> Markdown version of [/jobs/ext/1216010-senior-information-systems-manager-cybersecurity-assessment-manager](https://www.wearedevelopers.com/jobs/ext/1216010-senior-information-systems-manager-cybersecurity-assessment-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Manager / Cybersecurity Assessment Manager - **Company:** Makpar Corporation - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, Cloud Computing, Cyber Security, Information Systems, Databases, System Configuration, Linux, Mainframes, Comptia Pentest+ CE, Security Content Automation Protocol, Virtualization Technology, Software Vulnerability Management, Firewalls (Computer Science), Nessus, CIS Benchmarks, Plan of Action and Milestones - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9b7cb3dbcc34b501 ## About the Role * High school diploma or higher. * Demonstrated experience with federal government cybersecurity audits and assessments. * Demonstrated experience implementing security controls, configuration changes, software/hardware updates, and vulnerability management. * Demonstrated experience in IT/cybersecurity project and personnel management. * At least one of the required PWS-listed certifications, including CASP+ CE, CCNP Security, CISA, CISSP or Associate, GCED, GCIH, CCSP, CISM, GSLC, CCISO, HCISPP, CEH, CySA+, GSNA, CFR, or PenTest+. A minimum two-year IT/cybersecurity program may substitute for certification. * Ability to complete IRS suitability / staff-like access requirements. * Ability to provide resume and Letter of Commitment. Preferred Qualifications * Prior IRS, Treasury, FTI, Publication 1075, or Safeguards experience. * Experience with NIST 800-53, NIST RMF, FISMA, CIS Benchmarks, DISA STIGs, Nessus, SCAP, and POA&M validation. * Experience leading review teams across Windows, Linux, UNIX, cloud, mainframe, database, network, firewall, virtualization, and container environments. * Strong technical writing for federal findings and remediation guidance. ## Description Our Mission: We solve complex problems for the Federal government to accelerate access to citizen services. When it comes to excellence, we deliver. Learn more about our employer brand at makpar.com/careers. The Senior Information Systems Manager will lead and manage federal cybersecurity audits and assessments. This person should understand security controls, configuration changes, vulnerability management, software and hardware updates, and the practical execution of cybersecurity reviews across complex government environments., * Lead or oversee cybersecurity audits and assessments for federal, state, and local partner agency environments. * Manage assessment personnel and coordinate technical review execution. * Support system configuration checks, interviews with system users and administrators, and review of security artifacts. * Oversee findings development, remediation guidance, vulnerability management, and control implementation analysis. * Support computer security review deliverables, including scope memos, SCSEMs, Nessus results, PFRs, SRR Section H packages, CAP/POA&M materials, and AARs. * Coordinate technical issue resolution across Government stakeholders, partner agencies, and contractor teams. * Support methodology improvements and updates where assessment findings indicate process or technical gaps. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)