Information System Security Manager (ISSM)
Role details
Job location
Tech stack
Job description
The Information System Security Manager (ISSM) provides leadership and oversight for a program, organization, system, or enclave's Information Assurance program. This role is responsible for implementing and enforcing security policies, maintaining the operational security posture of assigned systems, and supporting security authorization activities in accordance with Risk Management Framework (RMF) and applicable DoD requirements. The ISSM partners closely with engineering, operations, and government stakeholders to ensure secure, compliant, and mission-aligned environments., * Provide management oversight for information assurance and cybersecurity programs
- Coordinate implementation of IT security policies and security control requirements
- Manage and maintain the operational security posture of systems and enclaves
- Oversee vulnerability management and risk assessment activities
- Manage configuration control and security-related change management processes
- Assess and document security impacts of system modifications
- Oversee preparation and review of SSPs, Risk Assessment Reports, and authorization packages
- Support and guide security authorization activities under RMF
- Provide leadership and oversight to ISSOs and engineering staff
- Interface directly with Government stakeholders to achieve cybersecurity objectives
Requirements
Skill Level 2:
- Ten (10) years of experience in security authorization and RMF-based environments
- Experience with security tools, hardware/software security implementation, encryption, and/or communication protocols
- Bachelor's degree in Computer Science, Cyber Security, IT Engineering, or related field
- In lieu of a Bachelor's degree, four (4) additional years of relevant experience may be substituted
- DoD 8570 / 8140 compliance with IAM Level II required
Skill Level 3:
- Twelve (12) years of experience in security authorization
- Experience with security tools, authorization techniques, incident management, and enterprise security architecture
- Bachelor's degree in Computer Science, Cyber Security, IT Engineering, or related field
- In lieu of a Bachelor's degree, four (4) additional years of relevant experience may be substituted
- DoD 8570 / 8140 compliance with IAM Level III required
- US citizenship and an active TS/SCI with Polygraph security clearance required
Desired Experience:
- Strong working knowledge of NIST 800-53 and RMF processes
- Experience briefing senior leadership and government customers
- Familiarity with enterprise security architecture and system engineering integration
- Strong written and verbal communication skills