> Markdown version of [/jobs/ext/279232-information-system-security-officer-isso-iscm-lead-hybrid](https://www.wearedevelopers.com/jobs/ext/279232-information-system-security-officer-isso-iscm-lead-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) / ISCM Lead - Hybrid - **Company:** BOMBEAZY, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $200,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Cloud Computing Security, Configuration Management, CompTIA Security+, Cyber Security, Disaster Recovery, Information Security Management, Information Systems Security Architecture Professional, Software Vulnerability Management, SARS Software Products, Information Technology, RSA Archer Platform - **Published:** May 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8e8f43197e3c7766 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, Computer Science, or related field (or equivalent professional experience). * 5+ years of experience supporting information security, ISSO functions, RMF, A&A, compliance, or ISCM programs. * Strong knowledge of the Risk Management Framework (RMF), NIST standards, and federal cybersecurity compliance requirements. * Experience managing security authorization packages and ongoing authorization activities. * Experience maintaining and updating security documentation and artifacts. * Familiarity with governance, risk, and compliance (GRC) platforms such as Xacta or equivalent tools. * Experience supporting FISMA, OIG, or similar audit and assessment activities. * Understanding of security controls, vulnerability management, configuration management, and risk assessment methodologies. * Strong analytical, organizational, and communication skills. * Ability to coordinate across technical, operational, and business stakeholders., * Experience supporting federal or highly regulated environments. * Familiarity with NIST SP 800-37, NIST SP 800-53, and related cybersecurity frameworks. * Experience with continuous monitoring technologies and compliance automation tools. * Knowledge of cloud security, hybrid environments, and enterprise infrastructure security. * Experience supporting contingency planning, disaster recovery, and incident response coordination. Preferred Certifications Candidates should possess one or more of the following certifications: * Certified Information Systems Security Professional (CISSP) * Certified Information Security Manager (CISM) * Certified Authorization Professional (CAP) * CompTIA Security+ * Systems Security Certified Practitioner (SSCP) Core Competencies * Risk Management Framework (RMF) * Information Security Continuous Monitoring (ISCM) * Assessment & Authorization (A&A) * Security Compliance & Governance * Security Documentation Management * Internal Controls Assessment * Risk & Configuration Management * Audit Coordination & Evidence Collection * Stakeholder Collaboration * Cybersecurity Operations & Oversight ## Description The Information System Security Officer (ISSO) / Information Security Continuous Monitoring (ISCM) Lead is responsible for the strategic coordination and operational execution of security compliance, authorization support, and the enterprise Information Security Continuous Monitoring (ISCM) program. This role leads the implementation and sustainment of the Risk Management Framework (RMF) and Assessment & Authorization (A&A) lifecycle activities to ensure systems maintain ongoing authorization and compliance with federal and organizational cybersecurity requirements. The ISSO/ISCM Lead is responsible for maintaining and continuously updating all required security documentation and artifacts, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Disaster Recovery Plans (DRPs), contingency documentation, inventories, and related authorization artifacts to accurately reflect the current operational environment. This role serves as the primary liaison between business stakeholders, system owners, technical teams, and the Office of the CISO to coordinate security compliance activities, manage ongoing authorization efforts, support internal and external audits, and ensure all configuration deviations, failed settings, accepted risks, and POA&M items are formally documented and tracked within the system authorization boundary and governance/risk/compliance (GRC) platforms. Key ResponsibilitiesSecurity Compliance & Authorization Management * Lead the strategic and day-to-day execution of security compliance, authorization, and ongoing authorization activities. * Manage and oversee the implementation of the Risk Management Framework (RMF) and Assessment & Authorization (A&A) lifecycle processes. * Coordinate the development, maintenance, review, and update of security authorization documentation and artifacts, including: * System Security Plans (SSPs) * Configuration Management Plans (CMPs) * Disaster Recovery Plans (DRPs) * Contingency Plans * Security Assessment Reports (SARs) * Risk Assessments * POA&Ms * Security inventories and supporting documentation * Ensure all security documentation accurately reflects the current operational and technical environment. * Support ongoing authorization activities through continuous assessment, monitoring, and remediation coordination. Information Security Continuous Monitoring (ISCM) * Lead the execution and maturity of the Information Security Continuous Monitoring (ISCM) program. * Coordinate proactive internal controls testing and internal Security Control Assessments (SCAs) to validate the effectiveness of implemented security controls. * Monitor control implementation status and coordinate remediation activities for identified deficiencies and vulnerabilities. * Ensure continuous monitoring results, findings, and corrective actions are documented and tracked appropriately. Risk & Configuration Management * Manage the end-to-end lifecycle of: * Plans of Action and Milestones (POA&Ms) * Risk acceptance decisions * Configuration deviations * Failed configuration settings * Technical exceptions and mitigation plans * Ensure all deviations, accepted risks, and configuration-related findings are explicitly documented and tracked within the system authorization boundary and GRC platforms (e.g., Xacta or equivalent tools). * Collaborate closely with ISSO personnel, Security Engineers, system owners, and operational teams to ensure configuration and compliance data remain accurate and current. Stakeholder Coordination & Audit Support * Serve as the primary liaison between business functions, system stakeholders, and the Office of the CISO for security compliance and authorization activities. * Coordinate weekly security and compliance meetings to review system risks, POA&M status, audit findings, remediation efforts, and ongoing authorization activities. * Support internal and external audit activities, including FISMA, OIG, and other oversight reviews. * Manage the collection, validation, and submission of audit and assessment artifacts to ensure evidence meets quality and oversight standards. * Coordinate with stakeholders responsible for security, privacy, technology, engineering, and operations to support enterprise compliance initiatives. Security Engineering & Control Oversight * Collaborate with Security Engineers and technical teams to validate implementation and effectiveness of security controls. * Support review of system categorizations, control implementations, and risk-based security decisions. * Assist in identifying opportunities to improve security posture, automation, monitoring, and compliance processes. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)