Search

Lead Senior Information Systems Security Officer

PublishedPublished: 6/14/2022
Technology

Job Description

Job Description

Lead Senior Information Systems Security Officer

Position Summary

The Lead Senior Information Systems Security Officer serves as the contractor’s single point of accountability for technical execution. The Lead combines hands-on federal cybersecurity expertise with day-to-day leadership, quality control, stakeholder coordination, and oversight of all ISSO activities and deliverables.

Position Details

Employment: Full-time and dedicated to DFC

Place of Performance: Hybrid at DFC Headquarters, 1100 New York Avenue NW, Washington, DC 20527. The employee must work on site at least two days per week. The remaining work may be performed remotely within the continental United States.

Coverage: Coordinates staggered coverage with the Alternate Lead during DFC core business hours of 7:00 a.m. to 6:00 p.m. Eastern Time, Monday through Friday, excluding federal holidays.

Security: U.S. citizenship is required. The employee must satisfy DFC suitability requirements and be eligible for a Tier 4 High-Risk Public Trust investigation.

Reporting: Serves as the primary technical interface with the DFC Information System Security Manager, Chief Information Security Officer, Authorizing Official or Authorizing Official Designated Representative, System Owners, and other designated stakeholders.

Primary Responsibilities

  • Direct contractor ISSO activities across all supported systems and maintain consistent execution, technical quality, and timely performance.
  • Lead federal Risk Management Framework activities throughout the system lifecycle, including categorization support, control tailoring, implementation statements, assessment preparation, authorization packages, annual reviews, and reauthorization efforts.
  • Oversee the development, review, traceability, and submission of authorization artifacts in CSAM, including System Security Plans, control evidence, risk assessments, privacy artifacts, contingency documentation, and interconnection or inheritance records.
  • Manage continuous monitoring activities and translate information from CSAM, Splunk, vulnerability scanners, configuration tools, endpoint platforms, identity systems, cloud environments, and ticketing systems into current risk-posture information and actionable recommendations.
  • Oversee vulnerability and Plan of Action and Milestones support, including finding validation, root-cause analysis, remediation coordination, milestone tracking, aging analysis, escalation, and closure-evidence preparation. Federal personnel retain final approval authority.
  • Coordinate security impact analyses and change activities with System Owners, technical teams, the Change Control Board, and other governance bodies.
  • Ensure approved changes are reflected in authorization records, security documentation, control implementation statements, and continuous monitoring activities within required timelines.
  • Provide ISSO-level incident response coordination, including affected-system context, authorization-boundary analysis, risk analysis, situation reports, control-failure assessments, root-cause support, lessons learned, and coordination with the DFC Security Operations Center and incident response team.
  • Serve as the primary contractor ISSO interface during audits and assessments.
  • Coordinate audit evidence requests, validate completeness and traceability, track findings, and maintain audit-ready records.
  • Chair internal quality reviews of ISSO deliverables before Government submission.
  • Confirm that deliverables are complete, accurate, timely, professionally prepared, traceable, and aligned with applicable service levels and acceptance criteria.
  • Maintain the contractor’s risk and issue register, escalate material risks, and provide weekly, monthly, quarterly, and executive-level status information and recommendations.
  • Participate in DFC governance forums and technical reviews.
  • Present authorization status, continuous monitoring trends, POA&M aging, audit readiness, staffing risks, performance concerns, and recommended management actions.
  • Coordinate with the contractor’s corporate program management function on staffing, transition, reporting, invoicing support, performance monitoring, and corrective actions while remaining hands-on in cybersecurity delivery.
  • Lead transition-in and knowledge-transfer activities, establish operational procedures, confirm workforce readiness, and preserve service continuity without relying on incumbent overlap.
  • Maintain cross-functional coordination with DFC cybersecurity, privacy, records-management, audit, incident-response, and information technology teams.

Required Conditions

  • Must be a United States citizen. Dual citizenship remains subject to Government review and adjudication.
  • Must be eligible for and capable of satisfying Tier 4 High-Risk Public Trust requirements.
  • A current, in-scope federal investigation or suitability determination is strongly preferred because reciprocity and processing timelines are not guaranteed.
  • Must be available to support the 15-calendar-day transition period.
  • Must work on site at DFC Headquarters at least two days per week and provide additional on-site support when requested on a case-by-case basis.
  • Must maintain the qualifications, certifications, suitability, and availability approved at contract award throughout the period of performance.
  • Must demonstrate the judgment, communication skills, and technical depth required to interface directly with senior Government cybersecurity officials.
  • Must remain accountable for the quality and timely completion of all contractor ISSO deliverables.

Recommended Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, information systems, engineering, or a related field. Equivalent specialized federal cybersecurity experience may be considered.
  • Ten or more years of progressively responsible cybersecurity experience.
  • At least seven years of experience performing federal ISSO, Risk Management Framework, assessment and authorization, governance, risk, or compliance work.
  • At least three years of experience leading ISSO teams, cybersecurity programs, or multi-system federal authorization portfolios of comparable scope and complexity.
  • Demonstrated experience supporting FISMA Moderate systems, initial authorizations, annual assessments, reauthorizations, continuous monitoring, vulnerability management, POA&Ms, audit readiness, incident coordination, and cybersecurity governance.
  • Experience managing the development and quality review of federal authorization packages and supporting documentation.
  • One advanced cybersecurity certification such as CISSP, CGRC or CAP, CISM, or GSLC. CISSP or CGRC is preferred.
  • Additional cloud-security, audit, incident-response, or vulnerability-management credentials are advantageous.
  • Strong executive communication, technical writing, facilitation, risk analysis, quality-review, and stakeholder-management skills.

Technical Competencies

  • NIST Risk Management Framework and applicable federal cybersecurity requirements, including NIST SP 800-37, 800-53, 800-53A, 800-137, 800-128, 800-30, and 800-39.
  • FIPS 199, FISMA, OMB Circular A-130, applicable CISA Binding Operational Directives, and Emergency Directives.
  • Hands-on use of federal governance, risk, compliance, and authorization platforms. Direct CSAM experience is preferred.
  • Working proficiency with ServiceNow, Splunk, Qualys or comparable vulnerability platforms, Microsoft Defender, Microsoft Intune, BigFix, Microsoft Azure, Microsoft 365, Microsoft Entra ID, Okta, Palo Alto Panorama, Zscaler, and SharePoint.
  • Security documentation, evidence traceability, control assessment, risk analysis, POA&M lifecycle support, audit response, change control, and incident coordination.
  • Zero Trust concepts, FedRAMP inheritance, Customer Responsibility Matrices, Shared Responsibility Matrices, CIS Benchmarks, DISA Security Technical Implementation Guides, and secure configuration baselines.
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...