Senior ISSO

Chameleon Integrated Services

$100K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Must be a United States citizen.
  • Eligible for Tier 4 High-Risk Public Trust investigation.
  • 8+ years of cybersecurity experience required.
  • 5+ years in federal continuous monitoring or related security operations.
  • Experience with Tenable Nessus, Splunk, and NIST compliance standards.
  • One of several specified cybersecurity certifications is required.
  • Willingness to participate in after-hours incident rotation.

Responsibilities

  • Lead continuous monitoring and vulnerability management efforts.
  • Coordinate incident response and prepare situation reports and RCAs.
  • Validate Splunk timelines and manage system-level Continuous Monitoring Plans.
  • Reconcile vulnerability findings among multiple teams and records.
  • Support Priority 1 and Priority 2 incidents with relevant documentation.
  • Update and maintain Plans of Action and Milestones (POA&Ms).
  • Prepare security posture metrics and trend reporting.

Benefits

  • Competitive employee health insurance including dental.
  • 100% company paid vision plan.
  • Generous 401K plan with no vesting period.
  • 100% company paid life insurance.
  • 100% company paid long and short-term disability insurance.
  • Training allowance for professional development.
  • Paid time off (PTO) and additional perks.
Full Job Description
We offer a Full Benefits package including:
  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO and more

Senior ISSO, Continuous Monitoring, Vulnerability, and Incident Coordination
  • Must be a United States citizen.
  • Must be eligible for a Tier 4 High-Risk Public Trust investigation.
  • Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Role:
Lead continuous monitoring, vulnerability management, POA&M execution support, security posture reporting, Splunk validation, and ISSO-level incident coordination for assigned systems.

The position will reconcile vulnerability findings among scanners, ServiceNow, CSAM, remediation teams, and system authorization records. It will support Priority 1 and Priority 2 incidents, prepare situation reports and RCAs, validate Splunk timelines, update POA&Ms, and maintain system-level Continuous Monitoring Plans.

Minimum Requirements:
  • At least 8 years of cybersecurity experience
  • At least 5 years performing federal continuous monitoring, vulnerability management, ISSO, security operations, or related risk-management work
  • Direct experience with:
    • Tenable Nessus, Tenable Security Center, or Qualys
    • Splunk searches, dashboards, or event validation
    • Vulnerability triage and false-positive review
    • POA&M creation and maintenance
    • Finding assignment and remediation coordination
    • Security posture metrics and trend reporting
    • NIST SP 800-53 control monitoring
    • NIST SP 800-137 continuous monitoring
  • Experience coordinating remediation with endpoint, network, cloud, application, and identity teams
  • Experience supporting incident-response documentation, SitReps, after-action reports, or RCAs
  • Understanding of CISA directives, vulnerability-remediation deadlines, and federal logging requirements
  • One of:
    • CISSP
    • CISM
    • CGRC/CAP
    • CySA+ with substantial federal experience
    • GIAC certification relevant to incident response or vulnerability management
  • Must accept participation in an after-hours incident rotation

Competitive Differentiators:
  • Direct CSAM and ServiceNow integration or reconciliation experience.
  • Splunk Enterprise Security.
  • Microsoft Defender for Endpoint, Identity, or Cloud.
  • Tenable.sc or Qualys VMDR.
  • CISA Binding Operational Directives and Known Exploited Vulnerabilities tracking.
  • Azure and Microsoft 365 security monitoring.
  • Palo Alto, Zscaler, Entra ID, Okta, or endpoint-management experience.
  • Federal major-incident or P1 incident support.
  • Experience building ConMon dashboards for executive review.
  • Current Tier 4 or Tier 5 suitability.
The resume must clearly identify:
  • Number of assets, systems, or authorization boundaries monitored.
  • Scanner and SIEM tools used.
  • Candidate's role in vulnerability validation and POA&M administration.
  • Finding volume, backlog, aging, closure, or remediation metrics.
  • Incident severity and documentation responsibilities.
  • Splunk queries, timeline validation, or dashboards developed.
  • Examples of coordination with technical remediation teams.
  • Examples where monitoring results changed system risk posture or authorization records.


Similar Jobs

More Jobs at Chameleon Integrated Services

More Information Technology Jobs

Find similar Senior ISSO jobs: