Senior Information System Security Officer (ISSO)
OtherInformation System Security Officer
4 views0 saves0 applied
Quick Summary
Key Responsibilities
Provide on-site cybersecurity and RMF sustainment support. Maintain traceability between ServiceNow remediation tickets and CSAM POA&M records. Analyze findings, validate false positives,
Requirements Summary
C3EL is seeking a Senior Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract.
Technical Tools
OtherInformation System Security Officer
Responsibilities
~1 min read- →Provide on-site cybersecurity and RMF sustainment support.
- →Maintain traceability between ServiceNow remediation tickets and CSAM POA&M records.
- →Analyze findings, validate false positives, and prioritize remediation using CVSS, CISA KEV, exposure, exploitability, and mission impact.
- →Support notification, triage, CSAM context retrieval, Splunk verification, SitReps, RCA, corrective actions, and post-incident updates.
- →Support CAB/CCB/ERB reviews, security impact analysis, artifact updates, and post-change verification.
- →Track audit, penetration-test, and assessment findings through corrective action and evidence-supported closure.
- →Maintain incident-response plans and support tabletop or functional exercises.
- →Produce accurate, concise, and audit-ready Government cybersecurity documentation.
- →Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.
Requirements
~1 min read- U.S. Citizenship.
- Eligibility to obtain a Tier 4 High-Risk Public Trust.
- Minimum seven (7) years of cybersecurity.
- Minimum five (5) years in federal ISSO, ConMon, vulnerability, security operations, or compliance work.
- Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.
- Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint, and cloud-security platforms.
- Direct experience with Splunk searches, dashboards, ingestion verification, log coverage, and incident timeline support.
- Direct experience with ServiceNow incidents, problems, changes, remediation tickets, and reporting.
- Direct experience with Tenable Nessus, Qualys, ACAS, or comparable Government-approved scanners.
- Experience with Defender, Intune, BigFix, or equivalent endpoint and configuration platforms.
- At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.
- Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)
Location & Eligibility
Where is the job
Washington, United States
On-site at the office
Who can apply
US
Listing Details
- Posted
- September 2, 2026
- First seen
- September 2, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 27
- Repost count
- 0
- Trust Level
- 31%
- Scored at
- September 30, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.