> Markdown version of [/jobs/ext/1487147-lead-information-systems-security-manager-issm-isso-ts-security-clearance-required](https://www.wearedevelopers.com/jobs/ext/1487147-lead-information-systems-security-manager-issm-isso-ts-security-clearance-required). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Information Systems Security Manager| ISSM/ISSO | TS security clearance required - **Company:** Tulzi Technologies, LLC - **Location:** Joint Base Andrews, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Amazon Web Services, Microsoft Azure, Bash Shell, Unix, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, Linux, DevOps, Identity and Access Management, Information Security Management, Python (Programming Language), Linux System Administration, Cloud Services, Ansible, Zero Trust Network Access, Virtualization Technology, Rust (Programming Language), Data Logging, Scripting, Cloud Platform System, DevOps Tools - Open-source, Infrastructure as Code (IaC), Git, Containerization, Kubernetes, Information Technology, RSA Archer Platform, Terraform, Devsecops, Docker, Security Orchestration, Automation & Response, Jenkins, Plan of Action and Milestones, Vulnerability Analysis, Golang - **Published:** July 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7c0584db50e700a9 ## About the Role * Bachelor's degree or equivalent experience (8+ years), or advanced degree with 5+ years of experience. * TS/SCI eligibility. * DoD 8570/8140 IAM/IAT Level III compliant certification(s). * Strong understanding of the Risk Management Framework (RMF) and security governance principles. * Knowledge of Linux/Unix operating systems and their administrative concepts. * Familiarity with containerization and orchestration platforms (e.g., Docker, Kubernetes). * Ability to interpret and apply DISA STIG requirements across traditional, cloud, and containerized environments. * Proficiency in at least one scripting or automation language (e.g., Bash, Python, Go, Rust). * Strong analytical and problem-solving capabilities with the ability to work effectively in dynamic environments. * Effective written and verbal communication skills for both technical and non-technical audiences. * Experience supporting cybersecurity initiatives within large-scale DoD or Intelligence Community environments. * General understanding of endpoint security tools and broader security ecosystems. Nice-to-Have Qualifications * Background in DevSecOps, security automation, or secure CI/CD pipeline integration. * Experience with cloud security across platforms such as AWS, Azure Government, or GovCloud. * Advanced Kubernetes security experience beyond basic administration. * Experience developing Infrastructure as Code (IaC) and automating deployments. * Experience with DevOps tools and workflows (e.g., Jenkins, Git, Ansible, Terraform). * Additional professional certifications, such as: -AWS DevOps Professional - Certified Kubernetes Security Specialist (CKS) -GIAC Cloud Security Automation (GCSA) -Certified DevSecOps Professional (CDP) * Broader programming or automation experience beyond core scripting languages. Desired Skills: * Leadership and mentorship capabilities * Strong analytical and troubleshooting skills * Ability to communicate effectively with executives, engineers, and Authorizing Officials * Experience leading cross-functional cybersecurity initiatives * Strong understanding of software supply chain security and Zero Trust Architecture ## Description We are seeking a highly skilled and experienced Lead Information System Security Manager who operates at the intersection of ISSM and ISSO responsibilities. The ideal candidate will have a deep understanding of implementing security measures across enterprise systems, applying governance frameworks, and engineering secure solutions for traditional infrastructure, cloud environments, DevSecOps pipelines, and containerized platforms. This role requires strong RMF leadership, advanced security engineering expertise, and hands-on technical execution across Linux, Windows, cloud, and container ecosystems. The Lead Information System Security Manager will secure systems throughout their entire lifecycle from initial design and accreditation through continuous monitoring while working collaboratively with cross-functional teams to ensure cybersecurity is embedded into every aspect of the organization's IT infrastructure., * Lead RMF activities across the system lifecycle and maintain required security documentation. * Ensure compliance with applicable security frameworks and support all ATO processes. * Conduct security impact analysis for system, infrastructure, and application changes. * Manage RMF packages in enterprise GRC platforms and drive timely POA&M closure. * Track and report on security control performance, coordinate remediation with technical teams, and support audits through clear cybersecurity metrics. * Engineer secure architectures across operating systems, virtualized environments, container platforms, and cloud services. * Implement and review security controls and hardening standards and participate in security design evaluations. * Integrate defense-in-depth strategies across hybrid environments and perform enterprise vulnerability assessments. * Validate, analyze, and coordinate remediation of vulnerabilities while maintaining visibility through dashboards and reporting. * Embed security into CI/CD pipelines and support DevSecOps tools and processes. * Provide container and Kubernetes security engineering, including image assurance, runtime protection, and policy enforcement. * Conduct cloud security architecture reviews and implement controls for identity, encryption, networking, logging, and compliance. * Secure enterprise Windows and Linux environments and enforce configuration, identity, and platform security standards. * Manage patching and configuration compliance across enterprise platforms and automation tools. * Build dashboards for continuous monitoring, compliance reporting, vulnerability trends, threat intelligence, and enterprise risk scoring. * Provide mentorship and guidance to teams on cybersecurity best practices. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)