We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior ISSO, RMF and Authorization / Alternate Lead

Chameleon Integrated Services
United States, D.C., Washington
Jul 23, 2026
Senior ISSO, RMF and Authorization / Alternate Lead
  • Must be a United States citizen.
  • Must be eligible for a Tier 4 High-Risk Public Trust investigation.
  • Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Role:

Lead RMF and authorization work for an assigned portfolio of DFC systems and serve as the designated Alternate Lead ISSO. The candidate must be capable of assuming the Lead ISSO's duties during planned or unplanned absences without a reduction in service.

Primary work includes system categorization, control baseline selection and tailoring, SSP maintenance, inherited-control reconciliation, evidence readiness, assessment coordination, POA&M management, authorization milestone tracking, AO briefing materials, and CSAM workflow management. DFC requires final RMF records to be maintained in CSAM as the authoritative system of record.

Minimum Requirements:
  • At least 8 years of cybersecurity, information assurance, or risk-management experience.
  • At least 5 years performing federal ISSO, A&A, C&A, or RMF work.
  • Led complete authorization or reauthorization packages for federal systems.
  • Hands-on experience with:
    • NIST SP 800-37
    • NIST SP 800-53
    • FIPS 199 system categorization
    • Control tailoring
    • Control implementation statements
    • SSPs
    • SAPs and SARs
    • POA&Ms
    • Risk assessments
    • Assessment evidence
    • Authorization briefings
  • Experience coordinating security-control assessments and responding to assessment findings.
  • Experience maintaining concurrent authorization schedules for multiple systems.
  • Experience supervising or reviewing work performed by junior ISSOs or security analysts.
  • One of:
    • CISSP
    • CGRC/CAP
    • CISM
    • GSLC
  • Bachelor's degree preferred but not mandatory where experience is equivalent.

Competitive Differentiators:
  • Direct CSAM experience
  • Experience migrating authorization records into CSAM or correcting CSAM data quality
  • FedRAMP authorization packages and customer-responsibility matrices
  • Azure Government, Microsoft 365 GCC/GCC High, or ServiceNow FedRAMP environments
  • Common-control-provider and inherited-control reconciliation
  • Ongoing authorization or continuous authorization
  • Civilian-agency FISMA reporting
  • Current Tier 4 or Tier 5 suitability
  • Experience functioning as a deputy or alternate ISSO lead
The resume must clearly identify:
  • Specific systems and authorization boundaries supported
  • System impact levels
  • Exact authorization artifacts prepared
  • GRC system used
  • Number of authorization packages completed
  • Candidate's role in assessment and AO review
  • POA&M creation, validation, tracking, and closure support
  • Examples of inherited-control or shared-responsibility work
  • Examples of package acceptance, reduced rework, schedule recovery, or audit findings resolved


"We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status"

Texting Privacy Policy



  • Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
  • No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
  • Message frequency will vary depending on the application process.Msg & data rates may apply.
  • OPT out at any time by texting "Stop".

Applied = 0

(web-77cf7d65c7-rcc7h)