Senior ISSO/Alternate Lead ISSO
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: Hybrid - On-site at DFC Headquarters, 1100 New York Avenue NW, Washington, DC 20527 (minimum 2 days/week); balance remote (CONUS)
Clearance: Must be eligible for Tier 4 High-Risk Public Trust; U.S. Citizenship required
Job Type: Full-time
Contract Type: Government Contract (Base Year: 12 months; four 12-month option periods)
Position OverviewSeeking a highly experienced Senior Information System Security Officer (ISSO) / Alternate Lead ISSO to provide senior-level cybersecurity compliance, risk management, and authorization support to the U.S. International Development Finance Corporation (DFC), Office of Information Technology (OIT), Cybersecurity Division.
This role serves as the designated alternate to the Lead ISSO and provides senior-level ISSO support, continuity of operations, and coverage as necessary. The Senior ISSO / Alternate Lead ISSO is qualified to assume Lead ISSO duties during scheduled or unscheduled absences and maintains operational continuity in the Lead ISSO's absence.
This is a non-personal services contract position. The contractor employee reports to the Prime Contractor for HR and administrative matters, while receiving work direction from the Government ISSM and COR.
Hybrid position: minimum 2 days/week on-site at DFC Headquarters, Washington, DC; balance remote (CONUS). No travel required.
Key Responsibilities- Serve as designated alternate to the Lead ISSO; assume Lead ISSO duties during scheduled or unscheduled absences
- Maintain operational continuity in the absence of the Lead ISSO
- Perform senior ISSO duties for assigned systems as directed by the Lead ISSO
- Support consistent execution of ISSO activities across assigned systems
- Lead assigned RMF, Con Mon, vulnerability management, POA&M, audit-support, and compliance work streams
- Maintain proficiency in CSAM, Service Now, Splunk, Qualys, Microsoft Defender, Intune, Big Fix, Entra , Okta, Palo Alto Panorama, and Zscaler
- Provide RMF and authorization support per NIST SP 800-37 Rev. 2 (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor)
- Support Continuous Monitoring per NIST SP 800-137, including monthly Con Mon reporting, quarterly access recertification, and annual SSP currency reviews
- Support vulnerability management and POA&M lifecycle, including critical/emergency vulnerability response, CISA KEV/BOD 22-01 compliance, and monthly Service Now-to-CSAM reconciliation
- Support SIA and change coordination for CAB/CCB/ERB governance, including standard, expedited, and emergency changes
- Provide ISSO-level incident response coordination to DFC SOC/IR team, including CSAM context pull, Splunk log-verification, Sit Reps, RCA inputs, and corrective action tracking
- Support audit, assessment, and compliance activities, including FISMA reporting, evidence coordination, and audit finding remediation
- Support security documentation and artifact management (SSP, POA&M, Con Mon Plan, IRP, CP, PTA, PIA, ROB, SIA records, ISAs, MOU/MOA, SOPs, runbooks)
- Maintain Tier 4 Public Trust eligibility; complete all mandatory DFC training
- Comply with DFC security regulations and safeguard CUI
Education:
- Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)
Certifications (recommended):
- CISSP, CISM, CAP, or equivalent cybersecurity certification
Experience:
- Minimum 7 years cybersecurity experience, with at least 3 years in ISSO or RMF support
- Experience supporting federal agencies with FISMA Moderate systems
- Hands-on experience with NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, SP 800-53B, FIPS 199, SP 800-60, SP 800-137, SP 800-128, SP 800-30, and SP 800-39
- Experience with FISMA, OMB A-130, OMB M-22-09 (Zero Trust), and CISA BODs/EDs
- Experience with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).