We offer a Full Benefits package including:- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
Lead ISSO / Technical Program Lead- Must be a United States citizen.
- Must be eligible for a Tier 4 High-Risk Public Trust investigation.
- Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Role:Serve as Chameleon's single point of accountability for technical execution of the DFC ISSO program. The Lead ISSO will direct day-to-day work, assign systems and workstreams, oversee authorization packages, chair internal deliverable reviews, manage technical risks and issues, and represent Chameleon before the DFC ISSM, CISO, AO/AODR, System Owners, assessors, and cybersecurity governance bodies. This is a hands-on senior cybersecurity position.
It is not a purely administrative program manager role. The candidate must be capable of personally reviewing RMF artifacts, identifying technical and documentation defects, resolving conflicting security records, and defending recommendations before senior federal officials.
Minimum Requirements:- At least 10 years of progressively responsible cybersecurity experience.
- At least 7 years supporting federal ISSO, information assurance, assessment and authorization, C&A, or RMF activities.
- At least 3 years leading ISSOs, security control assessors, cybersecurity analysts, or authorization workstreams.
- Led or materially directed authorization support for multiple systems or authorization boundaries concurrently.
- Direct experience with NIST SP 800-37 and NIST SP 800-53.
- Experience developing, reviewing, or approving:
- System Security Plans
- Security control implementation statements
- Security assessment plans and reports
- POA&M records
- Risk assessments
- Authorization decision packages
- Continuous Monitoring Plans
- Security impact analysis
- Experience coordinating with Authorizing Officials, ISSMs, System Owners, Common Control Providers, assessors, privacy personnel, and technical remediation teams.
- Experience overseeing deliverable quality before Government submission.
- Strong executive briefing and federal technical-writing skills.
- One senior cybersecurity certification:
- CISSP
- CISM
- CGRC, formerly CAP
- GSLC
- Bachelor's degree preferred. Extensive relevant federal RMF experience may substitute.
Competitive Differentiators:- Direct CSAM experience
- Civilian federal agency FISMA experience
- Responsibility for FISMA Moderate systems
- Azure Government, Microsoft 365 GCC, or GCC High experience
- FedRAMP customer-responsibility and inherited-control analysis
- Experience with ServiceNow, Splunk, Tenable, Qualys, Microsoft Defender, Entra ID, Okta, Palo Alto, or Zscaler
- Experience supporting Inspector General, GAO, OMB CyberStat, CISA, or independent security-control assessments
- Current Tier 4 or Tier 5 suitability
- CISSP plus CGRC
- Experience managing 20 or more systems or several simultaneous authorization events
- Experience producing executive cybersecurity dashboards and quarterly risk briefings
The resume must clearly identify:- Number and type of systems supported
- FIPS 199 or comparable impact levels
- Candidate's authority and leadership responsibilities
- RMF steps personally performed or directed
- Authorization artifacts personally authored, reviewed, or approved for submission
- GRC tools used
- Number of ATOs, reauthorizations, assessments, or authorization packages supported
- POA&M and continuous-monitoring responsibilities
- Audit and assessment support
- Quantifiable quality, schedule, closure, or acceptance results