Skip to content
← Back to job listings

ISSO Lead

Cherokee Federal · Washington, DC, United States

CybersecurityExternal listingfull-timeabout 2 hours ago

About The Role

ISSO Lead

The ISSO Lead is a senior cybersecurity governance and risk-management professional responsible for supporting federal information systems throughout the complete Risk Management Framework (RMF) lifecycle. This position leads ISSO activities across a large portfolio of systems, maintains authorization status, oversees security documentation, and advises system owners, ISSMs, and Authorizing Officials on cybersecurity risk.

Compensation & Benefits

  • Pay commensurate with experience.
  • Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice.

ISSO Lead Responsibilities Include

  • Lead ISSO, FISMA, RMF, and Assessment and Authorization activities for federal systems.
  • Apply NIST SP 800-37, NIST SP 800-53, FIPS 199, and NIST SP 800-60 requirements.
  • Support obtaining and maintaining Authorities to Operate (ATOs).
  • Develop and maintain SSPs, POA&Ms, PIAs, DIRAs, ISAs, SARs, Security Assessment Plans, Incident Response Plans, Contingency Plans, and Security Impact Assessments.
  • Track system lifecycles, authorization status, control implementation, vulnerabilities, and enterprise risks.
  • Manage continuous-monitoring and annual FISMA reporting activities.
  • Coordinate vulnerability remediation with system owners, engineering teams, assessors, SOC teams, and security operations contractors.
  • Support federal audits, inspections, data calls, and security assessments.
  • Prepare executive-level risk briefings, compliance reports, metrics, and recommendations.
  • Lead or mentor ISSOs and maintain consistent security documentation across multiple systems.
  • Perform other job-related duties as assigned.

ISSO Lead Experience, Education, Skills, Abilities Requested

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field.
  • Minimum of 8 years of relevant cybersecurity experience.
  • CISSP, CISM, or equivalent senior-level cybersecurity certification.
  • Active Top Secret (TS) security clearance is required. Candidates must possess the required clearance to be considered for this position.
  • U.S. citizenship required.
  • Experience leading ISSO, FISMA, RMF, or Assessment and Authorization activities for federal systems.
  • Experience supporting large federal system portfolios preferred.
  • Department of State or Bureau of Consular Affairs experience preferred.
  • Familiarity with ArchAngel or another federal GRC platform preferred.
  • Experience with Tenable Nessus, Wiz, iPost, vulnerability reporting, and POA&M tracking preferred.
  • Understanding of DevSecOps, CI/CD security controls, cloud security, zero-trust requirements, and High Value Assets preferred.
  • Must pass pre-employment qualifications of Cherokee Federal.

Company Information

Criterion is part of Cherokee Federal — the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner supporting federal customers, Cherokee Federal companies are focused on solving complex challenges and serving the government’s mission

#CherokeeFederal #LI-SM2 #AppC

Similar searchable job titles

  • Lead Information System Security Officer
  • Senior ISSO
  • ISSO Manager
  • Cybersecurity Governance Lead
  • RMF Lead
  • Senior A&A Lead
  • Information System Security Manager
  • Cybersecurity Risk and Compliance Lead.

Keywords

  • ISSO
  • FISMA
  • RMF
  • ATO
  • NIST 800-37
  • NIST 800-53
  • FIPS 199
  • A&A
  • SSP
  • ArchAngel
  • Tenable

Pipeline Position Notice

This is a pipeline position intended to identify qualified candidates for anticipated future opportunities. This posting does not represent a current vacancy. Candidates who meet the qualifications may be contacted as positions become available and program requirements are finalized.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing