The Role
Lead continuous monitoring, vulnerability management, POA&M administration, security posture reporting, Splunk validation, and ISSO-level incident coordination. Reconcile scanner findings across tools, support Priority 1/2 incidents, produce SitReps/RCAs, update POA&Ms, maintain continuous monitoring plans, and coordinate remediation with technical teams.
Summary Generated by Built In
We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
We offer a Full Benefits package including:
Senior ISSO, Continuous Monitoring, Vulnerability, and Incident Coordination
Lead continuous monitoring, vulnerability management, POA&M execution support, security posture reporting, Splunk validation, and ISSO-level incident coordination for assigned systems.
The position will reconcile vulnerability findings among scanners, ServiceNow, CSAM, remediation teams, and system authorization records. It will support Priority 1 and Priority 2 incidents, prepare situation reports and RCAs, validate Splunk timelines, update POA&Ms, and maintain system-level Continuous Monitoring Plans.
Minimum Requirements:
Competitive Differentiators:
We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
We offer a Full Benefits package including:
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
Senior ISSO, Continuous Monitoring, Vulnerability, and Incident Coordination
- Must be a United States citizen.
- Must be eligible for a Tier 4 High-Risk Public Trust investigation.
- Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Lead continuous monitoring, vulnerability management, POA&M execution support, security posture reporting, Splunk validation, and ISSO-level incident coordination for assigned systems.
The position will reconcile vulnerability findings among scanners, ServiceNow, CSAM, remediation teams, and system authorization records. It will support Priority 1 and Priority 2 incidents, prepare situation reports and RCAs, validate Splunk timelines, update POA&Ms, and maintain system-level Continuous Monitoring Plans.
Minimum Requirements:
- At least 8 years of cybersecurity experience
- At least 5 years performing federal continuous monitoring, vulnerability management, ISSO, security operations, or related risk-management work
- Direct experience with:
- Tenable Nessus, Tenable Security Center, or Qualys
- Splunk searches, dashboards, or event validation
- Vulnerability triage and false-positive review
- POA&M creation and maintenance
- Finding assignment and remediation coordination
- Security posture metrics and trend reporting
- NIST SP 800-53 control monitoring
- NIST SP 800-137 continuous monitoring
- Experience coordinating remediation with endpoint, network, cloud, application, and identity teams
- Experience supporting incident-response documentation, SitReps, after-action reports, or RCAs
- Understanding of CISA directives, vulnerability-remediation deadlines, and federal logging requirements
- One of:
- CISSP
- CISM
- CGRC/CAP
- CySA+ with substantial federal experience
- GIAC certification relevant to incident response or vulnerability management
- Must accept participation in an after-hours incident rotation
Competitive Differentiators:
- Direct CSAM and ServiceNow integration or reconciliation experience.
- Splunk Enterprise Security.
- Microsoft Defender for Endpoint, Identity, or Cloud.
- Tenable.sc or Qualys VMDR.
- CISA Binding Operational Directives and Known Exploited Vulnerabilities tracking.
- Azure and Microsoft 365 security monitoring.
- Palo Alto, Zscaler, Entra ID, Okta, or endpoint-management experience.
- Federal major-incident or P1 incident support.
- Experience building ConMon dashboards for executive review.
- Current Tier 4 or Tier 5 suitability.
- Number of assets, systems, or authorization boundaries monitored.
- Scanner and SIEM tools used.
- Candidate’s role in vulnerability validation and POA&M administration.
- Finding volume, backlog, aging, closure, or remediation metrics.
- Incident severity and documentation responsibilities.
- Splunk queries, timeline validation, or dashboards developed.
- Examples of coordination with technical remediation teams.
- Examples where monitoring results changed system risk posture or authorization records.
Skills Required
- Must be a United States citizen
- Must be eligible for a Tier 4 High-Risk Public Trust investigation
- At least 8 years of cybersecurity experience
- At least 5 years performing federal continuous monitoring, vulnerability management, ISSO, security operations, or related risk-management work
- Direct experience with Tenable Nessus, Tenable Security Center, or Qualys
- Experience with Splunk searches, dashboards, or event validation
- Vulnerability triage and false-positive review experience
- POA&M creation and maintenance
- Finding assignment and remediation coordination
- Security posture metrics and trend reporting
- NIST SP 800-53 control monitoring
- NIST SP 800-137 continuous monitoring experience
- Experience coordinating remediation with endpoint, network, cloud, application, and identity teams
- Experience supporting incident-response documentation, SitReps, after-action reports, or RCAs
- Understanding of CISA directives, vulnerability-remediation deadlines, and federal logging requirements
- One of: CISSP, CISM, CGRC/CAP, CySA+ (with substantial federal experience), or GIAC certification relevant to incident response or vulnerability management
- Must accept participation in an after-hours incident rotation
- Resume must clearly identify assets/systems monitored, scanner and SIEM tools used, role in vulnerability validation and POA&M administration, remediation metrics, and incident responsibilities
- Direct CSAM and ServiceNow integration or reconciliation experience
- Experience with Splunk Enterprise Security
- Experience with Microsoft Defender for Endpoint, Identity, or Cloud
- Experience with Tenable.sc or Qualys VMDR
- Experience tracking CISA Binding Operational Directives and Known Exploited Vulnerabilities
- Azure and Microsoft 365 security monitoring experience
- Experience with Palo Alto, Zscaler, Entra ID, Okta, or endpoint-management
- Federal major-incident or P1 incident support experience
- Experience building continuous monitoring dashboards for executive review
- Current Tier 4 or Tier 5 suitability/adjudication
Similar Jobs
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Chameleon Integrated Services is an information technology company offering requirements management services.
.jpeg)








