Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

ISSO/ISCM Lead

K2United, LLC.

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness. Our four core values define how we show up every day: Respect Others - We lead with respect, building trust and connection. Internally Driven - We are relentlessly compelled to accomplish our objectives. Collaborative Innovation - We create by listening, sharing, and working together. Client Success - We hold our clients' mission as our own. We believe in people who are accountable, curious, and motivated to make an impact that matters. Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance. Key Responsibilities Manage the ISCM program and perform internal controls testing to sustain persistent authorization and compliance across all enterprise systems. Maintain and update A&A packages — System Security Plans, Configuration Management Plans, and Contingency and Disaster Recovery Plans — conforming to NIST SP 800-18 and USAC standards. Support systems undergoing new authorization, reauthorization, and ongoing authorization; identify compliance gaps and prepare risk-informed recommendations for management review. Execute internal Security Control Assessments and controls testing for minor systems, interim authorizations, and FedRAMP SaaS offerings using NIST SP800-53A as a guide, as directed. Own POA&M tracking, analysis, and reporting: document findings, monitor due dates and milestone dates, collect and validate closure evidence, and report on open, overdue, closed, and risk-accepted items with aging trend analysis. Collaborate with Security Engineers to ensure all configuration data — failed settings, technical deviations, and accepted risk decisions — is explicitly tracked within the system authorization boundary in the GRC system of record (e.g., Xacta). Perform Security Impact Analyses for requested deviations and facilitate the risk acceptance process with the USAC CISO and ISSM; ensure all approved deviations are reviewed annually for continued necessity. Serve as primary technical support and point of contact for all internal and external audits and assessments; drive artifact collection including logs, system configurations, and access lists, and validate evidence for completeness, accuracy, and oversight quality. Participate in accreditation interviews and audit meetings, providing technical insight into incident response and monitoring activities. Act as liaison between the client business units and the OCISO; facilitate weekly security meetings and manage inquiries on system modifications, implementation initiatives, and problem resolution. Conduct routine reviews of audit logs, patching status, access lists, and incident response testing; perform annual policy and procedure gap analyses against federal requirements. Requirements Bachelor's degree in information systems, cybersecurity, computer science, or a related field. Equivalent experience considered in lieu of degree. Eight or more years in federal or federally regulated information security compliance, including at least three years in an ISSO, ISSM, or continuous monitoring lead capacity. Demonstrated hands-on ownership of RMF and A&A lifecycle activities under NIST SP 800-37, including authorship and maintenance of SSPs, CMPs, and contingency plans. Direct experience supporting FISMA audits (OIG, IG, or independent assessor) as artifact owner or primary technical liaison. Working proficiency with NIST SP 800-53 Rev. 5, SP 800-53A, SP 800-137, and SP 800-18. Demonstrated experience administering a GRC or authorization tool of record — Xacta, eMASS, CSAM, RSA Archer, ServiceNow IRM, or equivalent. Experience managing POA&M lifecycles at enterprise scale, including risk acceptance workflows with a CISO or authorizing official. Preferred Qualifications Experience in a FISMA-adjacent non-agency environment — a federally chartered corporation, USF administrator, or similar entity where federal standards apply by memorandum of understanding rather than direct statute. Familiarity with FedRAMP authorization packages and SaaS control inheritance. Experience supporting Privacy Act systems of records and PII control implementation under OMB M-17-12. Required Certifications CISSP, or an equivalent information security governance and risk certification demonstrating substantially similar competency and approved by USAC (for example CISM or CGRC/CAP). CISSP is strongly preferred for evaluation positioning. Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process. The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens. K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status. This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice. #J-18808-Ljbffr K2United, LLC.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the ISSO/ISCM Lead in Washington DC vacancy
  •  ...Job Title: ISSO/ISCM Lead (RFP) Job Location: Washington, DC Contractor shall provide an ISSO/ISCM Lead responsible for the strategic coordination of compliance, authorization support, and the comprehensive execution of the Information Security Continuous Monitoring (... 
    Suggested
    For contractors
    Work at office

    Ampcus

    Washington DC
    4 days ago
  • Ampcus, Inc is seeking an ISSO/ISCM Lead in Washington, DC, responsible for overseeing the Information Security Continuous Monitoring (ISCM) program. The role involves strategic coordination of compliance, risk management, and documentation oversight. Candidates should... 
    Suggested
    Work at office

