Lead Information System Security Officer

Momentum Engineering
Washington, United States
1 day ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Cyber Security Information Systems Decision Support Systems Information Security Management Zero Trust Network Access Software Vulnerability Management SARS Software Products Information Technology Splunk Qualys
+2 more
Servicenow Plan of Action and Milestones

Job description

Momentum Engineering, Inc. fosters an employee-centric culture. Our strength lies in our people. With a high percentage of employees holding advanced degrees in engineering, computer science, and related disciplines, we bring deep technical expertise to every mission. Our team includes professionals with security clearances and full-scope polygraphs, ensuring trusted, secure support for the most sensitive national security initiatives. Additionally, our workforce is equipped with industry-leading certifications, demonstrating a commitment to continuous learning and excellence. Most importantly, our exceptional employee retention rate reflects a culture of professional growth, mission focus, and dedication-ensuring long-term stability and expertise for our customers’ critical needs., * Seeking a highly experienced Lead Information System Security Officer (Lead ISSO) to support a Federal cybersecurity program responsible for authorization support, continuous monitoring, cybersecurity governance, audit readiness, and security compliance activities across a complex hybrid-cloud environment

  • The Lead ISSO serves as the primary technical and operational cybersecurity lead responsible for coordinating Risk Management Framework (RMF) activities, supporting Authorization to Operate (ATO) efforts, maintaining cybersecurity artifacts, facilitating governance activities, and providing cybersecurity decision support to Federal stakeholders
  • This position requires significant experience leading cybersecurity compliance, governance, risk management, and continuous monitoring activities within Federal environments

Primary Responsibilities

  • Lead execution of RMF activities across the system lifecycle
  • Support ATO, reauthorization, and ongoing authorization activities
  • Develop, maintain, and review System Security Plans (SSPs), POA&Ms, SARs, SAPs, and supporting authorization artifacts
  • Coordinate with ISSMs, System Owners, Authorizing Officials, assessors, and program stakeholders
  • Lead continuous monitoring and cybersecurity posture management activities
  • Support cybersecurity governance boards, change-control activities, and security reviews
  • Oversee vulnerability management reporting, remediation tracking, and POA&M governance
  • Develop executive-level briefings, dashboards, metrics, and cybersecurity status reports
  • Support audits, assessments, FISMA reviews, and compliance reporting activities
  • Ensure cybersecurity artifacts remain accurate, current, auditable, and traceable
  • Lead risk identification, issue management, corrective actions, and escalation activities
  • Maintain audit-ready evidence repositories and documentation, + Security+
  • CGRC (formerly CAP)
  • Desired technical experience: *

  • CSAM
  • ServiceNow
  • Splunk
  • Tenable
  • Qualys
  • Microsoft Azure
  • Microsoft 365
  • Entra ID
  • Zero Trust initiatives

Requirements

  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 4 High-Risk Public Trust.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field.
  • 10+ years of cybersecurity experience
  • 5+ years supporting Federal RMF programs
  • Experience supporting FISMA Moderate or High environments
  • Experience supporting ATO and continuous authorization efforts
  • Experience managing POA&M programs and vulnerability remediation tracking
  • Experience supporting cybersecurity audits and assessment activities
  • Experience developing SSPs and authorization package documentation
  • Experience briefing senior leadership and governance boards

Benefits & conditions

Exempt hourly position. 11 paid holidays, minimum of 3 weeks PTO, company sponsored group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is dependent upon the candidate’s experience and qualifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all