Solve for today, evolve for tomorrow.
Lead Information Systems Security Officer, ISSO
Location
United States
Posted
3 days ago
Salary
$127.9K - $186.6K / year
Seniority
Senior
Job Description
Lead Information Systems Security Officer, ISSO
Excella
• Lead efforts to gather and organize technical information about the program’s security posture • Collaborate across teams to support ongoing security authorization • Proactively create, monitor, and update POA&Ms • Create Waivers or Risk Acceptance Memos • Conduct annual assessments as per DHS guidelines • Review and update security authorization documents annually • Coordinate with Privacy, Records, and Information Governance Divisions • Conduct Contingency Plan tests • Perform system self-assessments • Monitor and respond to ISVM and Patch Management requirements • Provide audit support through all audit phases • Maintain knowledge of inventory within the accreditation boundary • Ensure security requirements are incorporated into development cycle • Ensure configuration management processes are followed • Respond to emerging requirements from legislation or policy changes • Support annual independent assessments
Job Requirements
- 8+ years of experience in information security
- Expertise in cybersecurity best practices, vulnerability management, and cybersecurity scanning tools
- Expertise in Federal data privacy requirements and cloud-hosted cybersecurity management practices
- One or more certifications: CompTIA Security+, Cloud Security cert, Information Systems Security cert, Information Systems Security Management cert
- Ability to hold and maintain a DHS Public Trust
Benefits
- Top of industry medical, dental, and vision benefits with multiple options
- Employer-contributed health savings account
- Infertility coverage
- Orthodontia
- 8 weeks of Parental Leave
- Discounted pet insurance
- Care.com membership with 3 back-up emergency child or elder care days annually
- Bonus eligible starting day one
- 15 days of paid vacation
- 6 federal holidays
- 4 floating holidays
- TechEleX program for technology needs
- Annual Internet Reimbursement of $25 per month
- 3 days of paid professional development every year
- Wellness events, HeadSpace membership, and access to TalkSpace
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Director of Security
EarnestAt Earnest, we empower you to take control of your career so you can empower students to take control of their finances.
• Lead and scale the security team: Directly manage, mentor, and grow emerging security leaders and engineers, including a Sr Security Engineer, Security Architect, and your existing team members. • Define and evolve security strategy: Build and mature a comprehensive security program from an early stage, aligning security initiatives with overall business and product goals. • Embed security into engineering workflows: Collaborate closely with engineering and product teams to integrate security early in system designs (such as threat and design reviews) and into CI/CD pipelines. • Govern compliance and third-party risk: Own security architecture, operations, engineering, IT compliance, and third-party risk assessment programs to satisfy regulatory and fintech expectations. • Act as a risk-management partner: Serve as a pragmatic advisor who assesses risk and provides business-enabling guardrails rather than acting as a strict gatekeeper. • Communicate across stakeholders: Effectively translate complex security concepts and major risks to non-technical stakeholders, executive leadership, and cross-functional partners.
Security Solutions Specialist
CybitCybit is the one-stop-shop for digital transformation that scales in line with your growth
• Engage with customers to assess current security posture, identify vulnerabilities, gaps and risk exposure, and provide clear, prioritised recommendations for remediation • Lead and support security assessments, workshops and technical consultations • Translate security challenges into structured, actionable roadmaps and solution strategies • Contribute to the development and growth of the Cybit Security Practice, shaping the security proposition and go-to-market approach, and identifying opportunities • Stay up to date with emerging threats, technologies and regulations to provide informed guidance on customer risk and governance • Build strong relationships with strategic security vendors and partners to develop solution offerings and joint go-to-market initiatives • Ensure Cybit’s portfolio remains relevant, differentiated and scalable • Collaborate across technical, operational and sales teams to ensure aligned solutions, smooth delivery and clear visibility of commercial opportunities • Work with the Sales team to identify, develop and progress opportunities with both new and existing customers • Provide technical validation and credibility throughout the sales cycle
AI Security Engineer – Mid-Atlantic Region
GuidePoint SecurityFounded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security
• Advise on and assess the security posture of AI/ML systems, including LLMs, GenAI pipelines, and model serving infrastructure — identifying vulnerabilities, attack surfaces, and gaps against industry frameworks (e.g., OWASP LLM Top 10, MITRE ATLAS) • Lead threat modeling exercises specific to AI workloads, covering adversarial inputs, prompt injection, model inversion, data poisoning, and supply chain risks across SaaS, self-hosted, and local AI deployments. • Advise internal teams on securely integrating SaaS AI services and APIs (e.g., OpenAI, Azure OpenAI, Bedrock) into enterprise applications, including safe handling of credentials, outputs, and user data. • Evaluate and recommend controls for data ingestion pipelines, RAG architectures, and vector databases to prevent unauthorized data exposure, leakage through model outputs, or non-compliant data processing. • Serve as a trusted security advisor bridging business stakeholders, AI/ML engineers, IT operations, and information security teams on all matters related to AI risk and security. • Continuously track emerging AI security research, adversarial techniques, regulatory developments, and vendor security advisories to keep client guidance relevant and proactive. • Produce and maintain security architecture documentation, risk assessments, control frameworks, and guidelines tailored to the organization's AI environment. • Contribute to the development of a long-term AI security strategy, including prioritized remediation roadmaps, capability maturity assessments, and investment recommendations. • Develop and deliver training and awareness content for technical and non-technical stakeholders on AI-specific risks, responsible AI usage, and secure development practices for AI-powered applications.
• own and drive execution of multiple key security initiatives • collaborate with leadership to shape the team’s roadmap • mentor junior team members in the Security team • collaborate with engineering, IT, and product teams • champion continuous improvement in Security Engineering • lead PCI-DSS Compliance initiative • design, implement, and maintain security controls • contribute to threat modeling, risk assessments, and incident response • develop and refine internal security policies, standards, and tools • support and lead security awareness efforts • continuously evaluate emerging threats, technologies, and practices




