> Markdown version of [/jobs/ext/2599890-lead-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2599890-lead-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Information System Security Officer - **Company:** BizSolutions 360, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $101,563.0 - $122,313.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, SC Clearance, Information Technology, Servicenow, Plan of Action and Milestones - **Published:** August 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b6b2d8a314a494f4 ## About the Role The solicitation does not prescribe a specific degree, certification, or minimum number of years. B360 will give preference to candidates with: * Bachelor's degree in cybersecurity, information technology, computer science, engineering, information systems, or a related discipline. * CISSP, CISM, CGRC, CAP, CASP+, GSLC, CCSP, or comparable advanced cybersecurity certification. * Experience supporting a federal civilian agency. * Experience leading authorization activities for Microsoft Azure Government, Microsoft 365 GCC/GCC High, ServiceNow, or similar FedRAMP-authorized environments. * Experience developing executive cybersecurity dashboards and presenting risk information to senior federal stakeholders. * Current or recent Tier 4 Public Trust, Secret clearance, or comparable federal suitability determination.Key Personnel Requirement This position is designated as Key Personnel. The selected candidate's resume, certifications, technical qualifications, availability, and suitability may be submitted to the Government for evaluation and approval. Replacement or material reduction of the candidate's role after award may require prior written Government approval. ## Description * Serve as B360's single point of accountability for technical execution of ISSO support services. * Manage day-to-day work performed by the ISSO team. * Serve as the primary Contractor technical interface with the Government ISSM, CISO, Authorizing Official, AODR, System Owners, assessors, Common Control Providers, Privacy Office, and other cybersecurity stakeholders. * Direct and coordinate ISSO activities across supported information systems. * Assign work and provide technical supervision to Senior ISSOs. * Maintain continuity of ISSO coverage across planned absences, vacancies, surge periods, and security-processing delays. * Oversee RMF, authorization, reauthorization, and ongoing-authorization activities. * Review and quality-control authorization-package artifacts before Government submission. * Support development and maintenance of System Security Plans, control implementations, assessment evidence, security assessments, authorization packages, continuous-monitoring artifacts, and related security documentation. * Chair internal technical and quality reviews of ISSO deliverables. * Maintain Contractor risk, issue, action-item, and deliverable registers. * Escalate cybersecurity, authorization, compliance, staffing, quality, and schedule risks. * Lead continuous-monitoring, vulnerability-management, POA&M, security-impact-analysis, audit-support, and compliance workstreams. * Participate in cybersecurity governance forums, including change-control, enterprise-review, risk-management, privacy, and cybersecurity steering activities. * Support incident-response coordination, situation reporting, evidence preservation, corrective-action tracking, and root-cause-analysis activities. * Coordinate with technical teams responsible for vulnerability remediation without assuming final Government risk-acceptance or POA&M-closure authority. * Prepare and review dashboards, metrics, briefings, authorization-status reports, cybersecurity posture information, vulnerability trends, POA&M status, and executive-level recommendations. * Ensure cybersecurity artifacts remain accurate, complete, current, professionally prepared, traceable, and audit-ready. * Coordinate with B360 program management regarding staffing, reporting, invoicing, performance, quality, and contract administration. * Maintain hands-on technical involvement and not operate solely as an administrative manager. The Lead ISSO is expected to maintain availability, personally or through an approved designated Alternate, during DFC core business hours of 7:00 AM to 6:00 PM Eastern Time, Monday through Friday, excluding federal holidays.Preferred Qualifications ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)