1

Isso Consultant Jobs (NOW HIRING)

ISSO 1

Annapolis Junction, MD · On-site

$80K - $95K/yr

We are seeking an ISSO 1 to join our team. In this role, you will: -Provide support to senior ISSOs ... About Tensley Tensley Consulting is a Service-Disabled Veteran-Owned Small Business focused on ...

Senior ISSO

$45 - $65/hr

Senior ISSO Location: Remote Work authorization: US Citizen Position Summary We are seeking ... Careers STSI is an independent US-based Software services and consulting partner with a primary ...

Clear Resolution Consulting is seeking a highly qualified Information Systems Security Officer (ISSO) to support the 414th Combat Training Squadron (414 CTS) Red Flag Vault Operations Services ...

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. They are seeking an ISSO/ISCM Lead responsible for the strategic coordination of compliance ...

next page

Showing results 1-20

Isso Consultant information

What is an ISSO consultant?

An ISSO (Information System Security Officer) Consultant is a cybersecurity professional who specializes in ensuring that an organization's information systems comply with security policies, standards, and regulations. They assess risks, develop security plans, oversee security controls, and provide guidance on maintaining the confidentiality, integrity, and availability of information systems. ISSO Consultants often work with organizations to prepare for security audits and accreditations, and help implement best practices to protect sensitive data from cyber threats.

What are the main challenges ISSO consultants face when ensuring compliance with information security frameworks?

ISSO Consultants often navigate complex regulatory requirements and evolving security standards, which can be challenging as organizations adopt new technologies. A common difficulty is coordinating with multiple departments to ensure consistent implementation of security controls and documentation. Additionally, ISSO Consultants must stay up-to-date on threats and best practices to advise stakeholders effectively, requiring ongoing professional development. Strong communication and problem-solving skills are essential for addressing these challenges and maintaining compliance.

What are the key skills and qualifications needed to thrive as an ISSO consultant, and why are they important?

To excel as an ISSO (Information System Security Officer) Consultant, you need deep knowledge of cybersecurity principles, risk management frameworks (such as NIST RMF), and a relevant degree or certifications like CISSP or CISM. Familiarity with security assessment tools, compliance platforms, and vulnerability management systems is essential. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and interact with clients and stakeholders. These skills ensure robust security posture, regulatory compliance, and the mitigation of information security risks for organizations.

What is the difference between Isso Consultant vs Security Analyst?

AspectIsso ConsultantSecurity Analyst
CredentialsCertifications like CISSP, CISA, CompTIA Security+Certifications like CISSP, GIAC, CompTIA Security+
Work EnvironmentConsulting firms, client sites, IT departmentsIn-house security teams, cybersecurity firms, IT departments
Industry UsageFinancial, healthcare, government, techFinancial, healthcare, government, tech
Primary FocusImplementing security solutions, compliance, risk managementMonitoring security threats, incident response, vulnerability assessment

While both Isso Consultants and Security Analysts work within cybersecurity, Isso Consultants typically focus on implementing security solutions and ensuring compliance for clients, often working across multiple industries. Security Analysts primarily monitor and respond to security threats within an organization. Both roles require similar certifications and industry experience, but their day-to-day responsibilities and work environments differ.

What states have the most Isso Consultant jobs?

States with the most job openings for Isso Consultant jobs include:

What are popular job titles related to Isso Consultant jobs?

For Isso Consultant jobs, the most frequently searched job titles are:

Infographic showing various Isso Consultant job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 7% Part Time, and 6% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution.

Multiple ISSO Consultants

Washington, DC • On-site

Global It Solutions Usi Inc
IT Services • 11 - 50 employees

Other

Posted 29 days ago


Job description

Client Location: Washington D.C.

Work Location: On-site (mandatory)

Duration: 12 months (with another 3 x 12 months extensions)

Position 1:  Lead ISSO Consultant

Resource MUST HAVE an Active Secret or Top Secret Security Clearance with TSI

 Your Responsibilities:

  • You are the Single point of technical accountability for the entire engagement.
  • You direct two Senior ISSOs, own the quality of everything that goes to the Government, and are the primary technical voice to the agency ISSM, CISO, Authorizing Official, and System Owners.

What You Will Own:

  • Directing Senior ISSO workstreams and authorization schedules.
  • Chairing internal quality reviews before any deliverable reaches the Government.
  • Owning the risk and issue register and escalating on a fixed clock.
  • Representing the team in Change Advisory Board, Change Control Board, Enterprise Review Board, and cybersecurity steering committee forums.
  • Preparing Authorizing Official decision briefings.
  • Leading audit, Inspector General, and independent assessment response.
  • Carrying your own portfolio of systems alongside all of that.

