Lead Information System Security Officer (ISSO)

Current
Washington, DC, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$145,000.0 - $185,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Border Gateway Protocol Ubuntu (Operating System) Cisco PIX Cloud Computing Cloud Computing Security Cloud Engineering Control Objectives for Information and Related Technology (COBIT) Cyber Security Linux
+41 more
Enhanced Interior Gateway Routing Protocol Fiddler (Software) Federal Information Processing Standards (FIPS) Information Security Management Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Network Security Lightweight Directory Access Protocols (LDAP) Linux Distribution Windows Servers Network Architecture Networking Basics Routing Network Protocols Open Shortest Path First (OSPF) Open Source Technology PCI Data Security Standards Public Key Infrastructure Software Tools Security Assertion Markup Language (SAML) Security Information and Event Management TCP/IP Virtualization Technology VMware VSphere Software Vulnerability Management Wide Area Networks Identity Services Engine Load Balancing Firewalls (Computer Science) Information Technology SolarWinds (Software) Network Support Cybercrime Nessus Firewall Services Module ISO/IEC 27002 Splunk New Relic (SaaS) Qualys Vulnerability Analysis

Job description

We are seeking an energetic and highly motivated Lead Information System Security Officer (ISSO) to champion our organization’s cybersecurity initiatives and ensure the integrity, confidentiality, and availability of our IT infrastructure. In this pivotal role, you will lead a team of security professionals, develop and enforce security policies, and oversee comprehensive security programs aligned with industry standards and regulatory frameworks. Your expertise will drive proactive risk management, security assessment, incident response, and compliance efforts across diverse environments including cloud infrastructure, on-premises networks, and enterprise systems. This is an exciting opportunity to shape our cybersecurity posture while working in a dynamic, fast-paced environment committed to innovation and excellence., * Lead the development, implementation, and maintenance of system security plans in accordance with NIST standards (such as SP 800-53), ISO 27000 series, and other applicable frameworks.

  • Oversee the design and management of network security architectures including LAN, WAN, VPNs, firewalls (e.g., Cisco ASA), IDS/IPS systems, SIEM tools (like Splunk), and cloud security solutions (AWS, Azure).
  • Conduct comprehensive security risk assessments and vulnerability management activities to identify threats within IT infrastructure, cloud environments, and operational processes.
  • Manage security compliance programs by ensuring adherence to government regulations such as FISMA, FedRAMP, PCI DSS, and other regulatory frameworks relevant to information & network security.
  • Supervise incident response procedures including threat detection & response, incident recovery planning, system hardening, and forensic analysis utilizing tools like Fiddler, SolarWinds, or open-source scripting.
  • Collaborate with cross-functional teams on identity & access management (IAM) solutions-integrating LDAP, SSO protocols (SAML), PKI systems-and enforce robust authentication mechanisms across all platforms.
  • Lead governance efforts by managing security policy implementation, conducting security assessments using GRC software tools, and maintaining documentation aligned with ISO 27002 standards.
  • Provide team leadership by mentoring cybersecurity staff on best practices in network engineering, system administration (Windows/Linux), threat intelligence analysis, and vulnerability research to foster a culture of continuous improvement.

Requirements

  • Proven experience in leading cybersecurity teams within complex IT environments involving computer networking concepts such as routing protocols (OSPF/EIGRP/BGP), network architecture design, and network support functions.
  • Extensive knowledge of cybersecurity frameworks including NIST Cybersecurity Framework (CSF), RMF (Risk Management Framework), COBIT principles, and DIACAP.
  • Hands-on expertise with firewall configuration (Cisco ISE/ASA), network protocols (TCP/IP/UDP), load balancing solutions (F5 or equivalent), virtualization platforms (VMware vSphere), and cloud architecture deployment on AWS or Azure.
  • Demonstrated ability to perform security risk assessments investigations using vulnerability management tools like Nessus or Qualys; experience with threat detection & response strategies utilizing SIEMs such as Splunk or New Relic.
  • Strong background in computer science or information technology with certifications such as CISSP, CISM or equivalent; familiarity with operating systems including Windows Server/Linux distributions like Ubuntu or openSUSE is preferred.
  • Knowledge of government information & network security standards including FIPS compliance for cryptography modules; experience working within regulated environments governed by FISMA or FedRAMP is highly desirable.
  • Excellent leadership skills with a track record of managing cross-disciplinary teams focused on IT security management-including incident management, audit processes, and continuous monitoring-ensuring organizational resilience against cyber threats.

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Retirement plan

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all