> Markdown version of [/jobs/ext/1956820-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/1956820-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Cotiviti, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $135,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Data Analysis, Software System Penetration Testing, Microsoft Azure, Software as a Service, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Cloud Services, SAP (Applications), Software Vulnerability Management, Information Security Management System, Google Cloud, Plan of Action and Milestones - **Published:** August 6, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17826015?backUrl=%2Fcareer%2F17826015%2FInformation-Systems-Security-Manager ## About the Role * 8+ years of information security, risk, or compliance experience, including interaction with senior leadership, auditors, and regulators. * Demonstrated experience leading or managing FISMA Moderate or High authorizations and ongoing ATO maintenance. * Strong working knowledge of FedRAMP framework, NIST SP 800-53, and NIST RMF * Experience managing SSPs, POA&Ms, vulnerability remediation, audits, and Continuous Monitoring programs. * Hands-on experience with cloud service providers (AWS, Azure, GCP) and SaaS environments. * Proven ability to lead cross-functional initiatives across technical and non-technical team. * Excellent written and verbal communication skills, with the ability to translate complex regulatory requirements for varied audiences. * Strong organizational skills and ability to prioritize effectively in a highly regulated environment. * Security or compliance certifications (CISSP, CISM, Security+, AWS/Azure Security certifications). Cognitive/Mental Requirements: * Communicating with others to exchange information. * Problem-solving and thinking critically. * Completing tasks independently. * Interpreting data. * Making timely decisions in the context of a workflow. * Maintaining focus. * Assessing the accuracy, neatness and thoroughness of the work assigned. * Learning new tasks and completing tasks in situations that have a speed or productivity quota. * Remembering and adhering to processes and protocols. * Applying established protocols in a timely manner. Working Conditions and Physical Requirements: * Must be able to provide high-speed internet access / connectivity and office setup and maintenance. * Remaining in a stationary position, often standing or sitting for prolonged periods. * Repeating motions that may include the wrists, hands and/or fingers. * Must be able to provide a dedicated, secure work area. * Must be able to provide high-speed internet access / connectivity and office setup and maintenance. * No adverse environmental conditions expected. ## Description The Information Systems Security Manager (ISSM), FedRAMP is responsible for overseeing and sustaining the security authorization and continuous compliance of cloud-based information systems supporting United States Federal Government customers. This role is accountable for ensuring the confidentiality, integrity, availability, privacy, auditability, and accountability of government information systems and associated data. The ISSM partners closely with Business Operations, Engineering, R&D, Product, Legal, and Information Security leadership to ensure information systems deliver required business functionality while being designed, implemented, and maintained in accordance with FedRAMP, NIST SP 800-53, the NIST Risk Management Framework (RMF), and all applicable federal and agency-specific requirements. This position owns overall FedRAMP strategy, authorization execution, continuous monitoring, and Authority to Operate (ATO) sustainment, ensuring ongoing compliance and continuous audit readiness throughout the system lifecycle. In addition, the role supports broader Government (GOV) system security and compliance activities, helping ensure consistent governance and adherence to regulatory requirements across all in-scope federal and state environments. Responsibilities Manage and oversee end-to-end FedRAMP authorization activities, including planning, execution, resourcing, and stakeholder coordination. * Own the development, maintenance, and quality of all FedRAMP-required security documentation, including the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action & Milestones (POA&M), and Continuous Monitoring artifacts. * Oversee monthly POA&M management, including vulnerability prioritization, remediation tracking, and risk acceptance coordination. * Lead and coordinate independent security control assessments, vulnerability management, penetration testing, contingency plan testing, and other required security activities. * Direct FedRAMP Continuous Monitoring (ConMon) activities, ensuring timely and accurate submission of monthly, quarterly, and annual deliverables, including scan results, incident reports, and compliance attestations. * Serve as the primary point of contact for sponsoring agencies, 3PAOs, and internal stakeholders on all FedRAMP-related matters. * Oversee research and response efforts related to government security bulletins, vulnerability advisories, and federal data calls, ensuring timely and accurate responses. * Ensure accurate and up-to-date system, software, and hardware inventories for government-authorized environments. * Provide strategic guidance on secure cloud architecture and compliance-driven design decisions across AWS, Azure, and/or GCP environments. * Evaluate system changes for FedRAMP impact and ensure adherence to change management, configuration management, and incident response requirements. * Interpret evolving FedRAMP, NIST, and agency-specific requirements and translate them into actionable guidance for technical and business teams. * Coach and educate internal teams on FedRAMP obligations, audit expectations, and security best practices. * Identify and implement process improvements to enhance compliance efficiency, reduce risk, and strengthen audit readiness. * Develop and deliver status reporting and metrics to leadership on authorization posture, risk exposure, and overall compliance health. * Complete all responsibilities as outlined in the annual performance review and/or goal setting. * Complete all special projects and other duties as assigned. * Must be able to perform duties with or without reasonable accommodation. ## Related Videos - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)