Job Title: Lead ISSO (Information System Security Officer)
Location: Washington, DC (Hybrid 3-days onsite; core hours 7:00 AM to 6:00 PM ET)
Clearance Required: Must be able to obtain and maintain a Tier 4 High-Risk Public Trust
Salary: $120K-140K
Application Deadline: July 31, 2026
To apply, please follow these steps:
- Visit https://ibsscorp.com/careers/
- Select the position you are interested in
- Review the job details, then click Apply Now
- Complete and submit your application
Description:BackgroundIBSS supports a U.S. federal agency's cybersecurity program in Washington, DC, providing Information System Security Officer (ISSO) support across the system authorization lifecycle. The environment is a hybrid, Zero-Trust-aligned Microsoft Azure and Microsoft 365 enterprise supporting approximately 800 users and 32 information systems operating under FISMA, OMB Circular A-130, and applicable NIST guidance. Authorization artifacts are maintained in a Governance, Risk, and Compliance (GRC) system of record; security telemetry is centralized in a SIEM; and IT service management runs on an enterprise ITSM platform. These roles deliver RMF and authorization support, continuous monitoring, vulnerability and POA&M execution, security documentation, security impact analysis, incident-response coordination, and audit and compliance support - advising and preparing while the Government retains all authorization and risk decisions.
The Lead ISSO is the single point of technical accountability for the ISSO support team, the primary technical interface to the Government ISSM, CISO, AO/AODR, and System Owners, and a hands-on cybersecurity practitioner (not solely an administrative manager).
Responsibilities:1. Program leadership and governance• Serve as the single point of technical accountability; direct day-to-day ISSO support activities across all supported systems.
• Interface with the Government ISSM, CISO, AO/AODR, System Owners, and Common Control Providers; participate in agency cybersecurity governance forums.
• Manage the team's risk and issue registers; oversee quality review of ISSO deliverables before Government submission.
2. RMF and authorization support• Lead development, review, and submission of authorization-package artifacts (System Security Plans, control implementation and inheritance, assessment evidence) within the GRC system of record.
• Coordinate authorization and ongoing-authorization activities with assessors and Authorizing Officials.
3. Continuous monitoring, vulnerability, and POA&M• Oversee continuous monitoring and security-posture reporting reconciled to SIEM telemetry and GRC records.
• Oversee vulnerability management and POA&M execution, including remediation coordination and closure evidence.
4. Documentation, change, incident, and audit• Ensure security documentation is current, consistent, and audit-ready in the GRC system of record.
• Oversee security impact analyses and change coordination, incident-response coordination with the SOC and IR teams, and audit, assessment, and compliance support.
• Respect the advisory boundary: no ATO decisions, risk acceptance, or POA&M-closure approvals (reserved to the Government).
Education• Bachelor's degree with minimum 10-15 years of experience in cybersecurity, information technology, information systems, or a related field.
Key Technical Skills• Frameworks and policy: RMF (NIST SP 800-37), NIST SP 800-53 and 800-53A, NIST SP 800-137 (ConMon), FISMA, OMB Circular A-130, FIPS 199.
• GRC and authorization: CSAM (or comparable) as the authoritative system of record for SSPs, POA&Ms, control implementation and inheritance, and assessment evidence.
• Monitoring and vulnerability: Splunk (SIEM); Tenable Nessus or Qualys; Microsoft Defender for Endpoint/Identity/Cloud.
• Platforms and identity: Microsoft Azure and M365 (incl. Azure Government, GCC/GCC High), Entra ID, Okta; endpoint management (Intune, BigFix).
• ITSM and network: ServiceNow; Palo Alto Panorama; Zscaler.
Desired / Preferred Qualifications• Professional certifications such as CISSP, CGRC (formerly CAP), CISM, or equivalent.
• Prior experience as a federal ISSO or RMF lead supporting FISMA-Moderate systems and Authorization to Operate (ATO) activities.
• Hands-on experience with a federal GRC/authorization system of record (e.g., CSAM), Splunk, and Tenable Nessus or Qualys.
• Prior experience supporting a federal CFO Act agency or similar cybersecurity program.
IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.