Lead Information System Security Officer (ISSO) - CISSP

IBSS

• $140K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, IT, computer science, or related field, or equivalent experience.
  • Certified Information Systems Security Professional (CISSP) certification required.
  • Significant experience in cybersecurity risk management and compliance for federal systems, ideally in a senior ISSO role.
  • Advanced knowledge of FISMA, NIST RMF, and federal A&A processes, including NIST SP 800-37 and 800-53 Rev. 5.
  • Demonstrated experience with FedRAMP requirements and cloud service evaluations.
  • Proficient in developing federal cybersecurity documentation and using governance platforms like JCAM/CSAM.
  • Experience in vulnerability assessments and remediation validation.

Responsibilities

  • Lead cybersecurity activities throughout the NIST Risk Management Framework lifecycle.
  • Coordinate Assessment and Authorization activities, applying relevant cybersecurity frameworks and standards.
  • Advise stakeholders on security requirements, deficiencies, and remediation options.
  • Develop and maintain comprehensive cybersecurity documentation, including System Security Plans and risk assessments.
  • Execute continuous monitoring activities, assessing vulnerabilities and compliance.
  • Mentor less-experienced ISSOs and provide technical guidance on complex cybersecurity issues.
  • Support cybersecurity incident investigations and incorporate lessons learned into risk management.

Benefits

  • Medical, dental, vision, and prescription drug coverage with a company-paid deductible.
  • Paid time off and federal holidays.
  • Matching 401K plan.
  • Tuition and professional development reimbursement.
  • Flex-Spending (FSA) and Dependent Care Account (DCA) options.
Full Job Description
Job Title: Lead Information System Security Officer (ISSO) - CISSP
Location: Silver Spring, MD (downtown)
Clearance Required: Must be able to obtain a Public Trust Clearance
Salary Range: $140K-$150K (based on experience)
Application Deadline: October 31, 2026

To apply, please follow these steps:
  • Visit https://ibsscorp.com/careers
  • Select the position you are interested in
  • Review the job details, then click Apply Now
  • Complete and submit your application

Description:

The Lead Information System Security Officer (Lead ISSO) provides senior-level cybersecurity risk management, security authorization, assessment, and continuous monitoring support for a complex federal information system. The Lead ISSO serves as a senior cybersecurity advisor while remaining directly responsible for cybersecurity activities and work products associated with assigned system responsibilities.

The Lead ISSO also serves as a senior technical point of contact for the ISSO team, providing guidance on complex or unfamiliar cybersecurity matters and mentoring less-experienced ISSOs. This is a hands-on cybersecurity role requiring the ability to independently perform complex security analysis while providing technical guidance to other team members as needed.

The environment is geographically distributed and includes maritime and aviation platforms, land-based facilities, remotely deployed technologies, networked sensors and computing devices, public-facing applications, on-premises infrastructure, and FedRAMP-authorized Microsoft Azure services. The system is categorized as FIPS 199 Moderate and processes multiple forms of sensitive information.

Key Responsibilities:
• Lead and perform cybersecurity activities throughout the NIST Risk Management Framework (RMF) lifecycle, including system categorization, security control implementation, assessment, authorization, and continuous monitoring.
• Coordinate and support Assessment and Authorization (A&A) activities and apply the NIST Cybersecurity Framework (CSF), RMF, FISMA, NIST publications, FIPS standards, FedRAMP requirements, and organizational cybersecurity policies to system security activities.
• Advise system owners, engineers, administrators, and other stakeholders regarding security requirements, control implementation, identified deficiencies, remediation options, residual risk, and the cybersecurity implications of system changes.
• Develop, maintain, and update cybersecurity documentation, including System Security Plans (SSPs), Concepts of Operations (CONOPS), system boundary and architecture diagrams, Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), risk assessments, inventories, interconnection documentation, and continuous monitoring records.
• Work with system engineers, administrators, application owners, and other subject matter experts to ensure security documentation accurately reflects the operational environment and implemented controls.
• Lead and support security control assessments and evaluate technical, operational, and procedural evidence to determine whether controls are implemented correctly, operating as intended, and achieving required security outcomes.
• Execute continuous monitoring activities, including monitoring security control status, vulnerabilities, configuration compliance, security findings, system and cloud changes, and other risk indicators.
• Develop and maintain POA&Ms, coordinate corrective actions, evaluate remediation evidence, and determine whether identified deficiencies have been sufficiently addressed before recommending closure.
• Perform and analyze vulnerability and configuration assessments using automated vulnerability scanners, SCAP-compatible technologies, configuration assessment tools, and other security testing mechanisms. Evaluate findings based on technical and operational risk and validate remediation through rescanning, testing, configuration review, or supporting evidence.
• Assess Identity, Credential, and Access Management (ICAM) controls, including authentication, authorization, privileged access, role-based access control, least privilege, multi-factor authentication, account management, and applicable federal Zero Trust requirements and principles.
• Assess cryptographic protections, including encryption at rest and in transit, Public Key Infrastructure (PKI), digital certificates, trust relationships, authentication mechanisms, and applicable FIPS-validated cryptographic capabilities.
• Apply FedRAMP requirements when evaluating cloud services and system components operating within authorized cloud environments, including Microsoft Azure.
• Evaluate cloud security controls, configurations, authorization documentation, continuous monitoring information, and the allocation of security responsibilities among the system, cloud service provider, and other control providers, including inherited, shared, and system-specific controls.
• Assess cloud service changes, new services, architectural modifications, cloud findings, and changes to inherited controls for potential impact on system risk and authorization.
• Assess cybersecurity controls for networks, endpoints, servers, applications, databases, sensors, and other infrastructure, including network segmentation, firewalls, remote access, system interconnections, logging, and security monitoring.
• Support cybersecurity incident investigation, documentation, remediation, and post-incident activities and incorporate relevant lessons learned into risk-management and continuous monitoring activities.
• Assess cybersecurity risks associated with vendors, service providers, software, hardware, cloud services, and other external technology dependencies, including cybersecurity supply chain and third-party risk.
• Assess security controls protecting Personally Identifiable Information (PII), medical information, personnel information, administrative information, security audit data, and other sensitive information.
• Serve as a senior technical point of contact and escalation resource for the ISSO team, providing guidance on complex or ambiguous RMF, A&A, FedRAMP, security control, vulnerability, evidence, and risk-management matters.
• Mentor less-experienced ISSOs through knowledge sharing, explanation of analytical approaches, and guidance provided as issues arise during the performance of assigned responsibilities. Provide targeted review of analyses or work products when necessary to resolve significant technical questions or support mentoring.

