> Markdown version of [/jobs/ext/2547667-lead-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2547667-lead-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Information System Security Officer (ISSO) - **Company:** Current - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $145,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Border Gateway Protocol, Ubuntu (Operating System), Cisco PIX, Cloud Computing, Cloud Computing Security, Cloud Engineering, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Linux, Enhanced Interior Gateway Routing Protocol, Fiddler (Software), Federal Information Processing Standards (FIPS), Information Security Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Network Security, Lightweight Directory Access Protocols (LDAP), Linux Distribution, Windows Servers, Network Architecture, Networking Basics, Routing, Network Protocols, Open Shortest Path First (OSPF), Open Source Technology, PCI Data Security Standards, Public Key Infrastructure, Software Tools, Security Assertion Markup Language (SAML), Security Information and Event Management, TCP/IP, Virtualization Technology, VMware VSphere, Software Vulnerability Management, Wide Area Networks, Identity Services Engine, Load Balancing, Firewalls (Computer Science), Information Technology, SolarWinds (Software), Network Support, Cybercrime, Nessus, Firewall Services Module, ISO/IEC 27002, Splunk, New Relic (SaaS), Qualys, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=58dc560dec728e29 ## About the Role * Proven experience in leading cybersecurity teams within complex IT environments involving computer networking concepts such as routing protocols (OSPF/EIGRP/BGP), network architecture design, and network support functions. * Extensive knowledge of cybersecurity frameworks including NIST Cybersecurity Framework (CSF), RMF (Risk Management Framework), COBIT principles, and DIACAP. * Hands-on expertise with firewall configuration (Cisco ISE/ASA), network protocols (TCP/IP/UDP), load balancing solutions (F5 or equivalent), virtualization platforms (VMware vSphere), and cloud architecture deployment on AWS or Azure. * Demonstrated ability to perform security risk assessments investigations using vulnerability management tools like Nessus or Qualys; experience with threat detection & response strategies utilizing SIEMs such as Splunk or New Relic. * Strong background in computer science or information technology with certifications such as CISSP, CISM or equivalent; familiarity with operating systems including Windows Server/Linux distributions like Ubuntu or openSUSE is preferred. * Knowledge of government information & network security standards including FIPS compliance for cryptography modules; experience working within regulated environments governed by FISMA or FedRAMP is highly desirable. * Excellent leadership skills with a track record of managing cross-disciplinary teams focused on IT security management-including incident management, audit processes, and continuous monitoring-ensuring organizational resilience against cyber threats. ## Description We are seeking an energetic and highly motivated Lead Information System Security Officer (ISSO) to champion our organization's cybersecurity initiatives and ensure the integrity, confidentiality, and availability of our IT infrastructure. In this pivotal role, you will lead a team of security professionals, develop and enforce security policies, and oversee comprehensive security programs aligned with industry standards and regulatory frameworks. Your expertise will drive proactive risk management, security assessment, incident response, and compliance efforts across diverse environments including cloud infrastructure, on-premises networks, and enterprise systems. This is an exciting opportunity to shape our cybersecurity posture while working in a dynamic, fast-paced environment committed to innovation and excellence., * Lead the development, implementation, and maintenance of system security plans in accordance with NIST standards (such as SP 800-53), ISO 27000 series, and other applicable frameworks. * Oversee the design and management of network security architectures including LAN, WAN, VPNs, firewalls (e.g., Cisco ASA), IDS/IPS systems, SIEM tools (like Splunk), and cloud security solutions (AWS, Azure). * Conduct comprehensive security risk assessments and vulnerability management activities to identify threats within IT infrastructure, cloud environments, and operational processes. * Manage security compliance programs by ensuring adherence to government regulations such as FISMA, FedRAMP, PCI DSS, and other regulatory frameworks relevant to information & network security. * Supervise incident response procedures including threat detection & response, incident recovery planning, system hardening, and forensic analysis utilizing tools like Fiddler, SolarWinds, or open-source scripting. * Collaborate with cross-functional teams on identity & access management (IAM) solutions-integrating LDAP, SSO protocols (SAML), PKI systems-and enforce robust authentication mechanisms across all platforms. * Lead governance efforts by managing security policy implementation, conducting security assessments using GRC software tools, and maintaining documentation aligned with ISO 27002 standards. * Provide team leadership by mentoring cybersecurity staff on best practices in network engineering, system administration (Windows/Linux), threat intelligence analysis, and vulnerability research to foster a culture of continuous improvement. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)