> Markdown version of [/jobs/ext/3347605-isso-lead-dos-css](https://www.wearedevelopers.com/jobs/ext/3347605-isso-lead-dos-css). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO Lead DoS CSS - **Company:** OneZero Solutions - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $116,350.0 - $210,325.0 - **Contract:** Permanent contract - **Skills:** Cascading Style Sheets (CSS), Collaborative Software, Cyber Security, Databases, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Data Flow Control, Microsoft Visio, Systems Development Life Cycle, Data Streaming, Information Technology, Software Version Control, Devsecops, Plan of Action and Milestones - **Published:** September 26, 2026 - **Apply:** https://www.careerjet.com/jobad/us849dcbf2cb21d1d9e9991c6cd9ced600 ## About the Role Data Flow Package, Control Tailoring Rationale, and Audit and Data Call Response Package.Chair Implementation Readiness Reviews prior to independent Security Control Assessments and oversee SCRM/demo preparation(RMF Steps 3-4).Oversee iPost risk-score management, ensure findings open more than 30 days are tracked and reported, and enforce BOD remediation timelines across the portfolio(RMF Step 6).Lead post-incident reviews for significant incidents and ensure outcomes flow into risk assessments, POA&Ms, SSPs, and control implementation statements.Mentor, coach, and quality-review the work of SME, Senior, and Information Assurance analysts; set technical priorities for the Tenable, Wiz/cloud, and DevSecOps engineers.Identify security requirements for new systems throughout the SDLC and DevSecOps pipelines; participate in the Risk Governance process.Required QualificationsEight (8)+ years of experience as an ISSO or in a similar Assessment & Authorization role (RFQ §M, Factor 2).Experience supporting 50 or more FISMA information systems.Demonstrated expertise with the NIST Risk Management Framework and FISMA compliance (NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, SP 800-60, FIPS 199/200).Current CISSP or CISM certification.Active, final SECRET security clearance; U.S. citizenship.Experience leading and quality-reviewing the work of other ISSOs or IA analysts.Experience using an enterprise GRC tool to manage authorization packages and POA&Ms.Available at the time of Call Order award and committed to the full base period of performance.Preferred QualificationsMaster's degree in a related field.Department of State experience (DT, CA, or CST), including ArchAngel and iPost.CGRC/CAP, CISA, or CRISC certification in addition to CISSP/CISM.Experience with High Value Asset (HVA) systems, cloud/hybrid authorization boundaries, FedRAMP inheritance, and zero-trust overlays.Experience leading teams of 10 or more cybersecurity professionals.Technical SkillsExpert: NIST SP 800-37, 800-53/53A/53B Rev. 5, 800-60, 800-34, 800-61, 800-63 (DIRA), FIPS 199/200; OMB A-130; CISA BODs.GRC platforms (ArchAngel or equivalent), iPost or comparable continuous-monitoring scoring, POA&M lifecycle management.Ability to interpret Tenable and Wiz vulnerability/compliance output, KEV and STIG results, and translate them into risk decisions.SSP, SAR, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring; Visio data-flow and boundary diagrams.EducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field is requiredRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.Position Status:New Position, contingent upon Call Order awardOneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.Job Posted by ApplicantPro ## Description and risk management activity.Maintain version control of RMF artifacts and prepare briefings and reports for the ISSM, AO/AODR, and CST leadership.Assign systems to ISSO staff and balance workloads so that every current and future CA system completes the full RMF (Steps 1-6) at least every three years and maintains its ATO.Serve as senior escalation point for categorization, control tailoring, inherited-controls, and POA&M risk-rating decisions; review Security Plan Approval Recommendation Letters and AODR Information Sheets before release(RMF Steps 2 and 5).Provide direction and oversight to system-specific security operations contractors (database, application, and platform security operations) to obtain evidence and drive remediation, ensuring they do not independently develop authoritative RMF artifacts.Lead quarterly FISMA metrics submissions and support the Annual FISMA Review.Standardize and govern program-wide artifacts: Evidence Index, Inherited Controls Matrix, System Boundary &