> Markdown version of [/jobs/ext/1338604-cybersecurity-information-systems-security-manager-issm-clearance-required](https://www.wearedevelopers.com/jobs/ext/1338604-cybersecurity-information-systems-security-manager-issm-clearance-required). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity - Information Systems Security Manager (ISSM) - Clearance Required - **Company:** LMI - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cyber Security, Information Systems, SAP (Applications), Data Processing, Information Security Management System, Large Language Models, Information Technology, Devsecops, Plan of Action and Milestones - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bf811d2f6f8b6667 ## About the Role Active CBP Background Investigation required; U.S. citizenship is required. + Bachelor's degree in Information Systems, Computer Science, Cybersecurity, or a related field + 8+ years of experience in cybersecurity, information assurance, or related fields, with significant time in federal environments + 5+ years of hands-on RMF experience, including ATO development and continuous monitoring against NIST 800-53 + Demonstrated experience leading authorization activities and serving as the primary security interface to government Authorizing Officials and assessors + CISSP, CISM, or equivalent senior-level cybersecurity certification * Experience securing LLM, GenAI, or agentic AI systems, including data handling, prompt and tool-call risk, and model output controls * + Strong working knowledge of cloud security in AWS, particularly GovCloud or similar high-compliance environments + Experience writing, defending, and maintaining ATO-grade documentation that holds up to assessor and AO review + Ability to translate compliance requirements into specific engineering work and direct technical staff toward closure + Excellent written and verbal communication skills, with the ability to brief senior government and industry leaders on risk and compliance posture, Active CBP Background Investigation or prior CBP/DHS program support * Direct experience leading ATO or continuous authorization for systems hosted at DHS, or another DHS component * Familiarity with DHS 4300A and specific cybersecurity policies and processes * FedRAMP authorization or assessment experience (Moderate or High) * Experience securing LLM, GenAI, or agentic AI systems in federal environments * Familiarity with CISA Binding Operational Directives, Continuous Diagnostics and Mitigation (CDM), or High Value Asset (HVA) program requirements * Experience with ATO documentation tooling (e.g., Xacta, OpenRMF, or similar) * Experience integrating security and compliance activities into DevSecOps pipelines ## Description What You'll Do * Lead the full RMF lifecycle for LIGER's deployment, from system categorization and control selection through assessment, authorization, and continuous monitoring * Develop, maintain, and defend the authorization package: System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and supporting artifacts * Serve as LIGER's primary security management point of contact for Authorizing Officials, ISSOs, assessors, and cyber working groups * Advise LMI and government leadership on system risk levels, control effectiveness, and the cybersecurity posture of the platform, including emerging risks unique to AI/LLM systems * Develop and maintain LIGER security policies, procedures, and SOPs aligned to DHS requirements * Direct the work of cyber engineers and ISSOs supporting LIGER, ensuring activities align to compliance objectives and program timelines * Coordinate A&A activities across distributed teams, including engineering, infrastructure, and stakeholders * Track audit findings, remediation actions, and POA&M items to closure, escalating risks as needed * Interpret noncompliance and translate it into impact assessments and risk-informed mitigation plans * Support FedRAMP-aligned control implementation and inheritance where applicable * Stay current on evolving federal cybersecurity policy and translate changes into LIGER program direction ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)