> Markdown version of [/jobs/ext/2723304-lead-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2723304-lead-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Information System Security Officer - **Company:** Momentum Engineering - **Location:** Washington, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Cyber Security, Information Systems, Decision Support Systems, Information Security Management, Zero Trust Network Access, Software Vulnerability Management, SARS Software Products, Information Technology, Splunk, Qualys, Servicenow, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/e9611c28-1713-4fd4-83f5-cd7844c8b1ed ## About the Role * U.S. Citizenship required. * Ability to obtain and maintain a Tier 4 High-Risk Public Trust. * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field. * 10+ years of cybersecurity experience * 5+ years supporting Federal RMF programs * Experience supporting FISMA Moderate or High environments * Experience supporting ATO and continuous authorization efforts * Experience managing POA&M programs and vulnerability remediation tracking * Experience supporting cybersecurity audits and assessment activities * Experience developing SSPs and authorization package documentation * Experience briefing senior leadership and governance boards ## Description Momentum Engineering, Inc. fosters an employee-centric culture. Our strength lies in our people. With a high percentage of employees holding advanced degrees in engineering, computer science, and related disciplines, we bring deep technical expertise to every mission. Our team includes professionals with security clearances and full-scope polygraphs, ensuring trusted, secure support for the most sensitive national security initiatives. Additionally, our workforce is equipped with industry-leading certifications, demonstrating a commitment to continuous learning and excellence. Most importantly, our exceptional employee retention rate reflects a culture of professional growth, mission focus, and dedication-ensuring long-term stability and expertise for our customers' critical needs., * Seeking a highly experienced Lead Information System Security Officer (Lead ISSO) to support a Federal cybersecurity program responsible for authorization support, continuous monitoring, cybersecurity governance, audit readiness, and security compliance activities across a complex hybrid-cloud environment * The Lead ISSO serves as the primary technical and operational cybersecurity lead responsible for coordinating Risk Management Framework (RMF) activities, supporting Authorization to Operate (ATO) efforts, maintaining cybersecurity artifacts, facilitating governance activities, and providing cybersecurity decision support to Federal stakeholders * This position requires significant experience leading cybersecurity compliance, governance, risk management, and continuous monitoring activities within Federal environments Primary Responsibilities * Lead execution of RMF activities across the system lifecycle * Support ATO, reauthorization, and ongoing authorization activities * Develop, maintain, and review System Security Plans (SSPs), POA&Ms, SARs, SAPs, and supporting authorization artifacts * Coordinate with ISSMs, System Owners, Authorizing Officials, assessors, and program stakeholders * Lead continuous monitoring and cybersecurity posture management activities * Support cybersecurity governance boards, change-control activities, and security reviews * Oversee vulnerability management reporting, remediation tracking, and POA&M governance * Develop executive-level briefings, dashboards, metrics, and cybersecurity status reports * Support audits, assessments, FISMA reviews, and compliance reporting activities * Ensure cybersecurity artifacts remain accurate, current, auditable, and traceable * Lead risk identification, issue management, corrective actions, and escalation activities * Maintain audit-ready evidence repositories and documentation, + Security+ + CGRC (formerly CAP) * Desired technical experience: * + CSAM + ServiceNow + Splunk + Tenable + Qualys + Microsoft Azure + Microsoft 365 + Entra ID + Zero Trust initiatives ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)