Job Requirements
Washington
Top Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
OVERVIEW:
We are seeking an Information System Security Officer (ISSO) Team Lead to support a key client in Washington DC. This individual will provide expert level guidance and leadership in implementing, maintaining, and enforcing information security policies, standards, and methodologies in accordance with federal regulations and agency requirements. This is a working Team Lead role.
GENERAL DUTIES:
REQUIRED QUALIFICATIONS:
DESIRED QUALIFICATIONS:
CLEARANCE:
We are seeking an Information System Security Officer (ISSO) Team Lead to support a key client in Washington DC. This individual will provide expert level guidance and leadership in implementing, maintaining, and enforcing information security policies, standards, and methodologies in accordance with federal regulations and agency requirements. This is a working Team Lead role.
GENERAL DUTIES:
- Directly oversee ISSO team members including technical guidance and training, mentorship, performance management, and day-to-day work assignments
- Develop, review, and update system documentation and FISMA-compliant SA&A packages (e.g., SSP, IRP, SOP, POA&Ms, CMP, IPA, PIA, SORN) in accordance with client policies and procedures to obtain/maintain system accreditation (e.g., ATT, ATO, ATU, OA) using established processes
- Advise the Authorizing Official (AO) and System Owner (SO) on cybersecurity matters related to assigned information systems across all NIST RMF phases, including system categorization, control baselines, control assessments, document and track weaknesses, and oversee corrective actions.
- Serve as a member of the CCB to ensure system security requirements are addressed
- Monitor cybersecurity status of information systems throughout the system lifecycle
- Establish and regularly review audit trails, providing audit logs upon request
- Provide RMF process subject matter expertise across all FISMA-reportable systems
- Conduct SCA per NIST 800-53A, OMB A-130, OMB A-123, and client policies and schedules; report control gaps or weaknesses, risk levels, cost-benefit analysis, and impact to the client
- Maintain a full inventory of hardware and software for the information system
- Develop, coordinate, test, and train staff on Contingency Plans and Incident Response Plans; support Incident Response and DR/COOP activities
- Scan applications, networks, and databases; identify vulnerabilities
REQUIRED QUALIFICATIONS:
- Minimum of ten (10) years of hands-on ISSO experience, including High and Cloud systems
- Minimum two (2) active certifications: PMP, CISSP, CISM, CEH, CASP, CCSP, CCSK, or Security+
- Minimum two (2) years of hands-on experience with JCAM
- In depth understanding of FISMA, NIST RMF, and SA&A processes
- Exceptional interpersonal skills to establish and maintain positive working relationships with all stakeholders
- Experience with GRC tools such as vulnerability management, vulnerability scanning, endpoint management, data protection, SIEM, and GRC automation platforms
- Expert-level command of the English language (oral and written), with experience interacting effectively at the CIO and CISO levels of large organizations
- Expert-level organizational skills and ability to keep a multitude of tasks and projects on track at all times and with minimal supervision
DESIRED QUALIFICATIONS:
- Bachelors Degree or higher
- CISSP certification
CLEARANCE:
- Active Top Secret clearance
group id: 90943786