District of Columbia law requires most employers to post a pay range.
At a glanceSummarised by Seekless from the posting.
Must have12
Eligibility to obtain a Tier 4 High-Risk Public Trust
Minimum ten (10) years in cybersecurity
Minimum seven (7) years in federal RMF/ISSO work
Minimum three (3) years leading ISSO or authorization teams
Hands-on CSAM experience supporting system profiles, controls, evidence, POA&Ms, and authorization workflows
Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance
Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms
Direct experience briefing and coordinating with ISSMs, CISOs, AOs, AODRs, System Owners, assessors, and senior Government officials
Direct experience overseeing SSPs, SAPs, SARs, POA&Ms, risk assessments, control statements, and evidence packages
Expert knowledge of all seven RMF steps, ATO, reauthorization, ongoing authorization, control baselines, and inheritance
Working proficiency with ServiceNow, Splunk, and vulnerability-scanning platforms
Associate's degree in Cybersecurity, Information Technology, or related field
Nice to have1
At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC
Eligibility1
U.S. Citizenship
Skills
CSAM
ServiceNow
Splunk
GRC
ITSM
SIEM
NIST SP 800-37
NIST SP 800-53
NIST SP 800-53B
FIPS 199
FISMA
**CONTINGENT UPON CONTRACT AWARD**
Overview:
Job Title: Lead Information System Security Officer (ISSO)
Requirements
Security Clearance: Ability to Obtain Tier 4 High-Risk Public Trust
Location: Washington, D.C.
(Due to the nature of the work and contract requirements, U.S. Citizenship is required.)
Description:
C3EL is seeking a Lead Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract. This role will serve as the single point of accountability for technical performance and remain a hands-on cybersecurity practitioner as the technical leader, Government interface, and quality authority for the entire ISSO program.
Responsibilities will include, but not be limited to:
•
Provide on-site cybersecurity and RMF sustainment support.
•
Chair internal quality reviews and ensure deliverables are complete, current, consistent, timely, and audit ready.
Support weekly reports, monthly status reports, and quarterly executive reviews, including authorization, vulnerability, POA&M, audit, and staffing status.
•
Lead a team of two Senior ISSOs and maintain coverage during absence, vacancy, surge, or suitability delay.
•
Produce accurate, concise, and audit-ready Government cybersecurity documentation.
•
Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.
Minimum Qualifications:
•
U.S. Citizenship.
•
Eligibility to obtain a Tier 4 High-Risk Public Trust.
•
Minimum ten (10) years in cybersecurity.
•
Minimum seven (7) years in federal RMF/ISSO work.
•
Minimum three (3) years leading ISSO or authorization teams.
•
Hands-on CSAM experience supporting system profiles, controls, evidence, POA&Ms, and authorization workflows.
•
Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.
•
Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms.
•
Direct experience briefing and coordinating with ISSMs, CISOs, AOs, AODRs, System Owners, assessors, and senior Government officials.
•
Direct experience overseeing SSPs, SAPs, SARs, POA&Ms, risk assessments, control statements, and evidence packages.
•
Expert knowledge of all seven RMF steps, ATO, reauthorization, ongoing authorization, control baselines, and inheritance.
•
Working proficiency with ServiceNow, Splunk, and vulnerability-scanning platforms.
Preferred Qualifications:
•
At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.
Education:
•
Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)