Quick Overview
Job Description
Position Title: Information System Security Manager Location: Hill AFB, Utah (on-site) Clearance: ***Active Secret Clearance Required*** Salary: $165,000.00 - $180,000.00
Position Summary: The Information Systems Security Manager (ISSM) serves as the cybersecurity subject matter expert responsible for leading cybersecurity, Risk Management Framework (RMF), Authorization to Operate (ATO), vulnerability management, and continuous monitoring activities supporting U.S. Air Force mission systems and infrastructure.
The position provides technical and compliance leadership across program cybersecurity activities and serves as a primary cybersecurity interface between program leadership, engineering and operations teams, customers, and Authorizing Official (AO) stakeholders. The ISSM is responsible for managing multiple system authorization packages, including program and customer ATOs, and ensuring systems maintain an acceptable cybersecurity posture throughout the system lifecycle.
The position leads implementation of DoD and Department of the Air Force cybersecurity requirements, including DoD RMF, NIST SP 800-53, DISA Security Technical Implementation Guides (STIGs), vulnerability management, continuous monitoring, and associated cybersecurity documentation. This position also provides cybersecurity leadership supporting modernization of legacy Air Force infrastructure and transition of services to approved hosting and cloud environments.
Essential Duties & Responsibilities
- Provides technical leadership, direction, prioritization, and oversight for cybersecurity activities across the program.
- Coordinate cybersecurity activities across ISSOs, security engineers, system administrators, infrastructure teams, application teams, program management, customers, and other mission stakeholders.
- Manage multiple systems through the complete DoD Risk Management Framework lifecycle and maintain Authorization to Operate (ATO) packages within eMASS.
- Lead development, maintenance, and execution of program ATO packages and two customer ATO packages, including security controls, implementation statements, artifacts, assessment evidence, POA&Ms, continuous monitoring requirements, and authorization documentation.
- Serve as a primary cybersecurity point of contact for customer security organizations, assessors, Authorizing Official representatives, and other authorization stakeholders.
- Interpret and implement DoD RMF, NIST SP 800-53, Department of the Air Force, DISA, and applicable cybersecurity requirements across program systems and authorization boundaries.
- Develop and maintain system security documentation, including System Security Plans, continuous monitoring documentation, control implementation evidence, security procedures, risk documentation, and other RMF artifacts.
- Lead vulnerability management activities, including ACAS/Tenable scanning, vulnerability analysis, remediation prioritization, POA&M management, risk acceptance activities, and coordination of remediation efforts with infrastructure and sustainment teams.
- Oversee DISA STIG implementation and compliance activities, including STIG checklist development, validation of findings, documentation of applicability, and coordination of remediation with technical system owners.
- Monitor cybersecurity compliance and system security posture through continuous monitoring, vulnerability assessments, security control reviews, and analysis of technical and operational risk.
- Provide cybersecurity risk assessments and recommendations to Program Management and customer leadership, translating technical vulnerabilities and compliance deficiencies into mission and program risk.
- Develop, maintain, and communicate cybersecurity risks within the program risk register and coordinate mitigation strategies with Program Management and technical stakeholders.
- Support system architecture, data flow mapping, system boundary definition, network topology analysis, and cybersecurity requirements associated with modernization and hosting/cloud migration activities.
- Evaluate proposed system changes, architectures, software, hardware, and technical solutions for cybersecurity and RMF impacts.
- Coordinate security patching, vulnerability remediation, and configuration management activities with infrastructure and sustainment teams.
- Provide cybersecurity guidance and mentorship to program cybersecurity personnel and technical teams and establish priorities for cybersecurity activities based on mission risk and authorization requirements.
- Represent program cybersecurity status, risks, authorization progress, and significant issues during customer, technical, and program leadership meetings. Education, Certification & Experience Requirements: Education Required:
- Bachelor's Degree in Cybersecurity or IT related field
- Must have relevant Air Force Risk Management Framework (RMF) experience Certifications Required:
- Must meet applicable DoD 8140 qualification requirements at time of hire.
- Certified Information Security Manager (CISM) (preferred)
- Certified Information Systems Security Professional (CISSP) (preferred) Experience Required:
- 10 or more years experience in cybersecurity, information assurance, cybersecurity engineering, or related disciplines.
- Significant experience serving as an ISSM, senior ISSO or comparable cybersecurity authority within a DoD environment.
- Demonstrated experience managing systems through the complete RMF lifecycle and obtaining or maintaining ATOs.
- Experience managing multiple concurrent authorization packages and coordinating cybersecurity requirements across multiple system owners or customers.
