We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior ISSO

Chameleon Integrated Services
life insurance, 401(k)
United States, D.C., Washington
Jul 23, 2026


We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.

Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity.We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies.We are known for the great care we take with clients and employees, and we believe in promoting from within.

We offer a Full Benefits package including:
  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO and more

Senior ISSO, Continuous Monitoring, Vulnerability, and Incident Coordination
  • Must be a United States citizen.
  • Must be eligible for a Tier 4 High-Risk Public Trust investigation.
  • Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Role:
Lead continuous monitoring, vulnerability management, POA&M execution support, security posture reporting, Splunk validation, and ISSO-level incident coordination for assigned systems.

The position will reconcile vulnerability findings among scanners, ServiceNow, CSAM, remediation teams, and system authorization records. It will support Priority 1 and Priority 2 incidents, prepare situation reports and RCAs, validate Splunk timelines, update POA&Ms, and maintain system-level Continuous Monitoring Plans.

Minimum Requirements:
  • At least 8 years of cybersecurity experience
  • At least 5 years performing federal continuous monitoring, vulnerability management, ISSO, security operations, or related risk-management work
  • Direct experience with:
    • Tenable Nessus, Tenable Security Center, or Qualys
    • Splunk searches, dashboards, or event validation
    • Vulnerability triage and false-positive review
    • POA&M creation and maintenance
    • Finding assignment and remediation coordination
    • Security posture metrics and trend reporting
    • NIST SP 800-53 control monitoring
    • NIST SP 800-137 continuous monitoring
  • Experience coordinating remediation with endpoint, network, cloud, application, and identity teams
  • Experience supporting incident-response documentation, SitReps, after-action reports, or RCAs
  • Understanding of CISA directives, vulnerability-remediation deadlines, and federal logging requirements
  • One of:
    • CISSP
    • CISM
    • CGRC/CAP
    • CySA+ with substantial federal experience
    • GIAC certification relevant to incident response or vulnerability management
  • Must accept participation in an after-hours incident rotation

Competitive Differentiators:
  • Direct CSAM and ServiceNow integration or reconciliation experience.
  • Splunk Enterprise Security.
  • Microsoft Defender for Endpoint, Identity, or Cloud.
  • Tenable.sc or Qualys VMDR.
  • CISA Binding Operational Directives and Known Exploited Vulnerabilities tracking.
  • Azure and Microsoft 365 security monitoring.
  • Palo Alto, Zscaler, Entra ID, Okta, or endpoint-management experience.
  • Federal major-incident or P1 incident support.
  • Experience building ConMon dashboards for executive review.
  • Current Tier 4 or Tier 5 suitability.
The resume must clearly identify:
  • Number of assets, systems, or authorization boundaries monitored.
  • Scanner and SIEM tools used.
  • Candidate's role in vulnerability validation and POA&M administration.
  • Finding volume, backlog, aging, closure, or remediation metrics.
  • Incident severity and documentation responsibilities.
  • Splunk queries, timeline validation, or dashboards developed.
  • Examples of coordination with technical remediation teams.
  • Examples where monitoring results changed system risk posture or authorization records.


"We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status"

Texting Privacy Policy



  • Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
  • No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
  • Message frequency will vary depending on the application process.Msg & data rates may apply.
  • OPT out at any time by texting "Stop".

Applied = 0

(web-77cf7d65c7-rcc7h)