
Lead ISSO Manager
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in United States.
• Act as the primary advisor to senior SSD leadership on all matters related to cybersecurity and compliance for a designated portfolio of major applications, general support systems, and/or cloud environments (including FISMA-based, FedRAMP, Guaranty Agency, and Partner systems, etc.)
• Lead, mentor, and oversee the contractor team comprising ISSOs and junior security analysts.
• Manage the complete Risk Management Framework (RMF) lifecycle (NIST SP 800-37) for all assigned systems, which includes categorization, control selection, implementation, assessment, authorization, and ongoing monitoring.
• Create, maintain, and enforce the organization’s System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), Contingency Plans, Incident Response Plans, and Configuration Management Plans.
• Coordinate and supervise independent Security Controls Assessments (SCA) conducted by third-party assessors (3PAO) and internal red/white teams; review and approve final assessment reports and evidence artifacts.
• Monitor, validate, and drive the resolution of all POA&Ms to completion within the timelines established by FSA and DOED; escalate overdue high/critical findings to executive leadership.
• Ensure full compliance with federal mandates including FISMA, Executive Order 14028, OMB M-22-09 (Zero Trust), CISA Binding Operational Directives (BODs), and the NIST SP 800-53 Rev 5 baseline, inherited, and common controls where applicable.
• Review and approve all change requests, configuration adjustments, and new technology introductions from a security and compliance standpoint.
• Serve as the main liaison with the FSA and ED Security Operations Center (FSA SOC and ED-SOC), CISA, auditors, GAO, and other oversight entities during audits, penetration tests, and incident investigations.
• Prepare and present executive-level briefings, dashboards, and attestation letters (e.g., annual FISMA report, EO 14028 attestation, FedRAMP Significant Change Requests).
• Oversee the organization’s continuous diagnostics and mitigation (CDM) program integration, vulnerability management program, and endpoint detection & extended detection and response (EDR/XDR) operations.
• Develop and maintain security policies, standards, procedures, and guidelines; ensure they are communicated to subcontractors and cloud service providers.
• Supervise secure software supply chain practices (SBOMs, NIST SSDF, EO 14028 §4 requirements) for all custom and COTS software within the portfolio.
• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (Master’s degree preferred).
• A minimum of 10 years of progressive cybersecurity experience, including at least 5 years in an ISSO or senior security control assessor role on federal systems.
• At least 3 years of direct supervisory or team-lead experience.
• Must hold an active Secret clearance.
• Active certification(s) (one or more required): CISSP (must be current), CISSP-ISSMP or CISM (highly preferred), CAP or CGRC (Certified in Governance, Risk and Compliance), CCSP or CCSK (for cloud-heavy environments).
• Proven expert-level knowledge of NIST SP 800-53 Rev 5 (High baseline), 800-37 RMF, 800-137 Continuous Monitoring, FedRAMP and/or DoD RMF processes, Executive Order 14028, and CISA directives, as well as Zero Trust Architecture (NIST 800-207, OMB M-22-09).
• Experience in obtaining and maintaining ATOs at appropriate FISMA or FedRAMP impact levels.
• Exceptional written and verbal communication skills with a demonstrated ability to present to C-level executives and non-technical stakeholders.
• Must be a U.S. Citizen.
• Certification incentive program.
• Paid Time Off (PTO).
• Options for floating federal holidays.
• Various insurance options including HMO and High Deductible plans with Health Savings Accounts (HSAs).
• Flex Spending Accounts (FSAs).
• Comprehensive Dental Plans.
• Vision coverage.
• Short-Term/Long-Term Disability.
• Life Insurance.
• 401k matching program.
ReWorks Solutions
Johnson & Johnson
Thermo Fisher Scientific
Get handpicked remote jobs straight to your inbox weekly.