{"schemaVersion":"jobsearcher.job.v1","id":"afb79e6feaa4f9d4f2662cde","url":"https://jobsearcher.com/jobs/afb79e6feaa4f9d4f2662cde","canonicalUrl":"https://jobsearcher.com/jobs/afb79e6feaa4f9d4f2662cde","title":"Lead Information System Security Officer (ISSO)","description":"About Devis\nDevis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies such as DevSecOps, AI, and Machine Learning. With over 30 years of experience, we have established ourselves as a trusted partner for government agencies, delivering tailored, mission-critical solutions that drive digital transformation and operational excellence. Our client-centric approach, coupled with our deep domain expertise and technical prowess, enables us to forge enduring relationships and consistently deliver high-impact, adaptive solutions that resonate with the unique needs of the public sector.\n\nAbout This Role\nAs Lead ISSO, you will manage day-to-day delivery of all ISSO support services and serve as the primary technical interface with the government Information System Security Manager, the CISO, the Authorizing Official and designated representatives, System Owners, and other federal cybersecurity stakeholders. This is a hands-on leadership role rather than a purely administrative one. You will work directly in the agency’s compliance platform, chair quality reviews of authorization artifacts before they reach the government, and carry the technical credibility to defend a risk position in front of federal decision-makers.\n\nWhat You’ll Do\nOwn Technical Execution\nDirect ISSO activities across the full compliance lifecycle: program governance, Risk Management Framework and authorization support, continuous monitoring, vulnerability and POA&M management, security documentation, security impact analysis and change coordination, incident response coordination, and audit and assessment support\nOversee development, quality control, and submission of authorization packages in CSAM\nChair internal quality reviews of every deliverable before it goes to the government\nMaintain personal hands-on proficiency across CSAM, ServiceNow, Splunk, and enterprise vulnerability scanning platforms\nLead the Government Relationship\nServe as the primary technical interface with the government ISSM, CISO, Authorizing Official and designated representatives, System Owners, and Common Control Providers\nRepresent the team in agency governance forums including the Enterprise Review Board, Change Control Board, Cybersecurity Steering Committee, Risk Management Working Group, and Privacy Working Group\nPrepare and present authorization decision briefings to federal leadership\nEscalate risks and issues to government leadership with a recommended course of action attached\nRun the Program\nMaintain the risk and issue register and drive items to documented closure\nProduce weekly activity reports, monthly program status reports, and quarterly executive review materials\nTrack and report service-level and key-performance-indicator results across every work area\nCoordinate with corporate program management on staffing, reporting, and invoicing\nHold the Line on Service Levels\nMeet rapid-response commitments, including four-hour notification on known exploited vulnerabilities, one-business-day triage of critical findings, and one-hour incident acknowledgment during core hours\nMonitor first-time acceptance rates on deliverables and drive corrective action on any nonconformance\nKeep records audit-ready between audits, so evidence can be produced without a scramble\n\nWhat We’re Looking For\nRequired Qualifications\nEducation & Experience\nBachelor’s degree in cybersecurity, computer science, information systems, or a related technical discipline\nMinimum 10 years of cybersecurity experience\nAt least 5 years in ISSO, ISSM, or Risk Management Framework-centric roles supporting federal information systems\nDemonstrated experience leading RMF authorization efforts under NIST SP 800-37 Revision 2, including System Security Plans, security assessment plans and reports, and POA&M lifecycle management\nExperience presenting to and coordinating with federal governance bodies and authorizing officials\nRequired Certifications\nCISSP or CISM, or a comparable advanced security certification\nTechnical Skills\nHands-on experience with a federal governance, risk, and compliance platform. CSAM strongly preferred; eMASS, ArchAngel, or a comparable platform considered where you can demonstrate the ability to transition to CSAM\nWorking proficiency with ServiceNow, Splunk, and an enterprise vulnerability scanner such as Tenable Nessus or Qualys\nWorking knowledge of NIST SP 800-53, NIST SP 800-137, FIPS 199, and CISA Binding Operational Directive requirements including the Known Exploited Vulnerabilities catalog\nFederal-quality technical writing that an authorizing official or independent assessor can rely on without follow-up\nLeadership Capabilities\nTrack record of directing technical staff and holding a team to measurable service levels\nAbility to translate technical risk into terms federal executives can act on\nSound judgment about