Information System Security Officer, Lead
$99,000–$225,000 year
On-siteWashington, District of Columbia, United States or McLean, Virginia, United States
Job Summary
Ensure security of agency information systems in compliance with FISMA, NIST SP 800 series, and Risk Management Framework while serving as principal advisor to the Authorizing Official, System Owner, or CISO. Implement security controls for existing and new systems, maintain operational security posture, and oversee continuous monitoring activities including system security assessments and POA&M resolution. Supervise ISSO personnel supporting a portfolio of federal systems, establish priorities, and ensure consistent implementation of RMF processes and documentation. Collaborate with system owners, security teams, and IT staff to maintain a strong security posture and support authorization and risk management processes.
Required Qualifications
- 5+ years of experience with ISSO responsibilities within a federal agency or government contractor environment, including information security or cybersecurity
- Experience supporting security authorization packages through each RMF step, including system categorization, control selection and implementation, security assessment, authorization, and continuous monitoring ensuring required documentation is complete, accurate, and compliant with NIST, FISMA, and agency-specific requirements
- Experience supervising and directing ISSO personnel supporting a portfolio of federal information systems, establishing priorities, and ensuring consistent implementation of RMF processes, quality, and consistency of security documentation
- Knowledge of NIST RMF, FISMA, NIST 800-53, RMF, and federal cybersecurity policies
- Ability to interface with system administrators, auditors, executives, and cross-functional teams effectively
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
- Bachelor's degree
Desired Qualifications
- Experience working in a fast-paced team environment, promptly responding to client requests and needs
- Knowledge of cloud security frameworks such as FedRAMP, Zero Trust architecture, and emerging cybersecurity threats
- Possession of strong communication skills
- CISSP, CISM, CISA, Security+, CAP, or CEH Certification
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.