Information System Security Manager (ISSM) with Security Clearance
Why This Role Stands Out
This hybrid Information System Security Manager role offers a significant opportunity to lead security strategy and mentor a team within a reputable company, while benefiting from the flexibility of a hybrid work environment. You'll thrive here if you are a seasoned security professional with a strong understanding of RMF and NIST guidance, eager to make a substantial impact on critical information systems. Apply today to advance your career in a pivotal cybersecurity leadership position.
Quick Overview
Job Description
Information System Security Manager (ISSM) Description: We are looking for a dynamic Information System Security Manager to join our team! The Information System Security Manager (ISSM) serves as the principal advisor to the Authorizing Official (AO) and program leadership on all matters, technical and otherwise, involving the security of assigned information systems.
The ISSM is responsible for the development, implementation, and maintenance of the agency's information security program in accordance with the Risk Management Framework (RMF), NIST SP 800-series guidance, and applicable federal and agency-specific security policies. This role oversees a team of Information System Security Officers (ISSOs) and serves as the primary point of contact for security authorization, continuous monitoring, and incident response activities.
Responsibilities
- Serve as the principal advisor to the Authorizing Official (AO) and Information System Owner on the security of assigned information systems
- Lead and manage the Assessment and Authorization (A&A) process for information systems in accordance with the Risk Management Framework (RMF, NIST SP 800-37), ensuring timely issuance and maintenance of Authorizations to Operate (ATOs)
- Develop, review, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and other required RMF artifacts
- Oversee a team of Information System Security Officers (ISSOs), providing guidance on day-to-day security operations and compliance activities
- Conduct and oversee continuous monitoring activities, including vulnerability scanning, configuration management, and security control assessments, to maintain the security posture of authorized systems
- Ensure compliance with FISMA, NIST SP 800-53, NIST SP 800-171 (as applicable), CNSSI, and agency-specific cybersecurity policies and directives
- Coordinate incident response activities and report security incidents to the appropriate agency SOC/CSIRC and leadership in accordance with established procedures
- Manage risk assessments and communicate residual risk to the AO, providing recommendations for risk acceptance, mitigation, or remediation
- Ensure personnel supporting assigned systems meet DoD 8570.01-M / DoD 8140 information assurance workforce certification and training requirements
- Maintain security documentation in agency GRC/eMASS (or equivalent) systems and support periodic audits, Inspector General (IG) reviews, and independent assessments
- Support the development of security policies, procedures, and standard operating procedures (SOPs) to strengthen the agency's overall security program Requirements:
- Active Secret clearance or higher
- Minimum 3 years of experience in information systems security, information assurance, or cybersecurity, with direct experience supporting a federal agency
- Demonstrated experience serving as an ISSM, ISSO, or equivalent security role within the Risk Management Framework (RMF) or legacy DIACAP/C&A process
- Working knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-30, and FISMA reporting requirements
- Active DoD Secret security clearance required at time of hire; ability to maintain clearance eligibility for the duration of the contract
- Current DoD 8570.01-M / DoD 8140 IAM Level II certification (e.g., CAP, CASP+ CE, CISM, GSLC) at time of hire
- Strong written and verbal communication skills, with experience briefing technical risk and compliance matters to government leadership and Authorizing Officials
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience
Desired Skills
- IAM Level III certification (e.g., CISSP, CISSP-ISSMP, CISM) or equivalent advanced credential
- Experience using eMASS, Xacta, or other GRC platforms to manage A&A documentation
- Experience supporting defense, healthcare, or civilian federal agency security programs
- Familiarity with cloud security authorization processes (FedRAMP) and DevSecOps/continuous ATO practices
Similar jobs
- LS
IT Security Specialist (9822)
NewLutheran Services Florida
Tampa, FL🇺🇸On-site21 hours agoActive DirectoryEncryptionHTTPS+1Technology - DI
SAP security consultant
NewDella Infotech
Sunnyvale, CA🇺🇸On-site21 hours agoTechnology - BO
Cybersecurity - Information System Security Officer (ISSO) with Security Clearance
Boeing
Berkeley, MO🇺🇸$105.4k - $142.6k/yrHybrid6 weeks agoTechnology - EV
Sr SailPoint Identity Security (ISC) Analyst
NewEvolutyz Corp
United States🇺🇸Remote21 hours agoAdministrative - IF
Security Engineer with Security Clearance
NewITC Federal
Quantico, VA🇺🇸On-site21 hours agoGCPAWSEncryption+2Technology - TC
ISSO with Security Clearance
NewTEKsystems c/o Allegis Group
Dahlgren, VA🇺🇸$130k - $145k/yrHybrid21 hours agoTechnology