ISSO Team Lead
Role summary
AnaVation is seeking an Information System Security Officer (ISSO) Team Lead for a client in Washington DC. This role involves providing expert guidance and leadership in implementing and enforcing information security policies and federal regulations. Responsibilities include overseeing ISSO team members, developing and updating system documentation and SA&A packages, advising on cybersecurity matters across NIST RMF phases, and conducting security control assessments. The position requires a minimum of ten years of ISSO experience, two active certifications (PMP, CISSP, CISM, CEH, CASP, CCSP, CCSK, or Security+), and two years of experience with JCAM. An active Top Secret clearance with SCI Eligibility is mandatory. The role is currently remote but may require a hybrid or onsite presence in the DC-metro area.
AnaVation is seeking an Information System Security Officer (ISSO) Team Lead to support a key client in Washington DC. This individual will provide expert level guidance and leadership in implementing, maintaining, and enforcing information security policies, standards, and methodologies in accordance with federal regulations and agency requirements. This is a working Team Lead role.
What you will be doing
- Directly oversee ISSO team members including technical guidance and training, mentorship, performance management, and day-to-day work assignments
- Develop, review, and update system documentation and FISMA-compliant SA&A packages (e.g., SSP, IRP, SOP, POA&Ms, CMP, IPA, PIA, SORN) in accordance with client policies and procedures to obtain/maintain system accreditation (e.g., ATT, ATO, ATU, OA) using established processes
- Advise the Authorizing Official (AO) and System Owner (SO) on cybersecurity matters related to assigned information systems across all NIST RMF phases, including system categorization, control baselines, control assessments, document and track weaknesses, and oversee corrective actions.
- Serve as a member of the CCB to ensure system security requirements are addressed
- Monitor cybersecurity status of information systems throughout the system lifecycle
- Establish and regularly review audit trails, providing audit logs upon request
- Provide RMF process subject matter expertise across all FISMA-reportable systems
- Conduct SCA per NIST 800-53A, OMB A-130, OMB A-123, and client policies and schedules; report control gaps or weaknesses, risk levels, cost-benefit analysis, and impact to the client
- Maintain a full inventory of hardware and software for the information system
- Develop, coordinate, test, and train staff on Contingency Plans and Incident Response Plans; support Incident Response and DR/COOP activities
- Scan applications, networks, and databases; identify vulnerabilities
Required Qualifications:
Clearance:
Other Required Skills & Qualifications:
Preferred Qualifications:
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance