiceNow, CSAM, and remediation teams; supporting Priority 1/2 incidents; producing situation reports and RCAs;

Qualifications

  • At least 8 years of cybersecurity experience.
  • At least 5 years performing federal continuous monitoring, vulnerability management, ISSO, security operations, or related risk-management work.
  • Direct experience with: Tenable Nessus, Tenable Security Center, or Qualys.
  • Splunk searches, dashboards, or event validation.
  • Vulnerability triage and false-positive review.
  • POA&M creation and maintenance.
  • Finding assignment and remediation coordination.
  • Security posture metrics and trend reporting.
  • NIST SP 800-53 control monitoring.
  • NIST SP 800-137 continuous monitoring.

Responsibilities

  • Lead continuous monitoring, vulnerability management, POA&M execution support, security posture reporting, Splunk validation, and ISSO-level incident coordination for assigned systems.
  • The position will reconcile vulnerability findings among scanners, ServiceNow, CSAM, remediation teams, and system authorization records.
  • Support Priority 1 and Priority 2 incidents, prepare situation reports and RCAs, validate Splunk timelines, update POA&M s, and maintain system-level Continuous Monitoring Plans.

Skills

Cybersecurity experience
Federal continuous monitoring
Vulnerability management
ISSO/security operations
POA&M coordination
Splunk security
NIST SP 800-53
NIST SP 800-137
Incident coordination
Cross-team coordination

Education

CISSP
CISM
CGRC/CAP
CySA+
GIAC certification

Tools

Tenable Nessus
Tenable Security Center
Qualys
Splunk
ServiceNow
CSAM

Job description

We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.

Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.

We offer a Full Benefits package including:
  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO and more
Senior ISSO, Continuous Monitoring, Vulnerability, and Incident Coordination
  • Must be a United States citizen.
  • Must be eligible for a Tier 4 High-Risk Public Trust investigation.
  • Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Role:

Lead continuous monitoring, vulnerability management, POA&M execution support, security posture reporting, Splunk validation, and ISSO-level incident coordination for assigned systems.

The position will reconcile vulnerability findings among scanners, ServiceNow, CSAM, remediation teams, and system authorization records. It will support Priority 1 and Priority 2 incidents, prepare situation reports and RCAs, validate Splunk timelines, update POA&Ms, and maintain system-level Continuous Monitoring Plans.

Minimum Requirements:
  • At least 8 years of cybersecurity experience
  • At least 5 years performing federal continuous monitoring, vulnerability management, ISSO, security operations, or related risk-management work
  • Direct experience with:
    • Tenable Nessus, Tenable Security Center, or Qualys
    • Splunk searches, dashboards, or event validation
    • Vulnerability triage and false-positive review
    • POA&M creation and maintenance
    • Finding assignment and remediation coordination
    • Security posture metrics and trend reporting
    • NIST SP 800-53 control monitoring
    • NIST SP 800-137 continuous monitoring
  • Experience coordinating remediation with endpoint, network, cloud, application, and identity teams
  • Experience supporting incident-response documentation, SitReps, after-action reports, or RCAs
  • Understanding of CISA directives, vulnerability-remediation deadlines, and federal logging requirements
  • One of:
    • CISSP
    • CISM
    • CGRC/CAP
    • CySA+ with substantial federal experience
    • GIAC certification relevant to incident response or vulnerability management
  • Must accept participation in an after-hours incident rotation
Competitive Differentiators:
  • Direct CSAM and ServiceNow integration or reconciliation experience.
  • Splunk Enterprise Security.
  • Microsoft Defender for Endpoint, Identity, or Cloud.
  • Tenable.sc or Qualys VMDR.
  • CISA Binding Operational Directives and Known Exploited Vulnerabilities tracking.
  • Azure and Microsoft 365 security monitoring.
  • Palo Alto, Zscaler, Entra ID, Okta, or endpoint-management experience.
  • Federal major-incident or P1 incident support.
  • Experience building ConMon dashboards for executive review.
  • Current Tier 4 or Tier 5 suitability.
The resume must clearly identify:
  • Number of assets, systems, or authorization boundaries monitored.
  • Scanner and SIEM tools used.
  • Candidate’s role in vulnerability validation and POA&M administration.
  • Finding volume, backlog, aging, closure, or remediation metrics.
  • Incident severity and documentation responsibilities.
  • Splunk queries, timeline validation, or dashboards developed.
  • Examples of coordination with technical remediation teams.
  • Examples where monitoring results changed system risk posture or authorization records.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status

Texting Privacy Policy

  • Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
  • No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
  • Message frequency will vary depending on the application process.Msg & data rates may apply.
  • OPT out at any time by texting "Stop".
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISSO / Security Compliance Analyst
ISSO / Security Compliance Analyst

chameleonintegratedservices • Washington

On-site
USD 90,000 - 130,000
Health insurance
Vision plan
401K plan
+4
Lead ISSO / Technical Program Lead
Lead ISSO / Technical Program Lead

chameleonintegratedservices • Washington

On-site
USD 180,000 - 260,000
Health insurance
Vision plan (100% company paid)
401K match
+4
Senior ISSO
Senior ISSO

Agile Defense, LLC • Washington

On-site
USD 120,000 - 180,000
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
ISSO – Vulnerability Management
ISSO – Vulnerability Management

JCS Solutions LLC • Andrews (MD)

On-site
USD 100,000 - 114,000
Health, dental, and vision insurance
Life insurance
Short- and long-term disability
+3
Senior Information Assurance Analyst
Senior Information Assurance Analyst

Qmulos • Arlington (VA)

On-site
USD 90,000 - 120,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Steampunk, Inc. • McLean (VA)

On-site
USD 90,000 - 140,000
Cleared On Site Information Systems Security Officers (ISSO) (5359)
Cleared On Site Information Systems Security Officers (ISSO) (5359)

SMX • United States

On-site
USD 105,200 - 176,900
Health insurance
Paid leave
Retirement
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Themis Insight • Fort Meade (MD)

On-site
USD 125,000 - 160,000
Competitive health, dental, and vision
401k with 6% contribution
11 holidays and 25 days PTO
+2
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -

RedTrace Technologies • Washington

On-site
USD 80,000 - 100,000
Competitive salary
401(k) plan
Annual performance bonus
+5