Lead Information System Security Officer (ISSO)

E-Logic INC
Washington, DC, United States
28 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Antivirus Microsoft Azure Cloud Computing Cyber Security Information Security Management Zero Trust Network Access RSA (Cryptosystem) SAP (Applications) Security Information and Event Management Tenable Nessus RSA Archer Platform
+4 more
Splunk Qualys Servicenow Vulnerability Analysis

Job description

We are seeking an experienced and highly motivated Lead Information System Security Officer (ISSO) to support the U.S. International Development Finance Corporation (DFC). In this key leadership role, you will serve as the single point of accountability for all technical cybersecurity support services, managing a team of ISSOs and acting as the primary interface with senior federal officials, including the Information System Security Manager (ISSM), Chief Information Security Officer (CISO), and Authorizing Officials (AO). You will oversee the full lifecycle of cybersecurity support, ensuring compliance with the Risk Management Framework (RMF), NIST guidelines, and federal mandates. This is a senior-level position that requires a blend of hands-on technical expertise and strong program management skills., * Program Leadership: Manage the day-to-day execution of ISSO support activities, direct staff, and ensure consistent service delivery across all supported systems.

  • Government Liaison: Serve as the primary technical and operational interface with DFC federal leadership, including the ISSM, CISO, and System Owners.
  • RMF & Authorization: Oversee the development, quality control, and submission of critical authorization package artifacts (e.g., SSP, SAP, SAR) within the Cyber Security Assessment and Management (CSAM) tool.
  • Strategic Oversight: Chair internal quality reviews, manage the contractor risk/issue register, and represent the team in high-level DFC governance forums (e.g., Change Control Board, Enterprise Review Board).
  • Continuous Monitoring: Direct continuous monitoring and security posture management activities, ensuring alignment with DFC’s Zero Trust architecture and the agency’s ISCM strategy.

Requirements

  • Citizenship: Must be a U.S. Citizen.
  • Clearance: Must be eligible to obtain and maintain a Tier 4 High-Risk Public Trust background investigation.
  • Certifications: Must hold a relevant top-tier cybersecurity certification (e.g., CISSP, CISM, or equivalent).
  • Experience: Minimum of 8-10 years of progressive experience in cybersecurity, with at least 5 years in an ISSO or senior cybersecurity role managing RMF and federal compliance programs.
  • Technical Proficiency: Strong working knowledge of key security tools, including:
  • GRC Platforms (CSAM, RSA Archer, or similar).
  • SIEM Platforms (Splunk, Elastic, or similar).
  • Ticketing/ITSM (ServiceNow).
  • Vulnerability Scanners (Tenable Nessus, Qualys).
  • Cloud and Endpoint Security (Azure, Microsoft 365, Microsoft Defender).

Desired Experience:

  • Deep understanding of NIST SP 800-37 (RMF), NIST SP 800-53 (Security Controls), and FISMA compliance.
  • Experience supporting Authorization to Operate (ATO) processes for federal agencies.
  • Experience with FedRAMP and cloud shared-responsibility models.
  • Proven ability to manage and mentor a team of cybersecurity professionals.

Clearance Requirement: Must be eligible for a Tier 4 High-Risk Public Trust

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all