> Markdown version of [/jobs/ext/1504017-information-system-security-manager-issm-moonshot](https://www.wearedevelopers.com/jobs/ext/1504017-information-system-security-manager-issm-moonshot). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - Moonshot - **Company:** Hispanic Technology Executive Council - **Location:** Fairfax, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, Configuration Management, Cyber Security, Domain Name System (DNS), Information Security Management, Intrusion Detection Systems, Network Protocols, Systems Development Life Cycle, Release Management, Security Content Automation Protocol, TCP/IP, Information Security Management System, Firewalls (Computer Science), Information Technology, Patch Management, Cyber Warfare - **Published:** July 30, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/74839745/1 ## About the Role * Active TOP SECRET SCI security clearance with CI Poly * BS in Computer Science or equivalent field of study and 5 years related experience. * Meet the requirements of an DoD 8570.01M IASAE Level II. * Experience with Risk Management Framework (RMF), NIST SP 800-53, Security Technical Implementation Guides (STIGs) and Security Content Automation Protocol (SCAP) Compliance Checker. * Cloud experience including knowledge of cloud security design, requirements analysis, control implementation, and mitigation; and experience with common service providers, such as AWS and Azure. * Knowledge of IT security principles and methods (e.g., firewalls, demilitarized zones, encryption). * Knowledge of authentication, authorization, and access control methods. * Knowledge of key concepts in security management (e.g., Release Management, Patch Management). * Knowledge of cyber defense and information security policies, procedures, and regulations (e.g., RMF). * Knowledge of Intrusion Detection System (IDS)/Intrusion. * Knowledge of incident response and handling methodologies. * Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory service. * Communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. * Develop or recommend analytic approaches or solutions to problems and situations for which information is incomplete or for which no precedent exists. * Experience working to the constraints of Federal policies, procedures, and regulations. ## Description * ISSM: Oversee eight security authorization activities for all assets (currently 8) to ensure compliance with Risk Management Framework (RMF) policies and procedures. * Lead team consisting of sub-contractors to complete responsibilities. * Maintain operational security posture; perform vulnerability/risk assessment analysis * Ensure system security measures comply with applicable government policies. * Provide configuration management and accurately assess the impact of modifications and vulnerabilities for each system. * Active member of the Program Change Advisory Board. * Maintain thorough understanding of customer security controls, and determine which controls are applicable to the application, as well as document implementation in Security Controls Tractability Matrix (SCTM). * Draft and/or prepare and maintain security Assessment and Authorization documentation (i,e System Security Plan, Security Controls Traceability Matrix, Continuous Monitoring Plan and Certification Test Plan). * Manage all Assessment and Authorization (A&A) activities for IS according to the System Developed Life Cycle (SDLC) of the intelligence Community Directive (ICD)-503 Risk Management Framework process. Overall Program Support: Assist where needed to keep the overall program successful. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)