Lead Information System Security Officer (ISSO)

Farfield Systems
United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Cyber Security Information Systems Information Security Management Log Analysis Azure Active Directory Security Information and Event Management Okta Microsoft InTune Azure Security Center Palo Alto Networks
+5 more
Tenable Nessus Splunk Qualys Servicenow Vulnerability Analysis

Job description

As the Lead ISSO, you will manage the full system authorization lifecycle - from initiation through disposal - under NIST Risk Management Framework (RMF) principles. You will serve as Farfield’s primary technical interface with the Government ISSM, CISO, Authorizing Official/AODR, and System Owners; direct the work of Senior ISSOs and Cybersecurity Analysts; chair internal quality reviews of authorization-package artifacts before Government submission; manage the risk and issue register; and represent Farfield in DFC governance forums and technical reviews. You will also coordinate with the Farfield Program Manager on contract-level matters including invoicing, staffing, and reporting. This role is designated Key Personnel.

Requirements

  • U.S. citizenship required
  • Eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation; suitability adjudication must be completed before being granted privileged or administrative system access
  • Active, hands-on cybersecurity expertise - this role requires direct technical engagement, not solely administrative management
  • Demonstrated experience leading ISSO functions across multiple information systems in a federal RMF environment
  • Working familiarity with: CSAM (GRC/authorization-package platform), Splunk (SIEM/log analytics), ServiceNow ITSM modules, Tenable Nessus or Qualys vulnerability scanners, Microsoft Defender for Endpoint/Identity/Cloud/M365, Microsoft Intune and BigFix, Microsoft Azure and M365 security and compliance centers, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler administration consoles
  • Experience developing, reviewing, and submitting authorization packages, POA&Ms, Security Impact Assessments, and continuous monitoring deliverables
  • Strong written and verbal communication skills; ability to interface with senior federal cybersecurity stakeholders
  • Must maintain all qualifications, certifications, experience levels, and clearance eligibility throughout the period of performance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all