> Markdown version of [/jobs/ext/1264790-704-cybersecurity-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/1264790-704-cybersecurity-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # (704) Cybersecurity Information System Security Manager (ISSM) - **Company:** Arlo Solutions Llc - **Location:** Orlando, FL, United States - **Experience:** Expert - **Contract:** Contract - **Skills:** Xacta, Microsoft Windows, Systems Engineering, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Linux, Information Security Management, Information Systems Security Architecture Professional, Network Diagrams, Smartsuite, Zero Trust Network Access, Data Streaming, Systems Architecture, Virtualization Technology, Software Vulnerability Management, Cloud Platform System, Information Technology, Plan of Action and Milestones - **Published:** July 14, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9028399/704-cybersecurity-information-system-security-manager-issm ## About the Role * Active Top Secret Security Clearance (SCI eligibility preferred) * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field (or equivalent experience) * Minimum 8 years supporting DoD cybersecurity program * Minimum 5 years supporting DoD RMF and Assessment & Authorization activities * Experience supporting U.S. Army or other DoD cybersecurity programs * Experience managing multiple RMF authorization packages simultaneously * Excellent written, verbal, and presentation skills * Candidates should meet applicable DoD 8140 Cyber Workforce Qualification requirements. Preferred certifications include one or more of the following: * Certified Information Systems Security Professional (CISSP) * Certified Information Security Manager (CISM) * CompTIA CASP+ * Certified Cloud Security Professional (CCSP) Desired Qualifications: Required Knowledge & Experience The successful candidate should possess experience with: * Department of Defense Risk Management Framework (RMF) * U.S. Army RMF implementation * NETCOM RMF Business Rules and authorization processes * Continuous Monitoring (ConMon) * Vulnerability Management * Security Control implementation * Security Assessments and Authorization (A&A) * System Security Plans (SSP) * POA&M management * Security documentation development * Cybersecurity governance and compliance * eMASS, Xacta, or equivalent GRC tools * Microsoft Windows, Linux, virtualization, and enterprise networking * Cloud environments supporting FedRAMP and DoD Cloud SRG (preferred) Minimum Qualifications ## Description Arlo Solutions is seeking an experienced Information System Security Manager (ISSM) to support a U.S. Army customer in Orlando, Florida. This is a full-time on-site position responsible for managing the cybersecurity posture and Risk Management Framework (RMF) lifecycle for approximately 3-7 Army Information Systems supporting missions ranging from Controlled Unclassified Information (CUI) through classified environments. The ISSM serves as the primary cybersecurity advisor for assigned systems and is responsible for ensuring compliance with DoD RMF, Army Regulation (AR) 25-2, and U.S. Army NETCOM RMF policies, processes, and business rules. The position requires close coordination with Government leadership, Program Managers, Information System Owners, Security Control Assessors, engineers, and Authorizing Officials to maintain secure, compliant, and operationally ready systems throughout their lifecycle., * Serve as the Information System Security Manager (ISSM) for 3-7 assigned Army Information Systems. * Lead all phases of the DoD Risk Management Framework (RMF) lifecycle in accordance with NETCOM RMF guidance. * Develop, maintain, and manage Authorization Packages, including SSPs, POA&Ms, Security Categorization, Continuous Monitoring documentation, and supporting Body of Evidence. * Coordinate Authorization to Operate (ATO), Interim Authorization to Test (IATT), Authorization to Operate with Conditions (ATO-C), and reauthorization activities. * Manage Continuous Monitoring (ConMon) activities, vulnerability management, STIG compliance, ACAS review, and cybersecurity reporting. * Conduct cybersecurity risk assessments and recommend mitigation strategies supporting Authorizing Official (AO) risk decisions. * Coordinate Security Control Assessments (SCA) and remediation of assessment findings. * Review system architecture, authorization boundaries, network diagrams, data flows, and system changes to ensure continued compliance. * Manage Plans of Action & Milestones (POA&M) and track corrective actions through closure. * Provide cybersecurity guidance to system owners, engineers, administrators, and Government leadership. * Prepare and brief cybersecurity status, risks, and authorization recommendations to senior Government stakeholders. * Support implementation of Zero Trust Architecture (ZTA), cloud security, and secure system engineering principles where applicable. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)