Back to career page

Lead ISSO

E Logic

Location: Hybrid - On-site at DFC Headquarters, 1100 New York Avenue NW, Washington, DC 20527 (minimum 2 days/week); balance remote (CONUS)

Clearance: Must be eligible for Tier 4 High-Risk Public Trust; U.S. Citizenship required

Job Type: Full-time

Contract Type: Government Contract (Base Year: 12 months; four 12-month option periods)

Position Overview

Seeking a highly experienced Lead Information System Security Officer (ISSO) to provide leadership and technical expertise in cybersecurity compliance, risk management, and authorization support to the U.S. International Development Finance Corporation (DFC), Office of Information Technology (OIT), Cybersecurity Division.

This role serves as the Contractor's single point of accountability for technical execution under the Performance Work Statement (PWS) and leads ISSO support across DFC's portfolio of 32 FISMA Moderate systems. The Lead ISSO directs all Contractor ISSO activities, serves as the primary technical interface with the Government ISSM, CISO, AO/AODR, and System Owners, and ensures consistent execution across all eight (8) Task Areas.

This is a non-personal services contract position. The contractor employee reports to the Prime Contractor for HR and administrative matters, while receiving work direction from the Government ISSM and COR.

Hybrid position: minimum 2 days/week on-site at DFC Headquarters, Washington, DC; balance remote (CONUS). No travel required.

Key Responsibilities

  • Serve as the Contractor's single point of accountability for technical execution; manage day-to-day ISSO support across all eight (8) Task Areas
  • Serve as primary technical interface with Government ISSM, CISO, AO/AODR, and System Owners
  • Direct Contractor ISSO activities and ensure consistent execution across supported systems
  • Oversee development, review, quality control, and submission of authorization-package artifacts in CSAM
  • Chair internal quality reviews of ISSO deliverables before Government submission
  • Manage the Contractor's risk and issue register; escalate to Government leadership as appropriate
  • Participate in DFC governance forums (ERB, CAB, CCB, Cybersecurity Steering Committee, Risk Management Working Group, Privacy Working Group)
  • Coordinate with Contractor's Program Manager for invoicing, staffing, and reporting
  • Maintain hands-on cybersecurity expertise; not solely an administrative manager
  • Provide RMF and authorization support per NIST SP 800-37 Rev. 2 (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor)
  • Support Continuous Monitoring per NIST SP 800-137, including monthly ConMon reporting, quarterly access recertification, and annual SSP currency reviews
  • Support vulnerability management and POA&M lifecycle, including critical/emergency vulnerability response, CISA KEV/BOD 22-01 compliance, and monthly ServiceNow-to-CSAM reconciliation
  • Support Security Impact Analysis (SIA) and change coordination for CAB/CCB/ERB governance
  • Provide ISSO-level incident response coordination to DFC SOC/IR team, including CSAM context pull, Splunk log-verification, SitReps, RCA inputs, and corrective action tracking
  • Support audit, assessment, and compliance activities, including FISMA reporting, evidence coordination, and audit finding remediation
  • Maintain proficiency in CSAM, ServiceNow, Splunk, Qualys, Microsoft Defender, Intune, BigFix, Entra ID, Okta, Palo Alto Panorama, and Zscaler
  • Maintain Tier 4 Public Trust eligibility; complete all mandatory DFC training
  • Comply with DFC security regulations and safeguard CUI

Required Qualifications

Education:

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)

Certifications (recommended):

  • CISSP, CISM, CAP, or equivalent cybersecurity certification

Experience:

  • Minimum 10 years cybersecurity experience, with at least 5 years in ISSO, ISSM, or RMF leadership
  • Experience leading ISSO teams for federal agencies supporting FISMA Moderate systems
  • Hands-on experience with NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, SP 800-53B, FIPS 199, SP 800-60, SP 800-137, SP 800-128, SP 800-30, and SP 800-39
  • Experience with FISMA, OMB A-130, OMB M-22-09 (Zero Trust), and CISA BODs/EDs
  • Experience with FedRAMP-authorized cloud services and shared-responsibility models (Azure Government, M365 GCC/GCC High, ServiceNow)
  • Hands-on experience with CSAM (or equivalent GRC), ServiceNow (ITSM), Splunk (SIEM), Qualys/Tenable, and Microsoft Defender
  • Experience preparing AO decision briefing materials and supporting authorization package development
  • Experience with POA&M lifecycle management, risk acceptance coordination, and closure evidence validation
  • Experience with SIA, CAB/CCB/ERB governance, incident response coordination, and audit readiness

Citizenship:

  • U.S. Citizenship required

Security:

  • Must be eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation
  • Government does not sponsor Tier 4 investigations; reciprocity may be accepted but is not guaranteed

Language:

  • Fluent in written and verbal English

Technical Skills:

  • Proficiency in CSAM, ServiceNow, Splunk, Qualys, Microsoft Defender, Intune, BigFix, Entra ID, Okta, Palo Alto Panorama, and Zscaler

Preferred Qualifications

  • Experience serving as a back-up to a Government ISSM or ISSO Program Manager
  • Experience advising project teams and Senior Management on cybersecurity compliance
  • Experience with Zero Trust architecture and OMB M-22-09 implementation
  • Experience with CISA KEV, BOD 22-01, and Emergency Directive response
  • Experience with FedRAMP customer-responsibility and inherited-control reconciliation
  • Experience with privacy documentation support (PTA, PIA, SORN review inputs)
  • Experience with tabletop exercises and IRP testing

Work Role Information

Work Role: Lead Information System Security Officer (ISSO)

Proficiency Level: Senior/Expert

Key Personnel: Yes -- Full-time, dedicated

Alternate: One of the two Senior ISSOs serves as Alternate Lead ISSO

Additional Requirements

  • Must comply with DFC security regulations and safeguard CUI
  • Must pass background checks and suitability determinations
  • Must complete DFC IT Security Awareness Training annually
  • Must sign and comply with DFC Rules of Behavior
  • Must maintain Tier 4 Public Trust eligibility and required certifications
  • Must be available during core hours (7:00 AM - 6:00 PM ET, M-F, excluding federal holidays)
  • Occasional after-hours coordination as directed (no 24/7 on-call)
  • Must report on-site minimum 2 days/week at DFC HQ
  • Must not perform billable ISSO support requiring system access before suitability determination (except transition-in activities authorized in writing by the COR)

Schedule & Work Conditions

Hours: Up to 40 hours/week, Monday-Friday, 7:00 AM - 6:00 PM ET, excluding Federal holidays

Overtime: Only at Government's discretion

Telework: Hybrid -- minimum 2 days/week on-site at DFC HQ; balance remote (CONUS)

Travel: Not authorized

Place of Performance: DFC Headquarters, 1100 New York Avenue NW, Washington, DC 20527 (on-site); remote (CONUS) for balance

Equal Opportunity Employer

We are an equal opportunity employer and do not discriminate on the basis of race, color, religion, sex, gender identity, sexual orientation, national origin, genetics, disability, age, or veteran status.

Job type
Full Time