Lead Information System Security Officer; ISSO
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
** CONTINGENT UPON CONTRACT AWARD
** Overview:
Job Title: Lead Information System Security Officer (ISSO)
Security Clearance: Ability to Obtain Tier 4 High-Risk Public Trust
Location :
Washington, D.C.
(Due to the nature of the work and contract requirements, U.S. Citizenship is required.)
Description:C3EL is seeking a Lead Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract. This role will serve as the single point of accountability for technical performance and remain a hands-on cybersecurity practitioner as the technical leader, Government interface, and quality authority for the entire ISSO program.
Responsibilities will include, but not be limited to:
- Provide on-site cybersecurity and RMF sustainment support.
- Chair internal quality reviews and ensure deliverables are complete, current, consistent, timely, and audit ready.
- Manage technical risks, issues, escalations, SLA/KPI/AQL performance, action items, and corrective actions.
- Support weekly reports, monthly status reports, and quarterly executive reviews, including authorization, vulnerability, POA&M, audit, and staffing status.
- Lead a team of two Senior ISSOs and maintain coverage during absence, vacancy, surge, or suitability delay.
- Produce accurate, concise, and audit-ready Government cybersecurity documentation.
- Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.
- U.S. Citizenship.
- Eligibility to obtain a Tier 4 High-Risk Public Trust.
- Minimum ten (10) years in cybersecurity.
- Minimum seven (7) years in federal RMF/ISSO work.
- Minimum three (3) years leading ISSO or authorization teams.
- Hands-on CSAM experience supporting system profiles, controls, evidence, POA&M, and authorization workflows.
- Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.
- Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms.
- Direct experience briefing and coordinating with ISSMs, CISOs, AOs, AODRs, System Owners, assessors, and senior Government officials.
- Direct experience overseeing SSPs, SAPs, SARs, POA&M, risk assessments, control statements, and evidence packages.
- Expert knowledge of all seven RMF steps, ATO, reauthorization, ongoing authorization, control baselines, and inheritance.
- Working proficiency with Service Now, Splunk, and vulnerability-scanning platforms.
- At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.
- Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).