the boundary between contractor recommendation and government decision authority\nPreferred Qualifications\nFedRAMP inherited-control documentation experience, including Customer and Shared Responsibility Matrix reconciliation\nMicrosoft Azure Government and Microsoft 365 GCC/GCC High experience\nZero Trust architecture experience\nPrivacy documentation experience, including Privacy Threshold Analyses and Privacy Impact Assessments\nPrior experience supporting a small federal agency or a CISO organization\nCurrent or recent Tier 4 High-Risk Public Trust adjudication, or higher\nPerformance Expectations\nSuccess in this role means:\nAuthorization artifacts accepted by the government on first submission\nService-level and key-performance-indicator targets met across every work area\nFederal stakeholders able to make risk decisions without having to come back for more information\nA portfolio that stays audit-ready between audits\nSpecial Requirements\nBased in the Washington, DC metropolitan area. This position requires regular in-person presence at DFC headquarters at 1100 New York Avenue NW for governance forums, authorization briefings, and audit and assessment activity, with remote work between those commitments.\nAuthorization to work in U.S. without restriction.\nMust be eligible for and able to obtain a Tier 4 High-Risk Public Trust background investigation. Adjudication must be complete before privileged access to enterprise security tools or authorization repositories is granted.\nMust obtain and maintain an agency-issued PIV card.\nMust complete agency cybersecurity, privacy, records management, insider threat, and applicable role-based training on entry and annually thereafter.\nAvailability during core business hours, 7:00 a.m. to 6:00 p.m. Eastern, Monday through Friday, excluding federal holidays, and participation in a shared on-call rotation for off-hours incident acknowledgment.\nCompensation & Benefits\n$137,000.00 - $147,000.00 salary commensurate with experience and qualifications.\nThis position is contingent upon contract award.\nDevis is an AA/EOE/M/F/Disabled/VET Employer committed to providing equal employment opportunity without regard to an individual’s race, color, religion, age, gender, sexual orientation, veteran status, national origin or disability.\n4jzHCwPVL7","company":"Developmentinfostructure","rawCompany":"developmentinfostructure","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-15T13:34:18.846Z","occupations":[{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541990","title":"All Other Professional, Scientific, and Technical Services","slug":"all-other-professional-scientific-and-technical-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Information System Security Officer (ISSO)","description":"About Devis\nDevis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies such as DevSecOps, AI, and Machine Learning. With over 30 years of experience, we have established ourselves as a trusted partner for government agencies, delivering tailored, mission-critical solutions that drive digital transformation and operational excellence. Our client-centric approach, coupled with our deep domain expertise and technical prowess, enables us to forge enduring relationships and consistently deliver high-impact, adaptive solutions that resonate with the unique needs of the public sector.\n\nAbout This Role\nAs Lead ISSO, you will manage day-to-day delivery of all ISSO support services and serve as the primary technical interface with the government Information System Security Manager, the CISO, the Authorizing Official and designated representatives, System Owners, and other federal cybersecurity stakeholders. This is a hands-on leadership role rather than a purely administrative one. You will work directly in the agency’s compliance platform, chair quality reviews of authorization artifacts before they reach the government, and carry the technical credibility to defend a risk position in front of federal decision-makers.\n\nWhat You’ll Do\nOwn Technical Execution\nDirect ISSO activities across the full compliance lifecycle: program governance, Risk Management Framework and authorization support, continuous monitoring, vulnerability and POA&M management, security documentation, security impact analysis and change coordination, incident response coordination, and audit and assessment support\nOversee development, quality control, and submission of authorization packages in CSAM\nChair internal quality reviews of every deliverable before it goes to the government\nMaintain personal hands-on proficiency across CSAM, ServiceNow, Splunk, and enterprise vulnerability scanning platforms\nLead the Government Relationship\nServe as the primary technical interface with the government ISSM, CISO, Authorizing Official and designated representatives, System Owners, and Common Control Providers\nRepresent the team in agency governance forums including the Enterprise Review Board, Change Control Board, Cybersecurity Steering Committee, Risk Management Working Group, and Privacy Working Group\nPrepare and present authorization decision briefings