Senior ISSO (Information System Security Officer)

IBSS

$100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, information technology, or related field
  • Minimum 7 years of experience in cybersecurity or information systems
  • Familiarity with NIST frameworks and policies including FISMA and OMB Circular A-130
  • Proficient in GRC and authorization tools like CSAM
  • Experience with vulnerability management tools such as Splunk and Qualys

Responsibilities

  • Perform RMF and authorization support for assigned systems
  • Coordinate authorization activities with ISSM and System Owners
  • Execute continuous monitoring and reconcile GRC records with SIEM
  • Track vulnerabilities and coordinate remediation efforts
  • Maintain audit-ready security documentation in GRC system
  • Support change coordination and incident-response efforts
  • Maintain ability to assume Lead ISSO duties

Benefits

  • Medical, dental, vision, and prescription drug coverage with company-paid deductible
  • Paid time off and federal holidays
  • Matching 401K plan
  • Tuition/professional development reimbursement
  • Flex-Spending (FSA) and Dependent Care Account (DCA) options
Full Job Description
Job Title: Senior ISSO (Information System Security Officer)
Location: Washington, DC (Hybrid 3-days onsite; core hours 7:00 AM to 6:00 PM ET)
Clearance Required: Must be able to obtain and maintain a Public Trust
Salary: $100K-120K
Application Deadline: July 31, 2026

To apply, please follow these steps:
  • Visit https://ibsscorp.com/careers/
  • Select the position you are interested in
  • Review the job details, then click Apply Now
  • Complete and submit your application


Description:
Background
IBSS supports a U.S. federal agency's cybersecurity program in Washington, DC, providing Information System Security Officer (ISSO) support across the system authorization lifecycle. The environment is a hybrid, Zero-Trust-aligned Microsoft Azure and Microsoft 365 enterprise supporting approximately 800 users and 32 information systems operating under FISMA, OMB Circular A-130, and applicable NIST guidance. Authorization artifacts are maintained in a Governance, Risk, and Compliance (GRC) system of record; security telemetry is centralized in a SIEM; and IT service management runs on an enterprise ITSM platform. These roles deliver RMF and authorization support, continuous monitoring, vulnerability and POA&M execution, security documentation, security impact analysis, incident-response coordination, and audit and compliance support - advising and preparing while the Government retains all authorization and risk decisions.

The Senior ISSO performs hands-on ISSO support for assigned systems and is qualified to assume Lead ISSO duties during the Lead's absence, maintaining continuity of ISSO operations.

Responsibilities:

1. RMF and authorization execution
• Perform RMF and authorization support for assigned systems: author and maintain SSPs, control implementation and inheritance records, and assessment evidence in the GRC system of record.
• Coordinate with the ISSM, System Owners, and assessors on authorization and ongoing-authorization activities.

2. Continuous monitoring and vulnerability/POA&M
• Execute continuous monitoring and security-posture management, reconciling GRC records with SIEM telemetry.
• Perform vulnerability management and POA&M execution: track findings, distinguish false positives with documented rationale, coordinate remediation, and maintain closure evidence within timelines.

3. Documentation, change, incident, and audit
• Maintain current, consistent, audit-ready security documentation in the GRC system of record.
• Support security impact analyses and change coordination, incident-response coordination, and audit, assessment, and compliance activities.

4. Continuity
• Maintain proficiency in the agency's authoritative tools and be prepared to assume Lead ISSO duties without service degradation.
• Respect the advisory boundary; support and recommend while the Government retains all decisions.

Education
• Bachelor's degree with minimum 7+ years of experience in cybersecurity, information technology, information systems, or a related field.

Key Technical Skills
• Frameworks and policy: RMF (NIST SP 800-37), NIST SP 800-53/53A, NIST SP 800-137, FISMA, OMB Circular A-130, FIPS 199.
• GRC and authorization: CSAM (or comparable) for SSPs, POA&Ms, control implementation and inheritance, assessment evidence.
• Monitoring and vulnerability: Splunk; Tenable Nessus or Qualys; Microsoft Defender.
• Platforms and identity: Azure and M365 (incl. Azure Government, GCC/GCC High), Entra ID, Okta; Intune/BigFix.
• ITSM and network: ServiceNow; Palo Alto Panorama; Zscaler.

Desired / Preferred Qualifications
• Professional certifications such as CISSP, CGRC (formerly CAP), CISM, Security+, or equivalent.
• Prior experience as a federal ISSO supporting FISMA-Moderate systems, RMF, continuous monitoring, and POA&M management.
• Hands-on experience with a federal GRC/authorization system (e.g., CSAM), Splunk, Tenable Nessus or Qualys, and ServiceNow.
• Prior experience supporting a federal CFO Act agency or similar cybersecurity program.

IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.

Similar Jobs

More Jobs at IBSS

More Information Technology Jobs

Find similar Senior ISSO (Information System Security Officer) jobs: