Information Systems Security Manager (ISSM) - RMF & XACTA
Overview
Information Systems Security Management (ISSM), you will own the RMF workflow and A&A process for a premier cyber security risk management platform supporting DoD and Intelligence Community customers. You will ensure operational IT capabilities deliver timeliness, accuracy, and security of information across multiple fabrics and centers. Your days involve coordinating with stakeholders, managing system vulnerabilities, and maintaining compliance with NIST standards. This role stands out because you'll directly impact national security while working with leading-edge tools like XACTA 360 and STIGs. You will be the go-to expert for all security authorizations, guiding systems from concept to Authority to Operate (ATO).
What You'll Do9
- 1Drive the RMF workflow by proposing, coordinating, and enforcing information system security policies and standards.
- 2Review and approve access requests and device authorizations to maintain security posture.
- 3Maintain current system information in XACTA 360 to support organizational requirements and audits.
- 4Assess network and system changes for security impact and approve modifications using RMF processes.
- 5Manage multiple A&A projects from concept to Authority to Operate (ATO).
- 6Coordinate with stakeholders to mitigate vulnerabilities listed in POA&Ms and ensure system compliance.
- 7Submit recommendations for configuration deviations from the required baseline.
- 8Conduct periodic reviews to ensure adherence to the SSP and monitor system recovery processes.
- 9Ensure all security documentation is current and accessible to authorized personnel.
Requirements7
- 14+ years of experience in information systems security management.
- 2Demonstrated expertise with RMF, ICD 503, CNSSI 1253, and NIST SP 800-53/53A.
- 3Hands-on experience with STIGs and SCAP compliant tools.
- 4Proficiency in using XACTA 360 to manage security assessments and authorizations.
- 5Strong documentation skills to create and update policies, process docs, and procedures.
- 6Active TS/SCI clearance with polygraph.
- 7Bachelor's degree in Computer Engineering, Computer Science, Electrical Engineering, Information Systems, Information Technology, Cybersecurity, or a related field.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
02 CACI, INC.-FEDERAL
VerifiedInformation System Security Manager
Lead and oversee Risk Management Framework lifecycle activities for classified DoD systems supporting SAP SCI NSA missions. Manage system authorizations and cybersecurity compliance while serving as senior cybersecurity authority. Ensure systems remain secure compliant and fully authorized to operate.
KMS Solutions, LLC
VerifiedInformation Systems Security Manager ISSM
Lead cybersecurity leadership for PMS 340 systems ensuring compliance with DoD DoN NAVSEA NIST and CNSSI requirements. Oversee RMF accreditation and vulnerability management while coordinating with NAVSEA NSW SOF and other stakeholders.
Inadev
VerifiedInformation System Security Officer (ISSO), RMF & NIST
Own the security posture and authorization of a federal system as ISSO at Inadev. Manage the RMF lifecycle, maintain ATO documentation, and ensure continuous compliance with NIST 800-53 and FedRAMP. You will track findings, coordinate with DevSecOps, and report risks to stakeholders. This contract role offers a hybrid schedule in DC and Reston, VA, working with a vibrant team. You bring 5+ years of ISSO experience and a CISSP or equivalent certification.
The University of Texas at Austin
VerifiedInformation Systems Security Manager, Special Programs
As the Alternate Information Systems Security Manager (AISSM) and Assistant Contractor Special Security Officer (ACSSO), you will own security compliance for classified information systems at the Applied Research Laboratories. You will manage authorizations under the Risk Management Framework (RMF) and support Special Access Program (SAP) security. Working with the ISSM and CSSO, you will oversee continuous monitoring, self-inspections, and personnel security. This role offers direct impact on national security programs with a focus on NISPOM and JSIG compliance.
Nyla Technology Solutions
VerifiedSenior Information Systems Security Engineer
You will own technical security assessments and engineer IA solutions across multi-enclave environments at TS/SCI polygraph level. You will architect, integrate, and deploy security functionality into networking and computing components, ensuring compliance with RMF and NIST standards. Working with architects and developers, you will embed security throughout the engineering lifecycle. This role stands out for hands-on system building, not just audits, within a top-tier compensation package.
Astrion
VerifiedInformation Systems Security Manager Washington DCSA
The Information Systems Security Manager (ISSM) assists in establishing and maintaining security programs for classified information systems. This full-time role requires a bachelor's degree and extensive experience. The ISSM advises management on security matters and interfaces with DCSA. Candidates must hold a CAP CISM or CISSP certification and have active TS/SCI clearance.