Must have Skills:

  • 12-15 years of Federal cybersecurity experience.
  • 8 or more years of Federal ISSO or A&A experience.
  • 5 or more years experience directing other ISSOs, with named individuals reporting to you for technical direction
  • Should have at least one or more active Senior certifications in CISM, CISSP, or CISA
  • Demonstrated direct Stakeholder interface and working relationship with a federal ISSM, CISO, AO, or AODR.
  • Personally review and signed off Authorization package quality control on SSPs, SARs, RARs, POA&Ms, and assessment evidence before Government submission.
  • Led response to a FISMA audit, IG review, or independent security control assessment, including evidence production and finding remediation
  • CSAM administration: Working knowledge of the System Inventory, A&A and ATO, SSP and Security Controls, Assessments, Common Control and Inheritance, POA&M, and Continuous Monitoring modules

Preferred:

  • CISA specifically, because the audit credential maps to a heavy audit and compliance task area.
  • CISSP. A cloud certification such as AWS Solutions Architect or Azure equivalent.
  • Experience migrating control traceability from NIST SP 800-53 Revision 4 to Revision 5 inside CSAM.
  • FedRAMP Customer Responsibility Matrix and Shared Responsibility Matrix reconciliation.
  • Experience at a small federal agency where the ISSO function is thinly staffed and visible to leadership.

  <><><><>

Position 2:. Senior ISSO Consultant

Resource MUST have or eligible to obtain Level 4 Public Trust (OR) Secret Security Clearance.

Your Responsibilities:

  • You lead the continuous monitoring and vulnerability workstreams, and you are the designated backup to the Lead ISSO.
  • You must be able to assume Lead ISSO duties on no notice, which means carrying current knowledge of authorization status, deliverable schedules, open risks, and governance commitments at all times, not reconstructing it when called.

What You Will Own:

  • Monthly continuous monitoring reporting and enterprise dashboards sourced from CSAM telemetry.
  • Splunk log ingestion verification, including catching a log source that has silently stopped forwarding.
  • Vulnerability scan analysis, severity assignment, and false positive determination with documented rationale.
  • POA&M creation within three business days of finding identification and monthly reconciliation between ServiceNow and CSAM.
  • CISA Known Exploited Vulnerabilities and Emergency Directive response on a four-hour notification clock.
  • Assuming Lead ISSO duties during absence.

Must have Skills:

  • 8 or more years of Federal cybersecurity experience:
  • 5 or more years of ISSO, RMF, or authorization experience:
  • Have actually covered for a lead during absence, with responsibility for briefings, prioritization, and artifact approval
  • Should have at least one or more active Senior certifications in CISM, CISSP, or CISA
  • Vulnerability platforms: Production analysis in Tenable Nessus, Qualys, or ACAS, including credentialed scan coverage verification
  • Continuous monitoring: Built and maintained system-level ConMon plans and produced recurring posture reporting for federal decision makers
  • Splunk depth: Log source coverage verification, retention validation, and audit trail completeness, not just dashboard consumption

 Preferred:

  • Microsoft Intune and BigFix, used to confirm asset scope and substantiate POA&M closure.
  • Microsoft Defender for Endpoint, Identity, and Cloud. CyberScope preparation and quarterly or annual FISMA reporting inputs.
  • Inspector General response and penetration test coordination.
  • Security Impact Analysis under NIST SP 800-128.
  • FedRAMP inheritance documentation for AWS or Azure.

  <><><><>

Position 3. Senior ISSO Consultant

Resource MUST have or eligible to obtain Level 4 Public Trust (OR) Secret Security Clearance

Your Responsibilities:

  • Security impact analysis, change coordination, security documentation, and incident response coordination.
  • You are the person who catches the change that quietly expands an authorization boundary before it reaches production.

What You Will Own:

  • Written Security Impact Analyses within three business days of change request receipt, with a defensible disposition and named affected controls.
  • Retrospective SIAs within two business days of emergency changes.
  • Presenting security dispositions at change and release boards.
  • Maintaining SSPs, contingency plans, incident response plans, and control inheritance records in CSAM and designated repositories.
  • ISSO-level incident coordination: system context to responders within one business hour of declaration, Splunk timeline anchoring, situation reports, and root cause analysis inputs.
  • Quarterly reconciliation of inherited controls against provider Customer and Shared Responsibility Matrices.

Must have skills:

  • 6 or more years of Federal cybersecurity experience:
  • 4 or more years of ISSO, RMF, or authorization experience, including senior or lead responsibility
  • Security Impact Analysis like Performing SIA under NIST SP 800-128 and issued written dispositions, not just attended change boards
  • Security documentation like Authoring SSPs, control implementation statements, boundary and data flow content, and inheritance records that survived independent assessment
  • Supported incident response from the ISSO side: system context, log verification, situation reports, corrective action tracking
  • Cloud shared responsibilities like Mapping inherited and common controls for AWS or Azure and documented customer-side responsibilities
  • Should have at least one or more active Senior certifications in CISM, CISSP, CISA, or CASP+

 Preferred:

  • CNSSI 1253 categorization and National Security System control selection.
  • Container and DevSecOps exposure, including Docker and Kubernetes, AWS GovCloud.
  • Experience presenting to a Change Advisory Board or Enterprise Review Board.
  • Jira, Confluence, or Remedy alongside ServiceNow.

Thanks,

Ram M.

Global IT Solutions USI Inc.

Phone:   Ext. 205

Mobile:

E-mail:

An E-Verify Company                        

Certified Minority-owned Business Enterprise (MBE) – New York City (NYC), New York State (