Security Lead/ISSO
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Lentech is seeking a high-Performance, multi-disciplinary team to lead a technical implementation of a Microsoft Dynamics 365 and Power Platform-based case management system (CMS). This mission-critical project and CMS supports legal services to children in support of the U.S. Government. U.S. Citizenship is required along with the ability to positively pass a public trust background investigation.
The primary implementation timeline occurs across the first 180 days of the project and moves into steady state operations for the remainder of the first year. A five-year follow-on contract is expected based on positive performance in the first year. The implementation follows an aggressive timeline divided into four key phases:
Mobilization, Core Operations, Fully Functional Delivery, and Steady-state Operations.
This effort demands a collaborative team capable of maintaining operational continuity throughout the transition and into operations. You will be working with a primary legal team providing the CMS to the lawyers working each individual case. Candidates must be prepared to handle high-velocity delivery, strict data privilege boundaries, and the technical rigor required to support vulnerable populations.
Role Overview :The Security Lead/ISSO is a critical position for working towards an ATO during the implementation period. This role ensures that security and privacy are treated as active implementation work streams and release criteria rather than end-of-project documentation tasks. The lead is responsible for the overall security architecture, ensuring all security documents are created, producing all mandatory compliance artifacts, and establishing the tested protocols for incident response.
Core Responsibilities:- Security Artifact Production: Lead the development of a comprehensive artifact package, including the System Security Plan (SSP), FIPS 199 categorization, e-Authentication Risk Assessment, Business Impact Analysis (BIA), and the system contingency plan.
- Incident Management: Establish and manage the mandatory incident notification path and support the formal government reporting process.
- Access and Privilege Control: Implement "default-deny" access boundaries for attorney work product, manage organization isolation for external providers, and conduct monthly account and access reviews with retained evidence.
- Data Privacy Integration: Integrate privacy-by-design requirements into the data model, including data minimization, PII review protocols, and ensuring no Social Security Numbers are stored by design.
- Assessment and Findings Support: Maintain the Plan of Action and Milestones (POA&M) for open findings and provide the objective evidence required to support independent assessments and Government connection readiness.
- Governance: Participate in the Change Control Board (CCB) to review and approve all security-relevant and baseline changes.
- Technical Resilience: Implement and test backup, recovery, and reconstitution procedures based on Organization-approved RTO (Recovery Time Objective) and RPO (Recovery Point Objective) values.
- Must be a US citizen
- Must hold a PUBLIC TRUST or be eligible
- 8+ YOE as an ISSO
- Compliance Frameworks: Deep experience with NIST SP 800-53 controls and the security standards required for Government Community Cloud (GCC) environments. Understanding of FedRAMP inheritance and full compliance using a CSP provided Customer Responsibility Matrix (CRM)
- MS Dynamics 365/Power Platform Security: Expert knowledge of Dataverse security boundaries, including role-based access, field-level security, and organization-scoped data isolation.
- CUI Protection: Background in handling Controlled Unclassified Information (CUI) and maintaining the privilege boundary between program data and attorney work product.
- Professional
Certifications:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- Experience-based certifications in FedRAMP or NIST
-aligned federal security auditing.
Success in this role is measured by the delivery of a tested, supportable security posture that satisfies all RTM control…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).