Information Security Manager

Quantum Science Solutions
Arlington, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Xacta Microsoft Word Microsoft Excel Amazon Web Services User Authentication Bash Shell Burp Suite Configuration Management Cyber Security Information Systems Computer Literacy Customer Data Management
+24 more
Linux Identity and Access Management Information Security Management Python (Programming Language) Network Security Microsoft Security Essentials Microsoft Office Microsoft Visio Network Segmentation Nmap Microsoft PowerPoint Windows PowerShell Role-Based Access Control Aws Command Line Interface (CLI) Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Scripting AWS Lambda Information Technology Nessus Splunk Cisco Vulnerability Analysis

Job description

Quantum Science Solutions (QSS) provides advanced cybersecurity services supporting mission-critical federal programs focused on protecting national cyber infrastructure. We are seeking an experienced Information Security Manager III to support a critical customer mission by managing Risk Management Framework (RMF) activities, Assessment and Authorization (A&A) efforts, and information security compliance across enterprise systems. The Information Security Manager will work closely with technical teams, Information System Security Managers (ISSMs), and cybersecurity leadership to support Authorization to Operate (ATO) activities, implement security controls, perform risk assessments, and ensure compliance with federal cybersecurity requirements., * Support the full Risk Management Framework (RMF) lifecycle for Information Technology systems.

  • Develop and maintain Assessment and Authorization (A&A) documentation including System Security Plans (SSPs), Contingency Plans, Incident Response Plans, and Configuration Management Plans.
  • Support Authorization to Operate (ATO) efforts from system initiation through authorization and continuous monitoring.
  • Manage and maintain Plans of Action and Milestones (POA&Ms).
  • Perform risk assessments and security analyses to identify vulnerabilities and recommend mitigation strategies.
  • Assist in implementing security controls for hardware, software, cloud, and network environments.
  • Support implementation of DHS and NIST cybersecurity policies, standards, and best practices.
  • Gather and analyze technical information related to system security architecture, infrastructure, and mission requirements.
  • Assist technical and program leadership with complex cybersecurity initiatives and security planning.
  • Coordinate cybersecurity activities across multiple technical teams and stakeholders.
  • Support security audits, assessments, and compliance reviews.
  • Respond to customer data calls and support cybersecurity reporting requirements.
  • Provide technical guidance and recommendations to project leadership.
  • Lead or support major cybersecurity initiatives requiring advanced technical expertise.
  • Collaborate with geographically dispersed teams to achieve mission objectives.

Requirements

  • U.S. Citizenship
  • Active TS/SCI Clearance
  • Ability to obtain DHS Suitability
  • 5+ years of directly relevant information security management experience
  • Hands-on experience with Linux operating systems or Amazon Web Services (AWS)
  • Experience supporting the NIST Risk Management Framework (RMF)
  • Experience supporting complete Authorization to Operate (ATO) efforts from initiation through authorization
  • Experience developing RMF documentation including SSPs, Contingency Plans, Incident Response Plans, and Configuration Management Plans
  • Strong experience managing Plans of Action and Milestones (POA&Ms)
  • Knowledge of Assessment and Authorization (A&A) processes
  • Knowledge of Computer Network Defense (CND) policies, procedures, and regulations
  • Understanding of defense-in-depth principles and network security architecture
  • Knowledge of ATO requirements and continuous monitoring processes
  • Experience implementing and assessing security controls across hardware, software, and network environments
  • Knowledge of authentication, access management, boundary protection, and network segmentation
  • Proficiency with Microsoft Office Suite (Word, Excel, PowerPoint, and Visio)
  • Ability to manage multiple complex assignments requiring sound technical judgment and innovation
  • Excellent written and verbal communication skills
  • Ability to work effectively across geographically dispersed teams

Preferred Skills

  • Experience with RMF management tools such as CSAM, Xacta, Archer, or RegScale
  • Experience with vulnerability scanning tools including Nessus, Security Center, Tenable Vulnerability Management, Nmap, Wiz, or Burp Suite
  • Experience with Endpoint Detection and Response (EDR) platforms such as CrowdStrike or Carbon Black
  • Working knowledge of SIEM and SOAR platforms including Splunk, ELK, or similar technologies
  • Familiarity with Zero Trust architecture
  • Knowledge of role-based access control (RBAC)
  • Experience with scripting or automation using Python, AWS CLI, AWS Lambda, Bash, or PowerShell, Bachelor’s degree in Information Systems, Cybersecurity, Computer Science, Information Technology, or a related field. OR High School Diploma with 7+ years of directly relevant information security management experience.

Desired Certifications

  • DoD 8140.01 IAT Level III
  • CISSP
  • AWS Certification
  • Cisco Certification
  • Microsoft Security Certification

Benefits & conditions

  • Competitive compensation with annual performance bonuses
  • Premium Medical, Dental & Vision coverage
  • Generous PTO plus Federal Holidays
  • 401(k) with company match

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

1:38 min

Exploring developer resources for further API automation learning

Shweta Palande · LIVE

Videos

See all

Related articles

See all