Senior Information System Security Officer (ISSO)

E-Logic INC
Washington, DC, United States
28 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Information Security Management Security Information and Event Management Software Vulnerability Management Data Ingestion RSA Archer Platform Splunk Qualys
+3 more
Servicenow Plan of Action and Milestones Vulnerability Analysis

Job description

We are looking for a highly skilled and proactive Senior Information System Security Officer (ISSO) to join our team supporting the U.S. International Development Finance Corporation (DFC). As a Senior ISSO, you will act as the Alternate ISSO, fully qualified to step in for the Lead ISSO during their absence. You will be responsible for performing complex ISSO duties across a portfolio of FISMA-moderate systems, leading critical workstreams in RMF, continuous monitoring, and vulnerability management. You will work directly with federal staff to ensure systems maintain a strong security posture and achieve compliance with federal cybersecurity policies., * ISSO Operations: Perform senior-level ISSO duties for assigned information systems, managing their security posture throughout the system lifecycle.

  • RMF Execution: Lead the development and maintenance of RMF artifacts, including System Security Plans (SSPs), POA&Ms, and Security Control Assessments within the CSAM platform.
  • Continuous Monitoring: Manage continuous monitoring and security posture activities, including analyzing vulnerability scan results and verifying log ingestion in Splunk.
  • Incident & Audit Support: Provide critical ISSO support during cybersecurity incidents and audits by retrieving system context, coordinating with the SOC, and documenting corrective actions.
  • Change Management: Conduct Security Impact Analyses (SIAs) for proposed system changes and support federal decision-making at Change Control Boards (CCB).
  • Workstream Leadership: Lead assigned workstreams in areas such as vulnerability management, POA&M lifecycle management, or security documentation.

Requirements

  • Citizenship: Must be a U.S. Citizen.
  • Clearance: Must be eligible to obtain and maintain a Tier 4 High-Risk Public Trust background investigation.
  • Certifications: Must hold a relevant cybersecurity certification (e.g., CISSP, CISM, Security+, or equivalent). CISSP or CISM is highly preferred.
  • Experience: Minimum of 5-7 years of experience in information security, with at least 3 years of direct experience as an ISSO or in a similar RMF/compliance role within the federal government.
  • Technical Proficiency: Demonstrated hands-on experience with cybersecurity and compliance tools, including:
  • GRC Platforms (CSAM strongly preferred).
  • SIEM Platforms (Splunk strongly preferred).
  • ITSM Tools (ServiceNow).
  • Vulnerability Assessment Tools (Tenable, Qualys).
  • Cloud Security (Microsoft Azure, M365, Entra ID).

Desired Experience:

  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, and FISMA compliance.
  • Experience with federal audit preparation and Inspector General (IG) or GAO reviews.
  • Experience supporting FedRAMP-compliant cloud environments.
  • Excellent analytical, problem-solving, and communication skills.

Clearance Requirement: Must be eligible for a Tier 4 High-Risk Public Trust

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all