> Markdown version of [/jobs/ext/2475849-senior-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2475849-senior-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer (ISSO) - **Company:** Development InfoStructure - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $99,000.0 - $109,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Microsoft Windows, Microsoft Azure, Cloud Computing, Cyber Security, Information Systems, Information Security Management, Raw Data, Azure Security Center, Information Technology, Splunk, Qualys, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=97d5316e5bc6cbe2 ## About the Role * Bachelor's degree in cybersecurity, computer science, information systems, or a related technical discipline * Minimum 8 years of ISSO, security control assessment, or Risk Management Framework experience supporting federal information systems * Demonstrated production of RMF artifacts: System Security Plans, control implementation statements, assessment evidence, and POA&Ms * Readiness to assume Lead ISSO responsibilities, including governance-forum representation and internal quality review leadership Required Certifications * CISSP, CGRC (formerly CAP), or CASP+, or a comparable certification Technical Skills * Hands-on proficiency with CSAM. A comparable federal governance, risk, and compliance platform such as eMASS or ArchAngel considered where you can demonstrate the ability to transition to CSAM * ServiceNow, Splunk, and at least one enterprise vulnerability scanner * Working knowledge of NIST SP 800-37 Revision 2, NIST SP 800-53, and NIST SP 800-137 * Clear technical writing that stands up to federal review without rework Preferred Qualifications * FedRAMP shared-responsibility documentation experience * Microsoft Azure Government and Microsoft 365 GCC High familiarity * Privacy documentation support, including Privacy Threshold Analyses and Privacy Impact Assessments * Experience with Microsoft Defender for Endpoint, Identity, and Cloud * Current or recent Tier 4 High-Risk Public Trust adjudication, or higher ## Description As a Senior ISSO, you will perform senior ISSO duties for assigned systems and lead an assigned area of the program spanning authorization, continuous monitoring, vulnerability and POA&M management, audit support, and compliance. You will work directly in the agency's compliance platform rather than around it, and you will be expected to produce artifacts a federal assessor can accept without a round of rework. What You'll Do Maintain Authorization Packages * Maintain authorization packages, control implementation statements, inheritance records, and POA&M items in CSAM for assigned systems * Develop and recommend system security categorizations and control baselines, documenting tailoring rationale * Reconcile inherited controls against current cloud provider and common control provider documentation * Keep records audit-ready and internally consistent between the compliance platform and supporting repositories Run Continuous Monitoring * Execute continuous monitoring plans: recurring security reviews, Splunk log ingestion verification, and monthly posture reporting * Analyze vulnerability scan results from Tenable, Qualys, and Microsoft Defender; validate findings and document false-positive rationale with supporting evidence * Coordinate remediation with engineering teams and track POA&M items to closure with bidirectional ServiceNow traceability * Produce monthly reporting that gives federal stakeholders analysis and recommended action, not raw data extracts Analyze Change and Support Governance * Prepare security impact analyses for change requests within contract turnaround times * Support change advisory and change control board meetings, and perform post-change verification * Analyze proposed changes for significant-change implications and prepare the resulting assessment packages Support Incidents and Audits * Provide ISSO-side incident response coordination: affected-system context from CSAM within one business hour of declaration, situation reports, root cause analysis inputs, and corrective action tracking * Support audits, assessments, and FISMA reporting through evidence staging, auditor coordination, draft finding responses, and corrective action plans Cover the Lead * Step into Lead ISSO duties during planned and unplanned absences without a drop in service * Represent the team in agency governance forums when the Lead is unavailable * Lead internal quality reviews of deliverables when acting in the Lead role Areas of Focus Both positions carry the identical qualification bar and both must be able to assume the Lead ISSO role. They differ only in primary area of ownership, and each area has a trained backup so that no part of the program depends on one person. * Monitoring and Remediation: primary owner of continuous monitoring and security posture management and of vulnerability and POA&M execution, and the coordination point for incident response * Authorization and Assurance: primary owner of security documentation and artifact management, security impact analysis and change coordination, and audit, assessment, and compliance support, working alongside the Lead ISSO on authorization efforts. Depth in CSAM is prioritized for this position. Both positions are cross-trained across these areas and work staggered schedules to cover the core business day., * Authorization records for assigned systems accurate, current, and internally consistent * Findings triaged and reported inside contract turnaround times * Monthly reporting federal stakeholders can act on directly * Able to cover the Lead role on short notice without a dip in service Special Requirements * Primarily remote, with in-person presence required at DFC headquarters in Washington, DC on an as-needed basis for governance meetings, audits, and assessments. Candidates based in the Washington, DC metropolitan area are preferred. * Authorization to work in U.S. without restriction. * Must be eligible for and able to obtain a Tier 4 High-Risk Public Trust background investigation. Adjudication must be complete before privileged access to enterprise security tools or authorization repositories is granted. * Must obtain and maintain an agency-issued PIV card. * Must complete agency cybersecurity, privacy, records management, insider threat, and applicable role-based training on entry and annually thereafter. * Availability during core business hours, 7:00 a.m. to 6:00 p.m. Eastern, Monday through Friday, excluding federal holidays, and participation in a shared on-call rotation for off-hours incident acknowledgment. Compensation & Benefits ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing Clarity to Event Streams: Enabling Analytics and AI Through Rich Metadata](https://www.wearedevelopers.com/videos/1616-bringing-clarity-to-event-streams-enabling-analytics-and-ai-through-rich-metadata) - [Why Your AI Agent Keeps Hallucinating Your Data: Building Deterministic Context Layers](https://www.wearedevelopers.com/videos/2055-why-your-ai-agent-keeps-hallucinating-your-data-building-deterministic-context-layers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)