Senior Cloud ISSO

Fusion TechnologyWashington, DC
Onsite

About The Position

Fusion Technology is seeking a Senior Cloud ISSO to provide services supporting Information System (IS) Security. This role involves the day-to-day implementation, oversight, continuous monitoring, and maintenance of security configurations, practices, and procedures for each IS. The ISSO will act as a liaison between the system owner and other IS security personnel, ensuring that security controls are implemented and operating as intended throughout the IS lifecycle. This includes developing and maintaining system security documentation, conducting vulnerability scans, developing Plans of Action and Milestones (POAMs), and managing risks to ISs and other Agency assets. The role also involves coordinating correction or mitigation actions and tracking their completion. The ISSO will monitor security controls to maintain the Agency's IS Authorized to Operate (ATO) and upload security control evidence to the Governance, Risk, and Compliance (GRC) application. They will report changes affecting authorization status to the System Owner and IS Security Manager (ISSM) and coordinate the removal/retirement of decommissioned IS. This position will also perform Risk Management Assessment and Authorization (A&A) processes for systems in the Cloud, conduct cloud system risk assessments, enhance current process workflows, and develop new processes. The role requires providing cyber security expertise for AWS or Oracle Cloud Infrastructure (OCI) programs, offering Information Assurance guidance during cloud planning, and providing security support with reach back to OCIO. Recommendations for best practices in information security, information assurance, and cloud cybersecurity will be made, along with developing a monitoring and event logging strategy for future cloud migration efforts.

Requirements

  • Requires a Top Secret Clearance
  • Bachelor's Degree preferably in a related discipline with 9 years of experience in a computer science or cybersecurity related field
  • At least 7 years as an Information Systems Security Officer (ISSO) at a cleared facility
  • Familiarity with the use and operation of security tools including Tenable Nessus and/or Security Center, IBM Guardium, HP WebInspect, Network Mapper (NMAP), and/or similar applications
  • Required to hold at least one of the following: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), CompTIA Advanced Security Practitioner (CASP), or other certifications exemplifying skill sets such as those described in DoD Instruction 8570.1 Information Assurance Management (IAM) Level III proficiency
  • Required to hold at least one of the following: AWS Certified Security - Specialty, (ISC)2 Certified Cloud Security Professional (CCSP), AWS Certified Solutions Architect - Associate, AZ-500: Microsoft Certified: Azure Security Engineer Associate, Google - Professional Cloud Security Engineer

Responsibilities

  • Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each IS
  • Liaison support between the system owner and other IS security personnel
  • Ensure that selected security controls are implemented and operating as intended during all phases of the IS lifecycle
  • Ensure that system security documentation is developed, maintained, reviewed, and updated on a continuous basis
  • Conduct required IS vulnerability scans according to risk assessment parameters
  • Develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities
  • Manage the risks to ISs and other Agency assets by coordinating appropriate correction or mitigation actions, and oversee and track the timely completion of (POAMs)
  • Coordinate system owner concurrence for correction or mitigation actions
  • Monitor security controls for The Agency's ISs to maintain security Authorized to Operate (ATO)
  • Upload all security control evidence to the Governance, Risk, and Compliance (GRC) application to support security control implementation during the monitoring phase
  • Ensure changes to The Agency's IS, its environment, and/or operational needs that may affect the authorization status are reported to the System Owner and IS Security Manager (ISSM)
  • Ensure the removal and retirement of IS being decommissioned is in coordination with the System Owner, ISSM, and ISSR
  • Risk Management Assessment and Authorization (A&A) processes for systems in the Cloud
  • Performs Cloud system risk assessments while enhancing their current process workflows and developing new processes
  • Provide cyber security expertise for an AWS or Oracle Cloud Infrastructure (OCI) program
  • Provide Information Assurance perspective and guidance during cloud planning/discussions and provide security support with reach back to OCIO as needed
  • Recommend best practices with regards to information security, information assurance, and cloud cyber security
  • Making recommendations to leadership and developing a monitoring and event logging strategy in the cloud as The Agency considers future cloud migration efforts

Benefits

  • best-in-class matching 401K program
  • comprehensive healthcare plan through Aetna
  • competitive employer contribution to a health savings account
  • vision and dental plans
  • life insurance
  • short- and long-term disability
  • personal leave
  • paid certifications and training
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service