    Ampcus, Inc

    Washington DC
    2 days ago
  •  ...Guidehouse is seeking an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative. You will mentor staff and guide system owners through cloud and on‑premises security in hybrid environments. In... 
    Suggested

    3M HEALTHCARE

    Arlington, VA
    3 days ago
  •  ...insurance Position Overview SecurePro is seeking experienced Lead and Senior Information System Security Officers (ISSOs) to...  ...federal cybersecurity program in Washington, DC. The team will provide ISSO support across a portfolio of approximately 32 FISMA Moderate... 
    Suggested
    Contract work

    Securepro Inc

    Arlington, VA
    5 days ago
  • E-Logic Inc. is seeking an experienced Lead ISSO to support the U.S. International Development Finance Corporation (DFC) Information System Security Officer program. The Lead ISSO will serve as the single point of accountability for technical execution, managing day-to-... 
    Suggested
    For contractors

    E Logic

    Washington DC
    3 days ago
  • Bna Inc in Washington, DC is seeking a Senior ISSO to lead cybersecurity compliance and security operations for federal information systems. This role involves managing multiple cybersecurity activities, supporting classified environments, and requires strong RMF and vulnerability... 

    Bna Inc

    Washington DC
    4 days ago
  • Senior ISSO, RMF and Authorization / Alternate Lead Must be a United States citizen. Must be eligible for a Tier 4 High-Risk Public Trust investigation. Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation. Role: Lead RMF... 

    chameleonintegratedservices

    Washington DC
    4 days ago
  • cFocus Software Incorporated seeks a Lead ISSO to support the United States International Defense Finance Agency (DFC) program. This remote role requires an active Public Trust clearance and hands-on cybersecurity leadership to guide RMF implementations and ATO activities... 
    Remote job

    cFocus Software Incorporated

    Washington DC
    2 days ago
  • E-Logic Inc. seeks a Lead ISSO to support the U.S. International Development Finance Corporation (DFC) Information System Security Officer program. The Lead ISSO will be the single point of accountability for technical execution, managing day-to-day ISSO support activities... 

    E Logic

    Washington DC
    2 days ago
  • Zermount, Inc. is seeking an ISSO Program Manager in Arlington, VA. The successful candidate will provide project management and security expertise, managing a team to ensure compliance and risk management processes align with federal guidelines. Responsibilities include... 
    Remote job

    Zermount, Inc.

    Arlington, VA
    1 day ago
  • Arc Aspicio is seeking an experienced Information Systems Security Officer (ISSO) to support federal programs from the Washington, DC area. The role centers on securing information systems, developing System Security Plans (SSPs) in alignment with NIST SP 800-53 and RMF... 

    Arc Aspicio

    Washington DC
    5 days ago
  • Chameleon Integrated Services seeks a Senior ISSO, RMF and Authorization / Alternate Lead to steer RMF/authorization for a portfolio of DFC systems and to act as the designated Alternate Lead ISSO. The role requires hands-on experience with NIST RMF artifacts and authorization... 

    chameleonintegratedservices

    Washington DC
    2 days ago
  • $85k - $270k

    A technology and security solutions firm is looking for ISSE/ISSO professionals in Laurel, MD. The role requires an active TS/SCI security clearance and offers a competitive pay range of $85,000 - $270,000 per year based on skills and experience. Candidates must have experience... 

    Constellation Technologies, Inc

    Laurel, MD
    2 days ago
  • Euro Staffs seeks a Lead ISSO / Program Manager in Washington, DC, on-site. The role requires directing ISSO activities, coordinating with ISSM and government stakeholders, and managing the program's plans and reports. Candidates should have extensive federal cybersecurity... 

    Euro Staffs

    Washington DC
    1 day ago
  •  ...DFC ISSM. Serves as the single point of contact to the Contracting Officer's Representative. Core responsibilities Direct contractor ISSO activities and ensure consistent execution across all supported systems. Serve as primary technical interface to the ISSM, CISO, AO... 
    Contract work
    For contractors

    RJIT Solutions

    Washington DC
    1 day ago
  • Zermount, Inc is seeking an ISSO Program Manager to lead security governance and RMF activities for a federal client. This role combines project management with cybersecurity expertise to ensure secure, compliant operations across enterprise systems. The role requires... 

    Hiring Our Heroes

    Arlington, VA
    4 days ago
  • Agile Defense, LLC in Washington, DC seeks a Senior ISSO to safeguard government information systems. The role focuses on designing, implementing...  ...robust security architectures, perform risk assessments, and lead incident response activities in high-pressure #J-18808-Ljbffr... 

