Haystack
← Back to Jobs
Technology

Multiple ISSO Consultants

Global It Solutions Usi IncWashington, DC🇺🇸United StatesPosted 14 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Client Location: Washington D.C.

Work Location: On-site (mandatory)

Duration: 12 months (with another 3 x 12 months extensions)

 

Position 1:  Lead ISSO Consultant

Resource MUST HAVE an Active Secret or Top Secret Security Clearance with TSI

 Your Responsibilities:

  • You are the Single point of technical accountability for the entire engagement.
  • You direct two Senior ISSOs, own the quality of everything that goes to the Government, and are the primary technical voice to the agency ISSM, CISO, Authorizing Official, and System Owners.

What You Will Own:

  • Directing Senior ISSO workstreams and authorization schedules.
  • Chairing internal quality reviews before any deliverable reaches the Government.
  • Owning the risk and issue register and escalating on a fixed clock.
  • Representing the team in Change Advisory Board, Change Control Board, Enterprise Review Board, and cybersecurity steering committee forums.
  • Preparing Authorizing Official decision briefings.
  • Leading audit, Inspector General, and independent assessment response.
  • Carrying your own portfolio of systems alongside all of that.

Must have Skills:

  • 12-15 years of Federal cybersecurity experience.
  • 8 or more years of Federal ISSO or A&A experience.
  • 5 or more years experience directing other ISSOs, with named individuals reporting to you for technical direction
  • Should have at least one or more active Senior certifications in CISM, CISSP, or CISA
  • Demonstrated direct Stakeholder interface and working relationship with a federal ISSM, CISO, AO, or AODR.
  • Personally review and signed off Authorization package quality control on SSPs, SARs, RARs, POA&Ms, and assessment evidence before Government submission.
  • Led response to a FISMA audit, IG review, or independent security control assessment, including evidence production and finding remediation
  • CSAM administration: Working knowledge of the System Inventory, A&A and ATO, SSP and Security Controls, Assessments, Common Control and Inheritance, POA&M, and Continuous Monitoring modules

Preferred:

  • CISA specifically, because the audit credential maps to a heavy audit and compliance task area.
  • CISSP. A cloud certification such as AWS Solutions Architect or Azure equivalent.
  • Experience migrating control traceability from NIST SP 800-53 Revision 4 to Revision 5 inside CSAM.
  • FedRAMP Customer Responsibility Matrix and Shared Responsibility Matrix reconciliation.
  • Experience at a small federal agency where the ISSO function is thinly staffed and visible to leadership.

  <><><><>

Position 2:. Senior ISSO Consultant

Resource MUST have or eligible to obtain Level 4 Public Trust (OR) Secret Security Clearance.

Your Responsibilities:

  • You lead the continuous monitoring and vulnerability workstreams, and you are the designated backup to the Lead ISSO.
  • You must be able to assume Lead ISSO duties on no notice, which means carrying current knowledge of authorization status, deliverable schedules, open risks, and governance commitments at all times, not reconstructing it when called.

What You Will Own:

  • Monthly continuous monitoring reporting and enterprise dashboards sourced from CSAM telemetry.
  • Splunk log ingestion verification, including catching a log source that has silently stopped forwarding.
  • Vulnerability scan analysis, severity assignment, and false positive determination with documented rationale.
  • POA&M creation within three business days of finding identification and monthly reconciliation between ServiceNow and CSAM.
  • CISA Known Exploited Vulnerabilities and Emergency Directive response on a four-hour notification clock.
  • Assuming Lead ISSO duties during absence.

Must have Skills:

  • 8 or more years of Federal cybersecurity experience:
  • 5 or more years of ISSO, RMF, or authorization experience:
  • Have actually covered for a lead during absence, with responsibility for briefings, prioritization, and artifact approval
  • Should have at least one or more active Senior certifications in CISM, CISSP, or CISA
  • Vulnerability platforms: Production analysis in Tenable Nessus, Qualys, or ACAS, including credentialed scan coverage verification
  • Continuous monitoring: Built and maintained system-level ConMon plans and produced recurring posture reporting for federal decision makers
  • Splunk depth: Log source coverage verification, retention validation, and audit trail completeness, not just dashboard consumption

 Preferred:

  • Microsoft Intune and BigFix, used to confirm asset scope and substantiate POA&M closure.
  • Microsoft Defender for Endpoint, Identity, and Cloud. CyberScope preparation and quarterly or annual FISMA reporting inputs.
  • Inspector General response and penetration test coordination.
  • Security Impact Analysis under NIST SP 800-128.
  • FedRAMP inheritance documentation for AWS or Azure.

  <><><><>

Position 3. Senior ISSO Consultant

Resource MUST have or eligible to obtain Level 4 Public Trust (OR) Secret Security Clearance

Your Responsibilities:

  • Security impact analysis, change coordination, security documentation, and incident response coordination.
  • You are the person who catches the change that quietly expands an authorization boundary before it reaches production.

What You Will Own:

  • Written Security Impact Analyses within three business days of change request receipt, with a defensible disposition and named affected controls.
  • Retrospective SIAs within two business days of emergency changes.
  • Presenting security dispositions at change and release boards.
  • Maintaining SSPs, contingency plans, incident response plans, and control inheritance records in CSAM and designated repositories.
  • ISSO-level incident coordination: system context to responders within one business hour of declaration, Splunk timeline anchoring, situation reports, and root cause analysis inputs.
  • Quarterly reconciliation of inherited controls against provider Customer and Shared Responsibility Matrices.

Must have skills:

  • 6 or more years of Federal cybersecurity experience:
  • 4 or more years of ISSO, RMF, or authorization experience, including senior or lead responsibility
  • Security Impact Analysis like Performing SIA under NIST SP 800-128 and issued written dispositions, not just attended change boards
  • Security documentation like Authoring SSPs, control implementation statements, boundary and data flow content, and inheritance records that survived independent assessment
  • Supported incident response from the ISSO side: system context, log verification, situation reports, corrective action tracking
  • Cloud shared responsibilities like Mapping inherited and common controls for AWS or Azure and documented customer-side responsibilities
  • Should have at least one or more active Senior certifications in CISM, CISSP, CISA, or CASP+

 Preferred:

  • CNSSI 1253 categorization and National Security System control selection.
  • Container and DevSecOps exposure, including Docker and Kubernetes, AWS GovCloud.
  • Experience presenting to a Change Advisory Board or Enterprise Review Board.
  • Jira, Confluence, or Remedy alongside ServiceNow.

Thanks,

Ram M.

Global IT Solutions USI Inc.

Phone:   Ext. 205

Mobile:

E-mail:

 

An E-Verify Company                        

Certified Minority-owned Business Enterprise (MBE) – New York City (NYC), New York State (NYS) and The Port Authority of New York & New Jersey (PANYNJ)

Skills

Docker
AWS
Splunk
Azure
Compliance
Confluence
Jira
Kubernetes
Reconciliation
Root Cause Analysis
ServiceNow

Similar jobs