Haystack
← Back to Jobs
Administrative

Certified Lead Information Security Officer in Washington, DC

Elegant Enterprise Wide SolutionsWashington, DC🇺🇸United StatesPosted 20 Jul 2026

Why This Role Stands Out

Elevate your cybersecurity career as a Certified Lead Information Security Officer, where you'll lead critical federal client initiatives and shape robust security frameworks, offering significant professional growth. This hybrid role in Washington, DC is ideal for experienced cybersecurity leaders with a proven track record in federal compliance and a passion for driving impactful security strategies. You'll thrive in this position if you possess strong leadership skills and a deep understanding of RMF and FISMA, with the opportunity to further develop your expertise in cutting-edge technologies.

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Location: Washington, DC (Federal Client)
Duration: 12+ Months

Minimum Qualifications:
Bachelor's degree in cybersecurity, information systems, computer science, engineering, or a related discipline.
At least 10 years of progressively responsible cybersecurity experience.
At least 7 years of direct ISSO, RMF, security authorization, or federal cybersecurity compliance experience.
At least 3 years of experience leading ISSO personnel or cybersecurity governance activities.
Demonstrated experience supporting FISMA Moderate systems and NIST RMF activities.
Demonstrated experience developing or reviewing SSPs, SAPs, SARs, POA&Ms, continuous monitoring plans, security impact analyses, and assessment evidence.
Experience coordinating with Authorizing Officials, ISSMs, System Owners, assessors, auditors, SOC personnel, privacy personnel, and technical operations teams.
Experience managing deliverable quality, SLAs, KPIs, risks, issues, corrective actions, and audit evidence.
Ability to obtain and maintain Tier 4 High-Risk Public Trust suitability.
United States citizenship.

Preferred Qualifications
CISSP, CGRC/CAP, CISM, CCSP, or comparable senior cybersecurity certification.
PMP or equivalent program/project management certification.
Experience with CSAM or another federal GRC and authorization platform.
Experience with ServiceNow, Splunk, Tenable Nessus or Qualys.
Experience with Microsoft Azure Government, Microsoft 365 GCCC High, Entra ID, Defender, Intune, and BigFix.
Familiarity with Okta, Palo Alto Panorama, Zscaler, Cisco, and Aruba environments.
Experience with FedRAMP inherited controls, Customer Responsibility Matrices, Shared Responsibility Matrices, and cloud authorization packages.
Experience supporting FISMA audits, Inspector General reviews, GAO audits, penetration tests, and independent security control assessments.

Similar jobs