Required Skills /Education/ Certifications & Qualifications:
  • Bachelor's degree in cybersecurity, information technology, computer science, information systems, engineering, or a related discipline, or an equivalent combination of education and relevant professional experience.
  • Certified Information Systems Security Professional (CISSP) certification.
  • Significant experience performing cybersecurity risk management, assessment, compliance, or authorization activities for federal information systems, including experience in a senior ISSO, senior cybersecurity, or comparable technical GRC capacity.
  • Advanced knowledge and practical experience with FISMA, the NIST Risk Management Framework, federal A&A processes, NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FIPS 199/200, POA&M management, and continuous monitoring.
  • Demonstrated FedRAMP knowledge and experience, including security requirements, authorization concepts, control inheritance, shared security responsibilities, cloud authorization documentation, and continuous monitoring.
  • Experience supporting federal information systems that use FedRAMP-authorized cloud services and evaluating cloud services and inherited controls within a system authorization boundary.
  • Experience assessing security controls and independently evaluating technical and non-technical evidence for sufficiency, credibility, implementation, and effectiveness.
  • Experience developing and maintaining federal cybersecurity authorization documentation and using JCAM/CSAM or comparable federal cybersecurity governance, risk, and compliance platforms.
  • Experience performing and analyzing vulnerability and configuration assessments, coordinating remediation, and validating corrective actions.
  • Working knowledge of cloud and network security, ICAM, PKI and cryptography, vulnerability management, configuration management, security monitoring, incident response, Zero Trust principles, and Cybersecurity Supply Chain Risk Management (C-SCRM).
  • Experience providing technical guidance to cybersecurity personnel and mentoring less-experienced cybersecurity professionals.
  • Ability to analyze complex or ambiguous cybersecurity issues, translate requirements into actionable technical and operational requirements, and communicate risk effectively to technical personnel, system owners, management, assessors, and other stakeholders.


Desired Skills:
  • Experience supporting FIPS 199 Moderate federal information systems and geographically distributed or remotely deployed environments.
  • Experience with Microsoft Azure, FedRAMP-authorized cloud services, hybrid cloud environments, FedRAMP authorization packages, continuous monitoring information, and security control inheritance.
  • Experience with enterprise identity and security technologies, including Microsoft Active Directory, CAC/PIV, multi-factor authentication, PKI, digital certificates, SIEM, Endpoint Detection and Response (EDR), and centralized security monitoring.
  • Experience with vulnerability scanning, SCAP-compatible assessment technologies, secure configuration assessment, and remediation validation.
  • Experience with network security technologies and concepts, including segmentation, VLANs, firewalls, remote connectivity, and system interconnections.
  • Experience with FIPS-validated encryption, databases, web applications, and protection of PII and other sensitive federal information.
  • Experience with third-party risk management and Cybersecurity Supply Chain Risk Management.
  • Experience supporting maritime, aviation, scientific, sensor, or comparable operational environments.
  • CompTIA Security+, Certified Information Security Manager (CISM), cloud security, Microsoft Azure security, or other relevant cybersecurity, cloud security, security assessment, or risk-management certifications.

IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.

Similar Jobs

More Jobs at IBSS

More Information Technology Jobs

Find similar Lead Information System Security Officer (ISSO) - CISSP jobs: