Information System Security Manager
Overview
Lead and oversee Risk Management Framework lifecycle activities for classified DoD systems supporting SAP SCI NSA missions. Manage system authorizations and cybersecurity compliance while serving as senior cybersecurity authority. Ensure systems remain secure compliant and fully authorized to operate.
What You'll Do11
- 1Lead RMF lifecycle activities from system categorization through Authorization to Operate ATO Interim Authorization to Test IATT and continuous authorization
- 2Develop and manage SSPs POA&Ms Risk Assessments Implementation Plans and other RMF artifacts
- 3Coordinate with SCAs AOs Cyber Leads and program stakeholders to resolve findings and adjudicate risk
- 4Prepare systems for ATO IATT reauthorization and continuous monitoring
- 5Ensure compliant implementation of security controls per JSIG NIST SP 800-53 DoDI 8510.01 ICD 503 and SAP/NSA requirements
- 6Track remediate and validate POA&Ms to ensure timely closure of vulnerabilities
- 7Conduct internal cybersecurity compliance assessments and inspection-ready reviews
- 8Support DCSA SAP NSA and customer cybersecurity inspections
- 9Evaluate system architecture changes for compliance and cybersecurity impact
- 10Provide cybersecurity guidance and oversight to ISSOs admins engineers and program staff
- 11Develop and present cybersecurity briefings and risk recommendations to leadership and government customers
Requirements14
- 1TS/SCI with Poly Clearance
- 28+ years of cybersecurity experience supporting DoD classified systems (SCI SAP)
- 33+ years as an ISSM or senior cybersecurity lead
- 4Deep knowledge of JSIG RMF DoDI 8510.01 NIST SP 800-53 ICD 503
- 5Experience coordinating directly with AOs AO reps SCAs and government cyber stakeholders
- 6Ability to manage cybersecurity across multi-system classified environments
- 7Strong technical risk assessment and communication skills
- 8DoD 8140 IAM Level II/III or IAT III certification
- 9CISSP preferred
- 10Experience with eMASS and/or Xacta for RMF authorization and security control management
- 11SIEM platforms for security monitoring event analysis and incident response
- 12Vulnerability management tools including Nessus/ACAS or equivalent
- 13Tools used for STIG compliance configuration management and continuous monitoring POA&M tracking
- 14Bachelor’s degree in Cybersecurity IT Computer Science Engineering or related field
Salary Insight
$104 - $218k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
KMS Solutions, LLC
VerifiedInformation Systems Security Manager ISSM
Lead cybersecurity leadership for PMS 340 systems ensuring compliance with DoD DoN NAVSEA NIST and CNSSI requirements. Oversee RMF accreditation and vulnerability management while coordinating with NAVSEA NSW SOF and other stakeholders.
GD Information Technology, Inc.
VerifiedInformation Systems Security Manager (ISSM) - RMF & XACTA
Information Systems Security Management (ISSM), you will own the RMF workflow and A&A process for a premier cyber security risk management platform supporting DoD and Intelligence Community customers. You will ensure operational IT capabilities deliver timeliness, accuracy, and security of information across multiple fabrics and centers. Your days involve coordinating with stakeholders, managing system vulnerabilities, and maintaining compliance with NIST standards. This role stands out because you'll directly impact national security while working with leading-edge tools like XACTA 360 and STIGs. You will be the go-to expert for all security authorizations, guiding systems from concept to Authority to Operate (ATO).
Astrion
VerifiedInformation Systems Security Manager Washington DCSA
The Information Systems Security Manager (ISSM) assists in establishing and maintaining security programs for classified information systems. This full-time role requires a bachelor's degree and extensive experience. The ISSM advises management on security matters and interfaces with DCSA. Candidates must hold a CAP CISM or CISSP certification and have active TS/SCI clearance.
The University of Texas at Austin
VerifiedInformation Systems Security Manager, Special Programs
As the Alternate Information Systems Security Manager (AISSM) and Assistant Contractor Special Security Officer (ACSSO), you will own security compliance for classified information systems at the Applied Research Laboratories. You will manage authorizations under the Risk Management Framework (RMF) and support Special Access Program (SAP) security. Working with the ISSM and CSSO, you will oversee continuous monitoring, self-inspections, and personnel security. This role offers direct impact on national security programs with a focus on NISPOM and JSIG compliance.
1805 KBR Wyle Services, LLC
VerifiedSenior Information System Security Officer (ISSO)
Lead cybersecurity approval and compliance processes while supporting system owners and project managers. Review technical architectures and integrate security requirements throughout the system lifecycle. Ensure cybersecurity compliance and provide guidance to engineers and non-technical partners.
Nyla Technology Solutions
VerifiedSenior Information Systems Security Engineer
You will own technical security assessments and engineer IA solutions across multi-enclave environments at TS/SCI polygraph level. You will architect, integrate, and deploy security functionality into networking and computing components, ensuring compliance with RMF and NIST standards. Working with architects and developers, you will embed security throughout the engineering lifecycle. This role stands out for hands-on system building, not just audits, within a top-tier compensation package.