to federal leadership\nEscalate risks and issues to government leadership with a recommended course of action attached\nRun the Program\nMaintain the risk and issue register and drive items to documented closure\nProduce weekly activity reports, monthly program status reports, and quarterly executive review materials\nTrack and report service-level and key-performance-indicator results across every work area\nCoordinate with corporate program management on staffing, reporting, and invoicing\nHold the Line on Service Levels\nMeet rapid-response commitments, including four-hour notification on known exploited vulnerabilities, one-business-day triage of critical findings, and one-hour incident acknowledgment during core hours\nMonitor first-time acceptance rates on deliverables and drive corrective action on any nonconformance\nKeep records audit-ready between audits, so evidence can be produced without a scramble\n\nWhat We’re Looking For\nRequired Qualifications\nEducation & Experience\nBachelor’s degree in cybersecurity, computer science, information systems, or a related technical discipline\nMinimum 10 years of cybersecurity experience\nAt least 5 years in ISSO, ISSM, or Risk Management Framework-centric roles supporting federal information systems\nDemonstrated experience leading RMF authorization efforts under NIST SP 800-37 Revision 2, including System Security Plans, security assessment plans and reports, and POA&M lifecycle management\nExperience presenting to and coordinating with federal governance bodies and authorizing officials\nRequired Certifications\nCISSP or CISM, or a comparable advanced security certification\nTechnical Skills\nHands-on experience with a federal governance, risk, and compliance platform. CSAM strongly preferred; eMASS, ArchAngel, or a comparable platform considered where you can demonstrate the ability to transition to CSAM\nWorking proficiency with ServiceNow, Splunk, and an enterprise vulnerability scanner such as Tenable Nessus or Qualys\nWorking knowledge of NIST SP 800-53, NIST SP 800-137, FIPS 199, and CISA Binding Operational Directive requirements including the Known Exploited Vulnerabilities catalog\nFederal-quality technical writing that an authorizing official or independent assessor can rely on without follow-up\nLeadership Capabilities\nTrack record of directing technical staff and holding a team to measurable service levels\nAbility to translate technical risk into terms federal executives can act on\nSound judgment about the boundary between contractor recommendation and government decision authority\nPreferred Qualifications\nFedRAMP inherited-control documentation experience, including Customer and Shared Responsibility Matrix reconciliation\nMicrosoft Azure Government and Microsoft 365 GCC/GCC High experience\nZero Trust architecture experience\nPrivacy documentation experience, including Privacy Threshold Analyses and Privacy Impact Assessments\nPrior experience supporting a small federal agency or a CISO organization\nCurrent or recent Tier 4 High-Risk Public Trust adjudication, or higher\nPerformance Expectations\nSuccess in this role means:\nAuthorization artifacts accepted by the government on first submission\nService-level and key-performance-indicator targets met across every work area\nFederal stakeholders able to make risk decisions without having to come back for more information\nA portfolio that stays audit-ready between audits\nSpecial Requirements\nBased in the Washington, DC metropolitan area. This position requires regular in-person presence at DFC headquarters at 1100 New York Avenue NW for governance forums, authorization briefings, and audit and assessment activity, with remote work between those commitments.\nAuthorization to work in U.S. without restriction.\nMust be eligible for and able to obtain a Tier 4 High-Risk Public Trust background investigation. Adjudication must be complete before privileged access to enterprise security tools or authorization repositories is granted.\nMust obtain and maintain an agency-issued PIV card.\nMust complete agency cybersecurity, privacy, records management, insider threat, and applicable role-based training on entry and annually thereafter.\nAvailability during core business hours, 7:00 a.m. to 6:00 p.m. Eastern, Monday through Friday, excluding federal holidays, and participation in a shared on-call rotation for off-hours incident acknowledgment.\nCompensation & Benefits\n$137,000.00 - $147,000.00 salary commensurate with experience and qualifications.\nThis position is contingent upon contract award.\nDevis is an AA/EOE/M/F/Disabled/VET Employer committed to providing equal employment opportunity without regard to an individual’s race, color, religion, age, gender, sexual orientation, veteran status, national origin or disability.\n4jzHCwPVL7","datePosted":"2026-08-15T13:34:18.846Z","dateModified":"2026-08-15T13:34:18.846Z","hiringOrganization":{"@type":"Organization","name":"Developmentinfostructure","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"afb79e6feaa4f9d4f2662cde"},"url":"https://jobsearcher.com/jobs/afb79e6feaa4f9d4f2662cde"}}