- Demonstrated experience with NIST SP 800-53 security controls, eMASS, POA&M management, continuous monitoring, ACAS/Tenable, vulnerability management, and DISA STIGs.
- Experience communicating cybersecurity risk and authorization status to technical teams, customers, assessors, and program leadership. Knowledge, Skills & Abilities:
- Expert knowledge of DoD Risk Management Framework processes, NIST SP 800-53 security controls, and Department of the Air Force cybersecurity requirements.
- Advanced knowledge of system authorization, continuous monitoring, security control implementation and assessment, POA&M management, and cybersecurity risk management.
- Strong knowledge of DISA STIGs, ACAS/Tenable, eMASS, vulnerability management processes, and DoD cybersecurity compliance requirements.
- Working knowledge of enterprise infrastructure, networking, operating systems, virtualization, and cloud/hosted environments sufficient to assess cybersecurity risk and control implementation.
- Strong leadership and organizational skills with the ability to establish cybersecurity priorities across multiple simultaneous authorization and operational efforts.
- Advanced RMF, ATO, vulnerability management, STIG, and cybersecurity risk analysis skills.
- Strong written communication and technical documentation skills, including the ability to develop and review authorization artifacts and communicate cybersecurity risk to technical and nontechnical stakeholders.
- Strong interpersonal and stakeholder-management skills with the ability to work effectively with customers, government personnel, engineers, system administrators, cybersecurity personnel, and program leadership.
- Ability to lead cybersecurity activities across engineering, operations, sustainment, customer, and program management organizations.
- Ability to independently evaluate cybersecurity risk and provide technically sound recommendations to program and customer leadership.
- Ability to manage multiple concurrent ATO and continuous monitoring efforts while prioritizing activities based on mission impact and cybersecurity risk.
- Ability to interpret cybersecurity requirements and translate them into actionable technical and program requirements.
- Ability to balance operational mission requirements with DoD cybersecurity, authorization, and risk-management requirements.
Why Join Command Cyber Solutions: We recognize that our success begins with our people. We are dedicated to fostering a professional, collaborative, and growth-oriented environment where employees are empowered to excel and advance their careers, CCS offers opportunities to contribute to high-impact federal initiatives, supported by robust professional development programs, competitive compensation, comprehensive benefits, and flexible work arrangements. We prioritize investing in our workforce, ensuring each team member has the resources, support, and career pathways to achieve long-term success while delivering meaningful results for our clients.
Culture: At CCS, you'll be a part of a team that genuinely supports one another and where leadership is invested in the well-being and success of every employee. We foster a work culture where people are valued for who they are, not just what they do, and where your career goals are taken seriously. You'll be encouraged to grow through mentorship, hands-on experience, and access to continued learning opportunities that align with your aspirations.
Whether you're looking to deepen your expertise, earn new certifications, or take on leadership roles, CCS provides the environment and support to help you get there. Leadership is approachable, collaboration is natural, and success is shared. At CCS, you're not just joining a company; you're joining a community committed to your growth and success.
Benefits: We offer a comprehensive benefits package designed to support the health, financial security, and overall well-being of our employees and their families. Our offerings include medical and prescription drug plans, dental coverage, group life insurance, and options for supplemental life insurance to provide additional protection. We also provide short-term and long-term disability insurance, flexible spending accounts, and employee assistance programs to help employees ma
Similar jobs
- CM
Cyber Security Engineering B-2, 01.6.35 with Security Clearance
NewCredence Management Solutions
Wpafb, OH🇺🇸HybridYesterdayTechnology - EN
Information System Security Engineer (ISSE) with Security Clearance
NewEnvisioneering, Inc
Washington, DC🇺🇸$100k - $180k/yrHybridYesterdayActive DirectoryTechnology - AS
Senior Security Engineer, Forward Deployed Engineering, AWS Forw with Security Clearance
NewAmazon.com Services LLC
Boston, MA🇺🇸$178.4k - $226.7k/yrOn-siteYesterdayMicroservicesScalaAWS+7Technology - BA
Network Security Engineer, Senior with Security Clearance
NewBooz Allen Hamilton
Fort Meade, MD🇺🇸$86.9k - $198k/yrOn-siteYesterdayLoad BalancingAzureBashTechnology - XB
Security Engineer
NewXbowcareers
US remote🇺🇸Remote12 hours agoGCPAWSAzure+1Technology - AI
Senior Insider Threat Analyst
NewAnduril Industries
Reston🇺🇸$166k - $220k/yrHybrid10 hours agoAWSCDKComputer Vision+2Technology