Lead Senior Information Systems Security Officer (ISSO)Company: SMX Services & Consulting, Inc.
Customer: U.S. International Development Finance Corporation (DFC)
Program: DFC ISSO Support Services
Employment: Full-Time
Position Status: Key Personnel
SMX Labor Category Mapping: Senior IT Consultant
Hourly Pay Range:$90.35-$93.89/hourAnnualized Pay: $187,928-$195,291 based on 2,080 hours
Work Location: To be confirmed based on DFC PWS/contract requirementsSecurity: Tier 4 - High-Risk Public Trust suitability
Citizenship: U.S. Citizenship Required
Position SummarySMX Services & Consulting, Inc. is seeking a
Lead Senior Information Systems Security Officer (ISSO) to support the U.S. International Development Finance Corporation (DFC).
The Lead Senior ISSO will serve as a full-time
Key Person responsible for leading, coordinating, and overseeing ISSO activities supporting DFC information systems throughout the system lifecycle, including initiation, development, implementation, operations, modification, and disposal.
The position requires a senior cybersecurity professional capable of supporting cybersecurity governance, Risk Management Framework (RMF) activities, continuous monitoring, vulnerability remediation, system security documentation, compliance, and audit readiness.
Primary Responsibilities - Lead and coordinate ISSO activities supporting assigned DFC information systems.
- Provide senior-level cybersecurity guidance and security oversight throughout the system lifecycle.
- Support Risk Management Framework (RMF) activities.
- Support security authorization and ongoing authorization activities.
- Develop, review, maintain, and update required system security documentation.
- Support implementation, assessment, and continuous monitoring of security controls.
- Monitor and evaluate system cybersecurity posture and risks.
- Review vulnerability assessment and scanning results.
- Coordinate vulnerability remediation with technical and Government stakeholders.
- Develop, maintain, track, and support remediation of Plans of Action and Milestones (POA&Ms).
- Support security-control assessments and evidence collection.
- Maintain cybersecurity and compliance information within Government-designated systems.
- Support cybersecurity governance, compliance, and audit-readiness activities.
- Coordinate security issues, findings, risks, vulnerabilities, and remediation activities with system owners and technical teams.
- Provide cybersecurity status and risk information to appropriate stakeholders.
- Support cybersecurity incident coordination as required.
- Provide leadership and continuity for ISSO operations.
Technical EnvironmentThe DFC environment identified in the PWS includes technologies and cybersecurity platforms such as:
- Cyber Security Assessment and Management (CSAM)
- Splunk
- ServiceNow
- Tenable/Nessus and/or Qualys
- Microsoft Defender
- Microsoft Intune
- BigFix
- Microsoft Azure
- Microsoft 365
- Microsoft Entra ID
- Okta
- Palo Alto Panorama
- Zscaler
Candidates should have experience with these technologies or comparable enterprise cybersecurity, identity-management, vulnerability-management, monitoring, endpoint-management, and IT service-management platforms.
QualificationsCandidates should demonstrate senior-level experience relevant to:
- Information System Security Officer (ISSO) responsibilities
- Federal information-system cybersecurity
- NIST-based cybersecurity controls
- Risk Management Framework (RMF)
- Security authorization
- Continuous monitoring
- Vulnerability management and remediation
- POA&M management
- System security documentation
- Security-control assessments
- Cybersecurity governance and risk management
- Compliance and audit readiness
- Identity and access management
- Security monitoring and incident coordination
- Working with system owners, technical teams, cybersecurity personnel, and Government stakeholders
Federal information-system security experience is highly relevant to this position.
Security and Suitability - U.S. Citizenship required
- Must satisfy DFC requirements for a Tier 4 - High-Risk Public Trust investigation and suitability determination
- Work may involve Controlled Unclassified Information (CUI), Personally Identifiable Information (PII), and other sensitive unclassified information
- Privileged system access is subject to Government security and suitability requirements
- Existing investigations may be considered for reciprocity subject to Government determination
- Secret or Top Secret clearance is not identified as the baseline requirement
Compensation$90.35-$93.89 per hourEquivalent annualized compensation at 2,080 hours:
$187,928-$195,291 per yearActual compensation within the range will depend on the candidate's relevant experience, qualifications, technical background, and ability to satisfy the contract's Key Personnel requirements.
Key Personnel StatusThe
Lead Senior ISSO is a Government-designated Key Personnel position. The selected individual must be available to perform the required full-time role and satisfy applicable DFC security, suitability, access, and performance requirements.
Position OverviewFull-Time | Key Personnel | Federal Cybersecurity / ISSO | $90.35-$93.89/hour | Tier 4 High-Risk Public Trust | U.S. Citizen