> Markdown version of [/jobs/ext/1918098-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/1918098-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Parsons View all jobs - **Location:** Columbia, MD, United States - **Salary:** $157,500.0 - $283,500.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Microsoft Azure, Spreadsheets, Cloud Engineering, Cyber Security, Continuous Delivery, Continuous Integration, Identity and Access Management, Information Systems Security Architecture Professional, Open Source Technology, Software Deployment, Kubernetes Helm Charts, Information Technology, CIS Benchmarks, Terraform, Devsecops, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 4, 2026 - **Apply:** https://www.careerjet.com/job/usfbcc3947afba0eecf6070abb774be86b/eaa ## About the Role * Minimum 15 years relevant experience with Masters Degree in Computer Science, Cybersecurity, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or University. * Active DoD IAM and/or IAT Level III, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or SecurityX * Mastery of the Risk Management Framework (RMF) and associated federal cybersecurity standards, including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253. * Demonstrated understanding and experience with Enterprise-level Cloud Architecture & Security principles, including control inheritance and shared responsibility models across AWS and Azure. * DevSecOps practices, automated pipeline security (SAST, DAST, SCA), and CI/CD tools. * Experience as SETA contractor. * Demonstrated experience providing technical leadership on assignments. * Active TS SCI w/Polygraph required ## Description In a world of possibilities, pursue one with endless opportunities. Imagine Next! At Parsons, you can imagine a career where you thrive, work with exceptional people, and be yourself. Guided by our leadership vision of valuing people, embracing agility, and fostering growth, we cultivate an innovative culture that empowers you to achieve your full potential. Unleash your talent and redefine what's possible., Parsons is looking for an amazingly talented Information Systems Security Manager to join our team! In this role you will get to lead the shift from static, point-in-time compliance assessments to a dynamic, real-time risk authorization posture RMF. What You'll Be Doing: * Govern a secure, pre-accredited DevSecOps platform designed for downstream applications to inherit security controls seamlessly. * Define, implement, and maintain automated risk thresholds, security baselines, and compliance rules integrated directly into continuous integration/continuous deployment (CI/CD) pipelines * Oversee real-time configuration tracking, live vulnerability assessments, and threat analytics to ensure ongoing compliance * Act as the interface translating automated pipeline data, Software Bills of Materials (SBOMs), and tool generated security metrics into actionable risk acceptance frameworks to the Task Lead. * Guide and orchestrate the POA&M process, transitioning it from a manual tracking spreadsheet to an automated, tool-driven lifecycle RMF * Set formal governance criteria outlining exactly what level of security vulnerabilities (e.g., critical/high SAST, DAST, or container flaws) will automatically break a software build or block a production deployment DevSecOps Basics DevSecOps Roles & Responsibilities * Validate that Terraform scripts, Helm charts, and cloud-native templates used to spin up environments are programmatically hardened against DISA STIGs and NIST baselines * Enforce rigorous software supply chain security standards, including automated container scanning, open-source dependency tracking, signature validation, and compliance with SLSA frameworks Software Composition Analysis DoD Continuous Authorization Implementation Guide * Govern the Least Privilege Access model across the entire development community, strictly partitioning and isolated tenant developer environments from live, production-level pipelines * Serve as a collaborative bridge between system administrators, software engineers, cloud architects, and compliance officers to shift security left into the early design phases * Establish goals and plans that meet project objectives., JOB SUMMARY: Arundel Mills Supervision of all employees assigned to the Security department, with full responsibility for performance management of said staff. Manage and oversee… + 1 day ago, JOB SUMMARY: Arundel Mills Supervision of all employees assigned to the Security department, with full responsibility for performance management of said staff. Manage and oversee… + 1 day ago + ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)