Senior Information System Security Officer (ISSO)
OtherInformation System Security Officer
4 views0 saves0 applied
Quick Summary
Key Responsibilities
Provide on-site cybersecurity and RMF sustainment support. Independently manage categorization, control selection, implementation evidence, assessment readiness, authorization, and monitoring.
Requirements Summary
C3EL is seeking a Senior Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract.
Technical Tools
OtherInformation System Security Officer
Responsibilities
~1 min read- →Provide on-site cybersecurity and RMF sustainment support.
- →Independently manage categorization, control selection, implementation evidence, assessment readiness, authorization, and monitoring.
- →Develop and maintain SSPs, SAPs, SARs, POA&Ms, risk assessments, control statements, inheritance records, and evidence packages.
- →Support FedRAMP-authorized cloud services, provider artifacts, customer responsibilities, CRMs, SRMs, and inherited controls.
- →Support privacy controls, PTAs, PIAs, and systems processing PII.
- →Pre-stage evidence and coordinate SCA interviews, walkthroughs, demonstrations, findings, and comment adjudication.
- →Track ATO dates, conditions, milestones, open risks, and briefing materials for AO/AODR decisions.
- →Produce accurate, concise, and audit-ready Government cybersecurity documentation.
- →Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.
Requirements
~1 min read- U.S. Citizenship.
- Eligibility to obtain a Tier 4 High-Risk Public Trust.
- Minimum seven (7) years of cybersecurity.
- Minimum five (5) years in federal RMF, A&A, ISSO, or authorization work.
- Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.
- Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint and cloud-security platforms.
- Hands-on CSAM experience supporting system profiles, controls, evidence, POA&Ms, and authorization workflows.
- Experience with Azure Government, Microsoft 365 GCC/GCC High, and cloud shared-responsibility models.
- Experience with Entra ID, Okta, privileged access, role assignments, and access recertification.
- At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.
- Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)
Location & Eligibility
Where is the job
Washington, United States
On-site at the office
Who can apply
US
Listing Details
- Posted
- August 28, 2026
- First seen
- August 28, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 32
- Repost count
- 0
- Trust Level
- 31%
- Scored at
- September 30, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.