1

Sr Isso Jobs (NOW HIRING)

Cybersecurity - Lead ISSO

Arlington, VA · On-site

$12K - $15K/mo

Candidates will be considered for either the Lead ISSO or Senior ISSO role based on experience and qualifications. Key Responsibilities * Execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA ...

Cybersecurity - Lead ISSO

Arlington, VA · On-site

$120 - $190/hr

Candidates will be considered for either the Lead ISSO or Senior ISSO role based on experience and qualifications. Key Responsibilities * Execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA ...

$130 - $175/hr

The Sr. ISSO-TS/SCI FS Poly will plan, manage, coordinate and provide support to various programs to ensure that the completion of all Assessment and Authorization (A&A) activities per ICD 503, NISTs ...

Senior Information Security Engineer (ISSO)

$109K - $147K/yr

The Senior ISSO serves as an experienced security practitioner responsible for performing RMF activities, maintaining authorization documentation, evaluating compliance requirements, and supporting ...

The work The Sr. ISSO is responsible for leading the end-to-end security readiness of applications, ensuring compliance with federal and enterprise security frameworks, ATO processes, and risk ...

Minimum of 7+ years of experience as an ISSO supporting IC or DoD programs and contracts of similar scope, type, and complexity. DoD 8570 compliance with IAM Level II or IAT Level III (i.e., CASP ...

Showing results 21-40

Sr Isso information

See salary details

$46K

$118.3K

$184.5K

How much do sr isso jobs pay per year?

As of Sep 4, 2026, the average yearly pay for sr isso in the United States is $118,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,000.00 and $138,000.00 per year, depending on experience, location, and employer.

What is a Sr ISSO?

A Sr ISSE, or Senior Information Systems Security Engineer, is a professional responsible for designing, implementing, and maintaining security measures for an organization’s information systems. They ensure that systems comply with security policies and regulations, conduct risk assessments, and oversee the integration of security protocols into IT projects. Sr ISSEs often act as subject matter experts on cybersecurity, working closely with other IT staff to mitigate threats and vulnerabilities. Their role is critical in safeguarding sensitive data and maintaining the overall security posture of the organization.

How does a Sr ISSO typically collaborate with other departments to ensure information security compliance?

A Sr Information System Security Officer (Sr ISSO) works closely with IT, legal, compliance, and business units to ensure that security policies are effectively implemented across the organization. Collaboration often includes regularly reviewing security controls with system administrators, coordinating with compliance teams for audits, and advising project managers on security best practices during new system implementations. Effective communication and cross-functional teamwork are essential, as the Sr ISSO must balance technical requirements with business needs while ensuring adherence to regulatory standards.

What are the key skills and qualifications needed to thrive as a Sr ISSO, and why are they important?

To thrive as a Sr. Information Systems Security Officer (Sr ISSE), you need deep expertise in information security principles, risk management, and compliance frameworks, usually backed by a relevant degree and certifications such as CISSP or CISM. Familiarity with security tools like SIEM platforms, vulnerability scanners, and governance, risk, and compliance (GRC) systems is vital. Excellent communication, leadership, and analytical problem-solving skills set top performers apart in this role. These skills ensure robust security postures, effective incident response, and regulatory compliance in complex IT environments.

What is the difference between Sr Isso vs Data Analyst?

AspectSr IssoData Analyst
Required CredentialsBachelor's degree, certifications in data management or business intelligenceBachelor's degree in data science, statistics, or related field
Work EnvironmentCorporate, IT, or data-driven departmentsBusiness, finance, marketing, or IT teams
Employer & Industry UsageUsed in tech, finance, healthcare, and large organizationsCommon across industries for data interpretation and reporting
Search & Comparison IntentYesYes

The main difference between Sr Isso and Data Analyst lies in their scope and seniority. Sr Isso typically involves more advanced responsibilities, such as overseeing data processes and mentoring junior staff, whereas Data Analysts focus on analyzing data and generating reports. Both roles require similar educational backgrounds and are prevalent across various industries, but Sr Isso positions usually demand more experience and technical expertise.

More about Sr Isso jobs

What cities are hiring for Sr Isso jobs?

Cities with the most Sr Isso job openings:

What states have the most Sr Isso jobs?

States with the most job openings for Sr Isso jobs include:

What job categories do people searching Sr Isso jobs look for?

The top searched job categories for Sr Isso jobs are:

Infographic showing various Sr Isso job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, and 10% Contract. Highlights an 70% In-person, 5% Hybrid, and 25% Remote job distribution, with an average salary of $118,327 per year, or $56.9 per hour.

Cybersecurity - Lead ISSO

Securepro Inc

Arlington, VA • On-site

$12K - $15K/mo

Full-time

Medical, Dental, Retirement

Posted 17 days ago


Key responsibilities

  • Support and execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA Moderate systems.

  • Develop, review, and maintain security authorization packages including SSPs, SARs, RARs, POA&Ms, and assessment evidence.

  • Coordinate cybersecurity incident response activities and support FISMA audits, reviews, and assessments.


