Purpose. Carry continuous monitoring, incident response coordination, and audit and assessment support; serve as second-line backup to the Lead ISSO.
Reports to: Lead ISSO for task direction.
Core responsibilities.
- Execute continuous monitoring and security posture management, producing outputs that support Government risk decisions, audit readiness, and ongoing authorization.
- Coordinate incident response with the DFC SOC, meeting the acknowledgement and notification timeframes in the PWS, and maintain incident documentation and after-action records.
- Support audits and assessments: maintain audit-ready evidence, sustain traceability between requirements and artifacts, reduce evidence-collection burden on Government staff, and identify documentation gaps before assessors do.
- Support vulnerability analysis and POA&M lifecycle activities in coordination with remediation teams, recognizing that closure approval, schedule extensions, and risk acceptance are reserved to Government officials.
- Maintain proficiency in CSAM, ServiceNow, Splunk, and the vulnerability scanning platforms in use.
Required qualifications. Ten or more years of federal cybersecurity experience. Hands-on authorization package development and security control assessment. Operational experience with a federal GRC platform and an enterprise SIEM. Demonstrated coordination with an agency security operations center during live incidents. Active CISSP.
Preferred. CGRC or CEH. Direct CSAM experience. Prior support to a federal civilian CISO organization. Existing federal background investigation eligible for reciprocity under PWS 5.4.