ISSO Lead
Paragon Technology Group, Inc. | |
United States, D.C., Washington | |
Aug 28, 2026 | |
|
ISSO Lead Paragon is seeking an experienced Information System Security Officer (ISSO) Lead to support the Department of State, Bureau of Diplomatic Technology (DT), Enterprise Applications (EA), Consular Systems and Technology (CST). The ISSO Lead will provide leadership and oversight for cybersecurity compliance, Risk Management Framework (RMF), Assessment and Authorization (A&A), continuous monitoring, and security risk management activities supporting Consular Affairs information systems. The ISSO Lead is responsible for maintaining an accurate, current portfolio of consular systems, including system lifecycle and authorization status, and providing a high-level view of risk assessment and risk management activities. The Lead also maintains version control and supports preparation of cybersecurity briefings and reports. The ISSO is the primary cybersecurity point of contact for assigned systems and requires support for system security documentation, categorization, security-control implementation and monitoring, and coordination with system owners, administrators, and other security stakeholders. Key Responsibilities * Maintain an accurate and up-to-date portfolio of supported consular systems, including system lifecycle, ATO/authorization status, significant cybersecurity risks, risk assessments, and risk-management activities. * Provide leadership and coordination for ISSO activities across assigned Department of State systems and serve as a senior cybersecurity point of contact. * Maintain appropriate document and artifact version control and assist with development of executive briefings, reports, metrics, findings, and recommendations. * Oversee and support the development, maintenance, and updating of System Security Plans (SSPs), Risk Assessments, Plans of Action and Milestones (POA&Ms), and other RMF documentation. * Ensure systems are appropriately categorized using FIPS 199 and NIST SP 800-60 and that applicable controls are selected, documented, implemented, and continuously monitored in accordance with NIST SP 800-53 Rev. 5. * Support continuous monitoring activities, including vulnerability scanning, patch-management reviews, audit-log analysis, and risk scoring. * Review security documentation supporting maintenance and renewal of Authorizations to Operate (ATOs). * Coordinate with system-specific security operations contractors and incorporate technical evidence, vulnerability information, operational findings, and security data into RMF documentation and A&A packages. * Develop and deliver ISSO reports describing compliance status, cybersecurity metrics, findings, risks, and recommendations; support quarterly FISMA reporting and annual FISMA reviews; and communicate identified threats, vulnerabilities, and compliance risks to stakeholders. * Support system authorization activities necessary to obtain and maintain ATOs, ensuring traceability of security controls, artifacts, and risk decisions throughout the RMF lifecycle. * Provide input to Security Assessment Reports (SARs), track remediation and issue-resolution status, and ensure security considerations are integrated throughout the system development lifecycle, including DevSecOps environments. * Support vulnerability and compliance scanning activities using tools such as Tenable Nessus for on-premises systems and Wiz for cloud-based systems, including integration of scanning information into broader risk-management and compliance activities. * Coordinate with system owners, system administrators, engineers, ISSMs, Authorizing Officials and their representatives, assessors, and other cybersecurity stakeholders to maintain an accurate understanding of system security posture. * Identify and elevate risks that could affect authorization status and recommend appropriate risk responses, including mitigation, acceptance, or transfer. Required Qualifications * Bachelor's degree. * Minimum eight (8) years of relevant experience. * CISSP, CISM, or equivalent cybersecurity certification. * The position requires a final Secret personnel security clearance at the start of performance and U.S. citizenship. * Demonstrated experience supporting information-system cybersecurity, RMF, FISMA compliance, A&A, and ATO processes. * Experience developing, reviewing, or managing cybersecurity and RMF artifacts such as SSPs, POA&Ms, risk assessments, SARs, security-control implementation statements, and continuous-monitoring documentation. * Demonstrated ability to track multiple systems and provide portfolio-level visibility into authorization status, cybersecurity risk, compliance status, and remediation activities. * Experience preparing cybersecurity metrics, reports, briefings, and recommendations for technical and management stakeholders. * Working knowledge of NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, FIPS 199, and NIST SP 800-60. * Strong leadership, organizational, analytical, written communication, and stakeholder-coordination skills. Work Location The position is primarily contractor-site based; however, because the ISSO Lead is designated Key Personnel, the individual must reside within a reasonable commuting distance of State Annex 17, 600 19th Street NW, Washington, D.C., and must be available for onsite meetings, mission-critical activities, and other Government-directed support as required. | |
Aug 28, 2026