    Agile Defense, LLC

    Washington DC
    4 days ago
  • E-Logic Inc. is seeking a Senior/Alternate ISSO to support DFC’s cybersecurity program. This role will perform senior ISSO duties for assigned...  ...workstreams. The Alternate ISSO must be qualified to assume Lead ISSO duties during scheduled or unscheduled absences. E-Logic Inc... 

    E-Logic, Inc.

    Washington DC
    3 days ago
  • Fusion Technology LLC is seeking a qualified Information Systems Security Officer to ensure comprehensive security measures for U.S. Government programs. This role requires at least 9 years of experience in a computer science or cybersecurity field and necessitates holding...

    Fusion Technology

    Washington DC
    2 days ago
  • K2United, LLC. in Washington, DC is seeking an experienced information security professional to lead RMF and A&A activities for enterprise systems, ensuring persistent authorization and compliance across all environments. You will coordinate with Security Engineers to... 

    K2United, LLC.

    Washington DC
    4 days ago
  •  ...Job Description Job Description Description: Xtreme Solutions is seeking an experienced Lead Information System Security Officer (ISSO) / Technical Program Lead to provide technical leadership and hands-on cybersecurity support for a federal customer in Washington... 
    For contractors
    Local area

    Xtreme Solutions Corporate

    Washington DC
    5 days ago
  • $150k - $180k

    GovCIO is currently hiring for a Vulnerability Management Team Lead to provide support to a Federal government contract. The Vulnerability...  ...preparation of VM weekly project status reports, updates to the ISSO Forum presentation, updates to the monthly Executive briefing,... 
    Contract work
    Work experience placement
    Currently hiring
    Work at office
    Remote work

    Govcio

    Bethesda, MD
    5 days ago
  • $125k - $175k

    OverviewSteampunk is seeking an ISSO Portfolio Manager / Team Lead to support a federal customer. This role is perfect for someone who blends strong cybersecurity expertise with exceptional customer engagement, coaching, and leadership skills. You’ll guide a team of ISSOs... 
    Contract work
    1 day per week

    Steampunk

    McLean, VA
    2 days ago
  •  ...Security Assessment Lead OCH Technologies is seeking a Security Assessment Lead to act as the technical authority for all independent...  ...with FAA Order 1370.82, FAA Order 1370.121, and the ATO ISCM Plan. Experience supporting FAA Assessment & Authorization (A&... 
    Contract work
    Temporary work
    For contractors
    Local area

    OCH Technologies LLC

    Washington DC
    5 days ago
  • $90.3k - $189.6k

    Job Title: Lead Senior Information System Security OfficerJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required...  ...for a Lead Senior Information System Security Officer (Senior ISSO) to support the FEMA Office of the Chief Information Security... 
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Washington DC
    4 days ago
  •  ...ensure compliance with agency policies and procedures. The ISSPO will lead, and guide efforts associated with obtaining and maintaining RMF...  ...as necessary when Information System Continuous Monitoring (ISCM) results will be used to support continuing authorization requirements... 
    Work at office
    Flexible hours
    2 days per week

    Science Applications International Corporation

    Washington DC
    2 days ago
  • $69.4k - $158k

     ...expertise required to analyze the policies that determine our cyber resilience.As an Information Systems Security Officer (ISSO) on our team, you’ll lead the assessment of the Department of War's IT infrastructure against current cyber policies, including RMF, and identify... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Laurel, MD
    2 days ago
  •  ...focused on continuous monitoring, incident response coordination, and audit support for government clients. The position reports to the Lead ISSO and requires CISSP, hands-on authorization package development, and strong experience with GRC platforms and SIEM tools such as... 
    Full time

    Euro Staffs

    Washington DC
    1 day ago
  •  ...Position Status: Contingent Position Title: Security Assessment Lead Location:Washington, DC Clearance: Secret   Duties and...  ...their purview Ensure Information Systems Security Officers(ISSO) complete a FIPS-199, Privacy Threshold Analysis (PTA), E-Authorizations... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago
  •  ...Position Status: Contingent Position Title: System Compliance Lead Location:Washington, DC Clearance: Secret   Duties and...  ...leadership, System Owners and Information System Security Officers (ISSO): Assist in completing TSA Management Control Objectives... 
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to ISSO/ISCM Lead. Be the first to apply!