Senior Information Security Engineer (ISSO)

Lumen

$84K — $124K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information assurance, cybersecurity, or a related field, or equivalent experience.
  • Minimum of 3 years of relevant experience in information assurance, governance, risk, and compliance, or cybersecurity.
  • Demonstrated experience supporting RMF activities, security assessments, audits, or authorization efforts.
  • Experience developing or maintaining authorization artifacts (e.g., SSPs, POA&;Ms, security plans, assessment evidence, or related documentation).
  • Experience in customer-facing or services-based environments supporting federal or regulated clients is preferred.
  • Relevant certifications in cybersecurity or governance, risk, and compliance (e.g., Security+, CGRC, CAP, CISA) are preferred.
  • Proficiency with technologies, tools, and processes supporting GRC, vulnerability management, and continuous monitoring.

Responsibilities

  • Support execution of the full RMF lifecycle, including control implementation and continuous monitoring.
  • Develop and maintain authorization artifacts ensuring accuracy.
  • Maintain ATO compliance and audit readiness for assigned systems.
  • Assist with vulnerability management and audit response activities.
  • Conduct security reviews to identify gaps, risks, and improvement opportunities.
  • Monitor security posture through vulnerability and audit data.
  • Coordinate with various teams to implement security controls.

Benefits

  • Comprehensive health, life, and voluntary lifestyle benefits.
  • Enrichment programs for physical, mental, emotional, and financial wellbeing.
  • Bonus structure including short-term and long-term incentives.
Full Job Description
The Role

At Lumen, the Senior Information Security Engineer (Senior ISSO) plays a critical role in advancing secure, compliant solutions for federal customers while supporting the execution of compliance activities across managed services environments. This is a hands-on role where you will work directly with Lead and Senior Lead ISSOs, engineering teams, program stakeholders, and customers to address ATO challenges, support assessment readiness, and help maintain the security posture of regulated systems.

The Senior ISSO serves as an experienced security practitioner responsible for performing RMF activities, maintaining authorization documentation, evaluating compliance requirements, and supporting continuous monitoring efforts. The pace is fast, the expectations are high, and the work is often complex. Success requires strong attention to detail, sound technical judgment, and the ability to collaborate effectively across teams. For those motivated to grow their expertise and contribute to meaningful outcomes in highly regulated environments, Lumen offers opportunities to develop advanced skills while supporting critical public sector customers.

The Senior ISSO operates as a customer-facing security practitioner responsible for supporting system authorization activities by helping align managed services, architectures, and implementations with federal compliance requirements. This includes contributing to authorization artifacts, supporting assessments, and coordinating with technical teams to maintain compliance and operational readiness.

The successful candidate will demonstrate the ability to:
  • Support execution of the full RMF lifecycle, including categorization, control implementation, assessment readiness, authorization support, and continuous monitoring.
  • Develop, maintain, and ensure accuracy of authorization artifacts (e.g., SSP, POA&M, control evidence, implementation narratives, and supporting documentation).
  • Support activities necessary to maintain ATO compliance and audit readiness for assigned systems.
  • Assist with vulnerability management, audit response, corrective action plans, and remediation tracking activities.
  • Conduct security and compliance reviews to identify gaps, risks, and improvement opportunities.
  • Support system-level risk assessments and provide recommendations regarding control implementation and remediation activities.
  • Monitor vulnerability, audit, and continuous monitoring data to maintain awareness of system security posture.
  • Coordinate with engineering, operations, and program teams to support implementation of security controls and corrective actions.
  • Participate in security assessments, audits, and inspections, including interactions with assessors and customer stakeholders.
  • Review security documentation, control evidence, and implementation artifacts for accuracy and completeness.
  • Evaluate products, services, and proposed technical solutions for compliance, risk, and implementation considerations.
  • Support customer integration of managed services by assisting with control implementation, inheritance analysis, and security documentation activities.
  • Contribute RMF and compliance expertise to solution implementation, delivery efforts, and operational improvement initiatives.
  • Maintain awareness of evolving federal compliance requirements, security threats, and industry best practices.


The Main Responsibilities

  • Strong working knowledge of NIST RMF (SP 800-37) and NIST SP 800-53 control framework.
  • Demonstrated experience performing RMF activities and supporting authorization efforts for federal or regulated systems.
  • Experience supporting FedRAMP and/or FISMA authorization processes, including documentation development and assessment support.
  • Ability to execute assigned security and compliance activities with limited supervision.
  • Understanding of control implementation, inheritance concepts, and shared responsibility models.
  • Ability to assess security risks and communicate findings clearly to technical and non-technical stakeholders.
  • Experience evaluating security and compliance considerations associated with products, services, and architecture.
  • Working knowledge of cryptographic fundamentals and emerging security technologies, including post-quantum cryptography (PQC).
  • Strong collaboration skills across engineering, operations, program management, and security teams.
  • Effective written and verbal communication skills.
  • Demonstrates Lumen leadership behaviors (teamwork, trust, transparency, clarity, courage, customer focus, growth mindset, respect).


What We Look For in a Candidate

Education and Experience:
  • Bachelor's degree in information assurance, cybersecurity, or a related field, or equivalent experience.
  • Minimum of 3 years of relevant experience in information assurance, governance, risk, and compliance, or cybersecurity.
  • Demonstrated experience supporting RMF activities, security assessments, audits, or authorization efforts.
  • Experience developing or maintaining authorization artifacts (e.g., SSPs, POA&Ms, security plans, assessment evidence, or related documentation).
  • Experience operating in customer-facing or services-based environments supporting federal or regulated clients is preferred.
  • Relevant certifications in cybersecurity or governance, risk, and compliance (e.g., Security+, CGRC, CAP, CISA) are preferred.
  • Broad security certifications (e.g., CISSP, CCSP, CISM) may supplement demonstrated experience.
  • Proficiency with technologies, tools, and processes supporting GRC, vulnerability management, and continuous monitoring.


Security Requirements:
  • US citizenship required.
  • The capability to meet the suitability requirements for a GSA public trust position is required.


Compensation

This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.

Location Based Pay Ranges

$84,629 - $112,838 in these states: AL AR AZ FL GA IA ID IN KS KY LA ME MO MS MT ND NE NM OH OK PA SC SD TN UT VT WI WV WY
$88,860 - $118,480 in these states: CO HI MI MN NC NH NV OR RI
$93,092 - $124,122 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA

Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process. Learn more about Lumen's:Benefits
Bonus Structure

#LI-Remote

What to Expect Next

Requisition #: 343084

Similar Jobs

More Jobs at Lumen

  • Field OPS Engineer II
    $71K — $94K *
    Portland, OR 97229 (Washington County)
    Telecommunications & Hardware
    In-Person
  • Sr Technical Project Manager
    $84K — $124K *
    Remote
    Telecommunications & Hardware
    Remote in United States
  • Field Ops Engineer II
    $74K — $99K *
    Dallas, TX 75217 (Dallas County)
    Telecommunications & Hardware
    In-Person
  • Field Ops Engineer II
    $71K — $94K *
    Denver, CO 80219 (Denver County)
    Telecommunications & Hardware
    In-Person
  • Field Ops Engineer II
    $74K — $99K *
    Los Angeles, CA 90011 (Los Angeles County)
    Telecommunications & Hardware
    In-Person

More Information Technology Jobs

Find similar Senior Information Security Engineer (ISSO) jobs: