> Markdown version of [/jobs/ext/575622-chief-information-security-officer-ciso-includes-isso-responsibilities](https://www.wearedevelopers.com/jobs/ext/575622-chief-information-security-officer-ciso-includes-isso-responsibilities). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) (includes ISSO responsibilities) - **Company:** 911INFORM LLC - **Location:** Wall Township, NJ, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Microsoft Access, Microsoft Windows, Amazon Web Services, JIRA, Software as a Service, Cyber Security, MongoDB, Systems Development Life Cycle, Security Information and Event Management, Data Management - **Published:** June 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7f4546883a62a49b ## About the Role Do you have experience in Tooling?, 10+ years in information security, with 3+ years in a leadership role (CISO, Deputy CISO, Director of Security, or equivalent). Demonstrated experience taking a SaaS product through FedRAMP Moderate (authorization or ConMon). Deep working knowledge of NIST 800-53 Rev. 5, FedRAMP, SOC 2 Type II, ISO 27001, and CJIS (preferred for public safety). Hands-on competence with AWS GovCloud + Commercial, Microsoft 365 GCC, and modern security tooling (EDR, SIEM, VM, GRC). Proven ability to operate as a player-coach - comfortable writing an SSP narrative one hour and presenting to the board the next. Excellent executive communication; able to translate technical risk into business language. Preferred Qualifications CISSP, CISM, or CCISO; additional certs (CCSP, CISA, CRISC) a plus. Prior experience as an ISSO, ISSM, or FedRAMP program lead. Experience with MongoDB Atlas for Government, CrowdStrike NGSIEM, Tenable, Action1, and Vanta. Background in 9-1-1, public safety, telecom, or critical infrastructure SaaS. Experience scaling a security team from 1 * 5+ FTEs. Success in the First 12 Months 90 days: Full ownership of SSP, ConMon cadence, and POA&M; clean audit evidence pipeline. 6 months: SOC 2 Type II and ISO 27001 cycles delivered without material findings; cyber insurance renewed. 12 months: Security roadmap approved by exec team; ISSO backfill hired; measurable reduction in critical POA&M aging. ## Description 911inform is hiring a Chief Information Security Officer (CISO) to lead our security, compliance, and risk program across our FedRAMP Moderate, SOC 2, and ISO 27001 environments. This is a player-coach role: the CISO sets strategy and personally owns ISSO-level execution until the program scales. You will be the executive accountable for the security of a SaaS platform protecting public-safety customers, with direct ownership of FedRAMP ConMon, board-level risk reporting, and the security roadmap. Strategic / Executive Responsibilities Security Strategy & Roadmap - Define and execute the multi-year security strategy aligned to 911inform's FedRAMP Moderate authorization, customer commitments, and growth plans. Executive & Board Reporting - Present security posture, risk register, and incident metrics to the CEO, CFO, and board; own cyber insurance renewal (currently trending to $10M+). Risk Management - Own the enterprise risk register; ensure critical and accepted risks route to the CFO per internal policy. Regulatory & Customer Assurance - Serve as the executive face of security for federal, state, and enterprise customers; lead responses to RFP security questionnaires and customer audits. Program Leadership - Build and mentor the security function (starting with the ISSO role embedded in this position); set hiring plan as the program matures. Incident Command - Serve as Incident Commander for Sev-1/Sev-2 security incidents; own external notifications, legal coordination, and post-incident reporting. Vendor & M&A Diligence - Lead security diligence on strategic vendors, partners, and any acquisition/integration activity. Budget Ownership - Own the security budget, tooling rationalization, and ROI justification. ISSO / Hands-On Responsibilities (performed directly until backfilled) Maintain the FedRAMP Moderate SSP, appendices, and supporting artifacts. Run monthly ConMon: Tenable scans, POA&M updates, inventory, and significant change requests. Drive POA&M remediation within FedRAMP timelines and document deviations. Lead SOC 2 Type II and ISO 27001 audit cycles end-to-end, including evidence packaging. Conduct or oversee quarterly access reviews across AWS GovCloud/Commercial, M365 GCC, MongoDB Atlas for Government, CrowdStrike, Tenable, Action1, Jira, and other in-boundary systems. Maintain and exercise the Incident Response Plan; run annual tabletop exercises and document evidence. Own third-party risk management: vendor onboarding, DPA/SLA review, risk register, and CFO routing for critical risks. Author and maintain core security policies: Access Control, Privileged Access, Data Management, IR, Secure SDLC, Third-Party Management. Oversee endpoint and vulnerability platforms (CrowdStrike, Tenable, Action1) - including coverage validation and agent troubleshooting escalations. ## Related Videos - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)