Back to career page

Senior ISSO / Alternate Lead ISSO

E Logic

Location: Hybrid - On-site at DFC Headquarters, 1100 New York Avenue NW, Washington, DC 20527 (minimum 2 days/week); balance remote (CONUS)

Clearance: Must be eligible for Tier 4 High-Risk Public Trust; U.S. Citizenship required

Job Type: Full-time

Contract Type: Government Contract (Base Year: 12 months; four 12-month option periods)

Position Overview

Seeking a highly experienced Senior Information System Security Officer (ISSO) / Alternate Lead ISSO to provide senior-level cybersecurity compliance, risk management, and authorization support to the U.S. International Development Finance Corporation (DFC), Office of Information Technology (OIT), Cybersecurity Division.

This role serves as the designated alternate to the Lead ISSO and provides senior-level ISSO support, continuity of operations, and coverage as necessary. The Senior ISSO / Alternate Lead ISSO is qualified to assume Lead ISSO duties during scheduled or unscheduled absences and maintains operational continuity in the Lead ISSO's absence.

This is a non-personal services contract position. The contractor employee reports to the Prime Contractor for HR and administrative matters, while receiving work direction from the Government ISSM and COR.

Hybrid position: minimum 2 days/week on-site at DFC Headquarters, Washington, DC; balance remote (CONUS). No travel required.

Key Responsibilities

  • Serve as designated alternate to the Lead ISSO; assume Lead ISSO duties during scheduled or unscheduled absences
  • Maintain operational continuity in the absence of the Lead ISSO
  • Perform senior ISSO duties for assigned systems as directed by the Lead ISSO
  • Support consistent execution of ISSO activities across assigned systems
  • Lead assigned RMF, ConMon, vulnerability management, POA&M, audit-support, and compliance workstreams
  • Maintain proficiency in CSAM, ServiceNow, Splunk, Qualys, Microsoft Defender, Intune, BigFix, Entra ID, Okta, Palo Alto Panorama, and Zscaler
  • Provide RMF and authorization support per NIST SP 800-37 Rev. 2 (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor)
  • Support Continuous Monitoring per NIST SP 800-137, including monthly ConMon reporting, quarterly access recertification, and annual SSP currency reviews
  • Support vulnerability management and POA&M lifecycle, including critical/emergency vulnerability response, CISA KEV/BOD 22-01 compliance, and monthly ServiceNow-to-CSAM reconciliation
  • Support SIA and change coordination for CAB/CCB/ERB governance, including standard, expedited, and emergency changes
  • Provide ISSO-level incident response coordination to DFC SOC/IR team, including CSAM context pull, Splunk log-verification, SitReps, RCA inputs, and corrective action tracking
  • Support audit, assessment, and compliance activities, including FISMA reporting, evidence coordination, and audit finding remediation
  • Support security documentation and artifact management (SSP, POA&M, ConMon Plan, IRP, CP, PTA, PIA, ROB, SIA records, ISAs, MOU/MOA, SOPs, runbooks)
  • Maintain Tier 4 Public Trust eligibility; complete all mandatory DFC training
  • Comply with DFC security regulations and safeguard CUI

Required Qualifications

Education:

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)

Certifications (recommended):

  • CISSP, CISM, CAP, or equivalent cybersecurity certification

Experience:

  • Minimum 7 years cybersecurity experience, with at least 3 years in ISSO or RMF support
  • Experience supporting federal agencies with FISMA Moderate systems
  • Hands-on experience with NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, SP 800-53B, FIPS 199, SP 800-60, SP 800-137, SP 800-128, SP 800-30, and SP 800-39
  • Experience with FISMA, OMB A-130, OMB M-22-09 (Zero Trust), and CISA BODs/EDs
  • Experience with FedRAMP-authorized cloud services and shared-responsibility models (Azure Government, M365 GCC/GCC High, ServiceNow)
  • Hands-on experience with CSAM (or equivalent GRC), ServiceNow (ITSM), Splunk (SIEM), Qualys/Tenable, and Microsoft Defender
  • Experience with POA&M lifecycle management, risk acceptance coordination, and closure evidence validation
  • Experience with SIA, CAB/CCB/ERB governance, incident response coordination, and audit readiness
  • Experience with security documentation and artifact management (SSP, POA&M, ConMon Plan, IRP, CP, PTA, PIA, ROB, SIA records, ISAs, MOU/MOA, SOPs, runbooks)

Citizenship:

  • U.S. Citizenship required

Security:

  • Must be eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation
  • Government does not sponsor Tier 4 investigations; reciprocity may be accepted but is not guaranteed

Language:

  • Fluent in written and verbal English

Technical Skills:

  • Proficiency in CSAM, ServiceNow, Splunk, Qualys, Microsoft Defender, Intune, BigFix, Entra ID, Okta, Palo Alto Panorama, and Zscaler

Preferred Qualifications

  • Experience serving as a back-up to a Government ISSM or Lead ISSO
  • Experience advising project teams and Senior Management on cybersecurity compliance
  • Experience with Zero Trust architecture and OMB M-22-09 implementation
  • Experience with CISA KEV, BOD 22-01, and Emergency Directive response
  • Experience with FedRAMP customer-responsibility and inherited-control reconciliation
  • Experience with privacy documentation support (PTA, PIA, SORN review inputs)
  • Experience with tabletop exercises and IRP testing

Work Role Information

Work Role: Senior Information System Security Officer (ISSO) / Alternate Lead ISSO

Proficiency Level: Senior/Expert

Key Personnel: Yes -- Full-time, dedicated

Alternate: Serves as designated alternate to the Lead ISSO; one of the two Senior ISSOs serves as alternate lead

Additional Requirements

  • Must comply with DFC security regulations and safeguard CUI
  • Must pass background checks and suitability determinations
  • Must complete DFC IT Security Awareness Training annually
  • Must sign and comply with DFC Rules of Behavior
  • Must maintain Tier 4 Public Trust eligibility and required certifications
  • Must be available during core hours (7:00 AM - 6:00 PM ET, M-F, excluding federal holidays)
  • Occasional after-hours coordination as directed (no 24/7 on-call)
  • Must report on-site minimum 2 days/week at DFC HQ
  • Must not perform billable ISSO support requiring system access before suitability determination (except transition-in activities authorized in writing by the COR)

Schedule & Work Conditions

Hours: Up to 40 hours/week, Monday-Friday, 7:00 AM - 6:00 PM ET, excluding Federal holidays

Overtime: Only at Government's discretion

Telework: Hybrid -- minimum 2 days/week on-site at DFC HQ; balance remote (CONUS)

Travel: Not authorized

Place of Performance: DFC Headquarters, 1100 New York Avenue NW, Washington, DC 20527 (on-site); remote (CONUS) for balance

Equal Opportunity Employer

We are an equal opportunity employer and do not discriminate on the basis of race, color, religion, sex, gender identity, sexual orientation, national origin, genetics, disability, age, or veteran status.

Job type
Full Time