ISSO / Cybersecurity Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+6 more
Job description
Working under the direction of the Lead and Senior ISSOs, you will perform the practical, outcome-driven cybersecurity work that keeps DFC’s 32 information systems authorized and operationally secure. Your responsibilities will span the ISSO support spectrum: creating and updating POA&M entries in CSAM after finding identification; preparing Security Impact Assessments for standard and significant system changes; supporting continuous monitoring activities; producing vulnerability assessment data from Tenable Nessus or Qualys; contributing to audit and assessment evidence packages; documenting corrective actions and RCA findings; and supporting incident response by providing affected-system context from CSAM to incident responders. You will work within defined SLA timelines and contribute to the team’s quality-first delivery culture. This is a full-time, direct-support role - not a coordination function.
Requirements
- U.S. citizenship required
- Eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation; suitability adjudication must be completed before being granted privileged or administrative system access
- Hands-on experience supporting ISSO functions, RMF activities, or cybersecurity operations in a federal IT environment
- Working familiarity with: CSAM (GRC/authorization-package platform), Splunk (SIEM/log analytics), ServiceNow ITSM modules, Tenable Nessus or Qualys vulnerability scanners, Microsoft Defender for Endpoint/Identity/Cloud/M365, Microsoft Intune and BigFix, Microsoft Azure and M365 security and compliance centers, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler administration consoles
- Experience creating and managing POA&Ms, supporting vulnerability management workflows, and preparing cybersecurity documentation in a federal GRC platform
- Ability to meet defined response and deliverable timelines in a fast-paced, audit-sensitive environment
- Strong attention to detail and commitment to accurate, complete recordkeeping
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
Walking Into The Era of Supply Chain Risks
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.