> Markdown version of [/jobs/ext/1193076-information-security-manager](https://www.wearedevelopers.com/jobs/ext/1193076-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Quantum Science Solutions - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Word, Microsoft Excel, Amazon Web Services, User Authentication, Bash Shell, Burp Suite, Configuration Management, Cyber Security, Information Systems, Computer Literacy, Customer Data Management, Linux, Identity and Access Management, Information Security Management, Python (Programming Language), Network Security, Microsoft Security Essentials, Microsoft Office, Microsoft Visio, Network Segmentation, Nmap, Microsoft PowerPoint, Windows PowerShell, Role-Based Access Control, Aws Command Line Interface (CLI), Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Scripting, AWS Lambda, Information Technology, Nessus, Splunk, Cisco, Vulnerability Analysis - **Published:** July 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9012866/information-security-manager ## About the Role * U.S. Citizenship * Active TS/SCI Clearance * Ability to obtain DHS Suitability * 5+ years of directly relevant information security management experience * Hands-on experience with Linux operating systems or Amazon Web Services (AWS) * Experience supporting the NIST Risk Management Framework (RMF) * Experience supporting complete Authorization to Operate (ATO) efforts from initiation through authorization * Experience developing RMF documentation including SSPs, Contingency Plans, Incident Response Plans, and Configuration Management Plans * Strong experience managing Plans of Action and Milestones (POA&Ms) * Knowledge of Assessment and Authorization (A&A) processes * Knowledge of Computer Network Defense (CND) policies, procedures, and regulations * Understanding of defense-in-depth principles and network security architecture * Knowledge of ATO requirements and continuous monitoring processes * Experience implementing and assessing security controls across hardware, software, and network environments * Knowledge of authentication, access management, boundary protection, and network segmentation * Proficiency with Microsoft Office Suite (Word, Excel, PowerPoint, and Visio) * Ability to manage multiple complex assignments requiring sound technical judgment and innovation * Excellent written and verbal communication skills * Ability to work effectively across geographically dispersed teams Preferred Skills * Experience with RMF management tools such as CSAM, Xacta, Archer, or RegScale * Experience with vulnerability scanning tools including Nessus, Security Center, Tenable Vulnerability Management, Nmap, Wiz, or Burp Suite * Experience with Endpoint Detection and Response (EDR) platforms such as CrowdStrike or Carbon Black * Working knowledge of SIEM and SOAR platforms including Splunk, ELK, or similar technologies * Familiarity with Zero Trust architecture * Knowledge of role-based access control (RBAC) * Experience with scripting or automation using Python, AWS CLI, AWS Lambda, Bash, or PowerShell, Bachelor's degree in Information Systems, Cybersecurity, Computer Science, Information Technology, or a related field. OR High School Diploma with 7+ years of directly relevant information security management experience. Desired Certifications * DoD 8140.01 IAT Level III * CISSP * AWS Certification * Cisco Certification * Microsoft Security Certification ## Description Quantum Science Solutions (QSS) provides advanced cybersecurity services supporting mission-critical federal programs focused on protecting national cyber infrastructure. We are seeking an experienced Information Security Manager III to support a critical customer mission by managing Risk Management Framework (RMF) activities, Assessment and Authorization (A&A) efforts, and information security compliance across enterprise systems. The Information Security Manager will work closely with technical teams, Information System Security Managers (ISSMs), and cybersecurity leadership to support Authorization to Operate (ATO) activities, implement security controls, perform risk assessments, and ensure compliance with federal cybersecurity requirements., * Support the full Risk Management Framework (RMF) lifecycle for Information Technology systems. * Develop and maintain Assessment and Authorization (A&A) documentation including System Security Plans (SSPs), Contingency Plans, Incident Response Plans, and Configuration Management Plans. * Support Authorization to Operate (ATO) efforts from system initiation through authorization and continuous monitoring. * Manage and maintain Plans of Action and Milestones (POA&Ms). * Perform risk assessments and security analyses to identify vulnerabilities and recommend mitigation strategies. * Assist in implementing security controls for hardware, software, cloud, and network environments. * Support implementation of DHS and NIST cybersecurity policies, standards, and best practices. * Gather and analyze technical information related to system security architecture, infrastructure, and mission requirements. * Assist technical and program leadership with complex cybersecurity initiatives and security planning. * Coordinate cybersecurity activities across multiple technical teams and stakeholders. * Support security audits, assessments, and compliance reviews. * Respond to customer data calls and support cybersecurity reporting requirements. * Provide technical guidance and recommendations to project leadership. * Lead or support major cybersecurity initiatives requiring advanced technical expertise. * Collaborate with geographically dispersed teams to achieve mission objectives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)