
Lead Information System Security Officer
Agile Defense
full-time
Posted on:
Location Type: Hybrid
Location: Reston • Virginia • United States
Visit company websiteExplore more
Job Level
Tech Stack
About the role
- Expertise in applying the Risk Management Framework (RMF) and NIST 800-series standards to protect multi-tenant cloud and hybrid-enterprise environments.
- Conduct deep-dive vulnerability analyses and engineering remediation plans that satisfy rigorous FISMA requirements.
- Translate technical security gaps into clear, executive-level narratives that facilitate informed risk-management decisions.
- Extensive experience with security authorization processes, such as Authorization/Certification & Accreditation (A&A) and Authorization to Operate (ATO).
- Strong understanding of current security tools, multi-tenant cloud environments, hardware/software security implementation, communication protocols, and encryption techniques.
- Analyze security vulnerabilities, provide comprehensive assessments, and develop effective remediation instructions.
- Present complex security information clearly and effectively to diverse audiences.
Requirements
- Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity
- A minimum of 8 years of experience in information security, with at least 5 years specifically in a lead ISSO or similar leadership capacity on large complex USG programs.
- One or more of the following certifications required:
- Active Certified Information Systems Security Professional (CISSP)
- Active Certified Information Security Manager (CISM)
- Other relevant certifications (e.g., CCSP, CEH) may be considered.
- Active CISSP
- Active Project Management Professional (PMP) certification
- Active ISC2 Certified in Governance, Risk and Compliance (CGRC)
- Knowledge of FedRAMP
- Knowledge of A-123 audit Experience and Expertise with GRC tools such as CSAM
Benefits
- Competitive and comprehensive benefits package
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
Risk Management Framework (RMF)NIST 800-series standardsvulnerability analysisFISMA compliancesecurity authorization processesAuthorization/Certification & Accreditation (A&A)Authorization to Operate (ATO)encryption techniquesremediation instructionssecurity assessments
Soft Skills
communicationleadershippresentation skillsnarrative developmentrisk management decision facilitation
Certifications
Certified Information Systems Security Professional (CISSP)Certified Information Security Manager (CISM)Certified Cloud Security Professional (CCSP)Certified Ethical Hacker (CEH)Project Management Professional (PMP)Certified in Governance, Risk and Compliance (CGRC)