Xtreme Solutions is seeking an experienced
Lead Information System Security Officer (ISSO) / Technical Program Lead to provide technical leadership and hands-on cybersecurity support for a federal customer in Washington, DC.
This is an opportunity for an accomplished federal cybersecurity professional who can lead an ISSO team while remaining deeply involved in RMF, authorization, continuous monitoring, vulnerability management, and security-risk decisions.
The ideal candidate has led complex federal authorization activities, can review and challenge technical cybersecurity deliverables, and is comfortable briefing senior Government stakeholders on system risk, authorization status, vulnerabilities, and remediation priorities.
What You'll Do- Lead day-to-day technical activities across the ISSO team.
- Assign systems, authorization boundaries, and security workstreams.
- Oversee multiple concurrent RMF authorization and reauthorization activities.
- Review and approve SSPs, SAPs, SARs, POA&Ms, risk assessments, Continuous Monitoring Plans, SIAs, and authorization packages.
- Perform technical QA/QC before cybersecurity deliverables are submitted to the Government.
- Track authorization milestones, dependencies, risks, issues, and corrective actions.
- Oversee POA&M, vulnerability-remediation, and continuous-monitoring activities.
- Coordinate with AOs/AODRs, the CISO, ISSMs, System Owners, assessors, privacy teams, Common Control Providers, and technical remediation teams.
- Resolve conflicting or incomplete cybersecurity information across tools, artifacts, and system records.
- Provide senior-level security posture, authorization, and risk briefings.
- Mentor and provide technical direction to ISSOs, assessors, and cybersecurity analysts.
- Support federal audits and independent security-control assessments.
Requirements
Must-Have Qualifications- 10+ years of progressively responsible cybersecurity experience.
- 7+ years supporting federal ISSO, IA, A&A/C&A, or RMF activities.
- 3+ years leading ISSOs, Security Control Assessors, cybersecurity analysts, or federal authorization workstreams.
- Demonstrated experience managing multiple federal systems or authorization boundaries concurrently.
- Advanced knowledge of NIST SP 800-37 and NIST SP 800-53.
- Hands-on experience reviewing federal RMF and authorization artifacts.
- Experience coordinating with senior federal cybersecurity stakeholders.
- Experience performing technical QA/QC of cybersecurity deliverables.
- Strong executive briefing and written communication skills.
- CISSP, CISM, CGRC/CAP, or GSLC required.
Preferred Qualifications- Experience with CSAM or another federal GRC platform.
- Experience with ServiceNow and federal ITSM workflows.
- FedRAMP and federal cloud-security experience.
- Experience with NIST SP 800-137 continuous monitoring.
- Current or recent Tier 4 or Tier 5 investigation.
- Experience supporting FISMA, IG, GAO, CISA, or similar federal assessments.