ISSO Lead DoS CSS
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. One Zero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.
Additional details are available on our website:
Position Title
:
ISSO Lead
Location
:
Remote; must reside within the National Capital Region (NCR).
Clearance
:
Secret
Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m.
- 3:00 p.m. ET, Monday - Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.
Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award
Position Summary
The ISSO Lead is the senior technical authority for the program and the Government's central ISSO point of contact for the DT/EA/CST portfolio. The ISSO Lead maintains an accurate, current picture of every consular system's lifecycle stage, authorization status, and risk posture; leads a team of SME, Senior, and Information Assurance analysts serving as ISSOs of record; sets technical direction for the vulnerability management and cloud engineers;
and interfaces daily with the Information Systems Security Manager (ISSM), Authorizing Official's Designated Representative (AODR), and system owners. This is a designated Key Personnel position.
Key Responsibilities
- Maintain an accurate, up-to-date portfolio of all consular systems, including system lifecycle stage, authorization status and ATO expiration, and a high-level view of risk assessment and risk management activity.
- Maintain version control of RMF artifacts and prepare briefings and reports for the ISSM, AO/AODR, and CST leadership.
- Assign systems to ISSO staff and balance workloads so that every current and future CA system completes the full RMF (Steps 1-6) at least every three years and maintains its ATO.
- Serve as senior escalation point for categorization, control tailoring, inherited-controls, and POA&M risk-rating decisions; review Security Plan Approval Recommendation Letters and AODR Information Sheets before release (RMF Steps 2 and
5). - Provide direction and oversight to system-specific security operations contractors (database, application, and platform security operations) to obtain evidence and drive remediation, ensuring they do not independently develop authoritative RMF artifacts.
- Lead quarterly FISMA metrics submissions and support the Annual FISMA Review.
- Standardize and govern program-wide artifacts:
Evidence Index, Inherited Controls Matrix, System Boundary & Data Flow Package, Control Tailoring Rationale, and Audit and Data Call Response Package. - Chair Implementation Readiness Reviews prior to independent Security Control Assessments and oversee SCRM/demo preparation (RMF Steps 3-4).
- Oversee iPost risk-score management, ensure findings open more than 30 days are tracked and reported, and enforce BOD remediation timelines across the portfolio (RMF Step
6). - Lead post-incident reviews for significant incidents and ensure outcomes flow into risk assessments, POA&M, SSPs, and control implementation statements.
- Mentor, coach, and quality-review the work of SME, Senior, and Information Assurance analysts; set technical priorities for the Tenable, Wiz/cloud, and Dev Sec Ops engineers.
- Identify security requirements for new systems throughout the SDLC and Dev Sec Ops pipelines; participate in the Risk Governance process.
Required Qualifications
- Eight (8)+ years of experience as an ISSO or in a similar Assessment & Authorization role (RFQ §M, Factor
2). - Experience supporting 50 or more FISMA information systems.
- Demonstrated expertise with the NIST Risk Management Framework and FISMA compliance (NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, SP 800-60, FIPS 199/200).
- Current CISSP or CISM certification.
- Active, final SECRET security clearance; U.S. citizenship.
- Experience leading and quality-reviewing the work of other ISSOs or IA analysts.
- Experience using an enterprise GRC tool to manage authorization packages and POA&M.
- Available at the time of Call Order award and committed to the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).