ISSO

TekSynapFort Belvoir, VA
$110,000 - $170,000Onsite

About The Position

The CSSP ISSO serves as the authoritative Risk Management Framework (RMF) and compliance subject matter expert supporting the Defense Threat Reduction Agency (DTRA). This role acts as a critical validation bridge between the CSSP Protect Team and the CSSP’s subscriber organizations. The ISSO will provide rigorous, specialized validation of cybersecurity artifacts against NIST 800-53 Rev 5 controls requirements to ensure accurate, continuous authorization and risk mitigation from all CSSP subscriber organizations.

Requirements

  • Active Top-Secret Clearance with SCI eligibility required.
  • DoD 8570/8140 IAM Level III
  • DoD 8570/8140 CSSP Auditor equivalent certification
  • 3–8 years of progressive experience in Information Assurance, RMF, and NIST compliance.
  • 2-5 Years working in a SOC or CSSP environment.
  • Extensive, hands-on experience with NIST SP 800-53 (Rev 5 preferred) and DoD RMF processes.
  • BA/BS College degree required.
  • Must be a US Citizen
  • Must possess and maintain an active Top Secret security clearance with SCI eligibility.

Responsibilities

  • Serve as the final layer of validation for RMF artifacts (e.g., Authorization Boundary Diagrams, HW/SW Lists, Credentialed Scans, SSPs, POA&Ms, SARs, SAPs) collected by Protect Analysts from CSSP subscribers, ensuring all evidence accurately satisfies operational directives.
  • Map collected artifacts and subscriber security implementations directly to NIST 800-53 Rev 5 control families, ensuring compliance with federal baseline security standards.
  • Partner closely with CSSP Protect Analysts to translate complex RMF requirements into actionable data-collection requests, bridging the gap between technical cybersecurity operations and formal governance/compliance requirements.
  • Cross-reference technical vulnerability scan data (ACAS, SCAP, HBSS findings) against subscriber-provided artifacts to ensure that active system weaknesses are accurately documented in current POA&Ms.
  • Verify, review, and assist in managing security control baselines and validation evidence directly within the Enterprise Mission Assurance Support Service (eMASS) database for all subscriber enclaves.
  • Evaluate subscriber POA&Ms for accuracy, feasibility, and appropriate risk scoring. Provide clear, actionable feedback to the Protect team and subscribers when artifacts fall short of compliance standards.
  • Work closely with the CSSP Auditor in maintain highly organized, audit-ready repositories of validated artifacts to support JFHQ-DoDIN operational directives and overarching CSSP Evaluator Scoring Metric (ESM) assessments.

Benefits

  • health
  • dental
  • vision
  • 401K
  • life insurance
  • short-term and long-term disability plans
  • vacation time
  • holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service