C3EL logo

C3EL

Senior Information System Security Officer (ISSO) at C3EL

Washington, D.C.Full-timeCybersecurityPosted about 1 month ago
Apply with Pipeline

About the Role

<h3 class="iCIMS_InfoMsg iCIMS_InfoField_Job">**CONTINGENT UPON CONTRACT AWARD**</h3> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Overview:</h2> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text"> <p><strong>Job Title:</strong> Senior Information System Security Officer (ISSO)</p> <p><strong>Security Clearance:</strong> Ability to Obtain Tier 4 High-Risk Public Trust</p> <p><strong>Location</strong>: Washington, D.C.</p> <p><strong><em>(Due to the nature of the work and contract requirements, U.S. Citizenship is&nbsp;required.</em></strong>)</p> <p>&nbsp;</p> </div> </div> </div> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Description:</h2> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text"> <p>C3EL is seeking a Senior Information System Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a new contract. This role will serve as the primary Alternate Lead, with deep CSAM, RMF, authorization, FedRAMP, cloud, identity, and assessment expertise, being capable of assuming Lead ISSO duties without service degradation for the program.</p> <p><strong>Responsibilities will include, but not be limited to:</strong></p> <ul> <li>Provide on-site cybersecurity and RMF sustainment support.</li> <li>Independently manage categorization, control selection, implementation evidence, assessment readiness, authorization, and monitoring.</li> <li>Develop and maintain SSPs, SAPs, SARs, POA&amp;Ms, risk assessments, control statements, inheritance records, and evidence packages.</li> <li>Support FedRAMP-authorized cloud services, provider artifacts, customer responsibilities, CRMs, SRMs, and inherited controls.</li> <li>Support privacy controls, PTAs, PIAs, and systems processing PII.</li> <li>Pre-stage evidence and coordinate SCA interviews, walkthroughs, demonstrations, findings, and comment adjudication.</li> <li>Track ATO dates, conditions, milestones, open risks, and briefing materials for AO/AODR decisions.</li> <li>Produce accurate, concise, and audit-ready Government cybersecurity documentation.</li> <li>Support team coverage from 7:00 a.m. to 6:00 p.m. ET (M-F) and participate in after-hours incident coverage as needed.</li> </ul> <p>&nbsp;</p> <h2>&nbsp;Minimum Qualifications:</h2> </div> </div> </div> <div class="iCIMS_InfoMsg iCIMS_InfoMsg_Job"> <div class="iCIMS_Expandable_Container"> <div class="iCIMS_Expandable_Text"> <ul> <li>U.S. Citizenship.</li> <li>Eligibility to obtain a Tier 4 High-Risk Public Trust.</li> <li>Minimum seven (7) years of cybersecurity.</li> <li>Minimum five (5) years in federal RMF, A&amp;A, ISSO, or authorization work.</li> <li>Working knowledge of NIST SP 800-37, 800-53, 800-53B, FIPS 199, FISMA, and applicable CISA/OMB guidance.</li> <li>Familiarity with GRC, ITSM, SIEM, scanner, identity, endpoint and cloud-security platforms.</li> <li>Hands-on CSAM experience supporting system profiles, controls, evidence, POA&amp;Ms, and authorization workflows.</li> <li>Experience with Azure Government, Microsoft 365 GCC/GCC High, and cloud shared-responsibility models.</li> <li>Experience with Entra ID, Okta, privileged access, role assignments, and access recertification.</li> </ul> <p>&nbsp;</p> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Preferred Qualifications:</h2> <ul> <li>At least one current cybersecurity certification such as CISSP, CGRC, CISM, CRISC, Security+, SecurityX, CCSP, or GIAC.</li> </ul> <p>&nbsp;</p> </div> </div> </div> <h2 class="iCIMS_InfoMsg iCIMS_InfoField_Job">Education:</h2> <ul> <li>Associate’s degree in Cybersecurity, Information Technology, or related field. (Relevant experience may be considered in lieu of formal education.)</li> </ul>