Job description

Benefits:
  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance

Position Overview
SecurePro is seeking experienced Lead and Senior Information System Security Officers (ISSOs) to support a federal cybersecurity program in Washington, DC. The team will provide ISSO support across a portfolio of approximately 32 FISMA Moderate information systems, including Risk Management Framework (RMF) and authorization activities, continuous monitoring, vulnerability management, POA&M execution, security documentation, security impact analysis, incident coordination, and audit support.
This is a hands-on, on-site position supporting a federal environment. Candidates will be considered for either the Lead ISSO or Senior ISSO role based on experience and qualifications.
Key Responsibilities
  • Execute the NIST SP 800-37 Rev. 2 RMF lifecycle for FISMA Moderate systems.
  • Develop, maintain, review, and quality-control authorization packages including SSPs, SARs, RARs, POA&Ms, security controls, and assessment evidence.
  • Manage POA&Ms from finding identification through validated closure.
  • Perform continuous monitoring and vulnerability analysis.
  • Verify security logging and audit coverage using Splunk.
  • Maintain authorization and compliance information in CSAM as the authoritative GRC platform.
  • Maintain ticket-to-POA&M traceability using ServiceNow.
  • Perform Security Impact Analyses for system and infrastructure changes.
  • Coordinate cybersecurity incident response activities and corrective actions.
  • Support FISMA audits, Inspector General reviews, independent assessments, and evidence requests.
  • Review inherited and common controls for AWS and Azure environments.
  • Participate in Change Advisory Boards, Change Control Boards, Enterprise Review Boards, and cybersecurity governance forums.
  • Coordinate with federal ISSMs, CISOs, Authorizing Officials, System Owners, and other cybersecurity stakeholders.
Lead ISSO Responsibilities
The Lead ISSO will serve as the primary technical lead for the engagement and will:
  • Direct Senior ISSO workstreams and authorization schedules.
  • Perform quality reviews before cybersecurity deliverables are submitted to the Government.
  • Own cybersecurity risk and issue tracking and escalation.
  • Prepare Authorizing Official decision briefings.
  • Lead responses to audits, IG reviews, and independent assessments.
  • Provide technical direction to other ISSOs while maintaining responsibility for an assigned system portfolio.
Required Qualifications — All Candidates
  • U.S. citizenship required.
  • Ability to obtain and maintain a Tier 4 High Risk Public Trust.
  • Hands-on experience with CSAM supporting federal authorization and RMF activities.
  • Experience executing NIST SP 800-37 Rev. 2 RMF for FISMA Moderate systems.
  • Hands-on ownership of the POA&M lifecycle through validated closure.
  • Working proficiency with Splunk and ServiceNow.
  • Experience developing and maintaining federal cybersecurity documentation.
  • Ability to work on-site in Washington, DC, five days per week.
  • Knowledge of NIST SP 800-53 security controls and federal cybersecurity requirements.
Lead ISSO Qualifications
  • 10+ years of federal cybersecurity experience.
  • 8+ years of federal ISSO, RMF, or Assessment & Authorization experience.
  • 5+ years providing technical direction to other ISSOs.
  • Demonstrated experience working directly with federal ISSMs, CISOs, Authorizing Officials, or AODRs.
  • Experience reviewing and approving SSPs, SARs, RARs, POA&Ms, and assessment evidence.
  • Experience leading FISMA audits, Inspector General reviews, or independent security assessments.
  • Working knowledge of CSAM System Inventory, A&A/ATO, SSP/Security Controls, Assessments, Common Control/Inheritance, POA&M, and Continuous Monitoring modules.
  • At least one active certification: CISM, CISSP, or CISA.
Senior ISSO Qualifications
  • 6–8+ years of federal cybersecurity experience, depending on position level.
  • 4–5+ years of ISSO, RMF, or federal authorization experience.
  • Experience with continuous monitoring, vulnerability management, security documentation, incident coordination, or Security Impact Analysis.
  • Experience with vulnerability platforms such as Tenable Nessus, Qualys, or ACAS.
  • Experience validating Splunk log-source coverage, retention, and audit-trail completeness.
  • Experience authoring SSPs, control implementation statements, system boundary/data-flow documentation, and control inheritance records.
  • At least one active certification such as CISM, CISSP, CISA, or CASP+.
  • Candidates considered for the Alternate Lead role must have experience assuming lead responsibilities, including briefings, prioritization, and artifact approval.
Preferred Qualifications
  • Active federal Public Trust or security clearance.
  • CISA certification.
  • AWS or Azure cloud certification.
  • AWS GovCloud or Azure Government experience.
  • FedRAMP shared-responsibility and control-inheritance experience.
  • NIST SP 800-53 Rev. 4 to Rev. 5 transition experience.
  • Microsoft Defender, Intune, BigFix, Palo Alto, Zscaler, Okta, or Entra ID experience.
  • CyberScope and federal FISMA reporting experience.
  • NIST SP 800-128 Security Impact Analysis experience.
  • Container, Kubernetes, or DevSecOps exposure.
  • Experience supporting federal audit, penetration testing, or Inspector General activities.
Work Environment
The engagement supports a hybrid federal technology environment that may include Azure Government, Microsoft 365 GCC/GCC High, Entra ID, Okta, Palo Alto, Zscaler, Tenable or Qualys, Microsoft Defender, Intune, BigFix, Splunk, ServiceNow, and CSAM.
This position is on-site in Washington, DC and is not remote or hybrid.
SecurePro is an equal opportunity employer. Employment for these positions is contingent upon contract award and successful completion of applicable federal suitability and onboarding requirements.