> Markdown version of [/jobs/ext/1992060-information-system-security-manager](https://www.wearedevelopers.com/jobs/ext/1992060-information-system-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager - **Company:** CACI International Inc. - **Location:** Florham Park, NJ, United States - **Experience:** Experienced - **Salary:** $103,800.0 - $218,100.0 - **Contract:** Contract - **Skills:** Xacta, Configuration Management, Cyber Security, Identity and Access Management, Information Security Management, SAP (Applications), SAP Security, Security Information and Event Management, Systems Architecture, Software Vulnerability Management, Information Technology, Nessus, Plan of Action and Milestones - **Published:** August 8, 2026 - **Apply:** https://dejobs.org/x/x/DED000BB6EAA4994B63D93EA487554FD/job/ ## About the Role Required: * TS/SCI with Poly Clearance * 8+ years of cybersecurity experience supporting DoD classified systems (SCI, SAP). * 3+ years as an ISSM or senior cybersecurity lead. * Deep knowledge of JSIG, RMF, DoDI 8510.01, NIST SP 800-53, ICD 503. * Experience coordinating directly with AOs, AO reps, SCAs, and government cyber stakeholders. * Demonstrated ability to manage cybersecurity across multi-system classified environments. * Strong technical risk assessment and communication skills. * Ability to operate independently in complex classified environments. * DoD 8140 IAM Level II/III or IAT III certification; CISSP preferred. Experience with cybersecurity and RMF toolsets, including: * eMASS and/or Xacta for RMF, authorization, and security control management. * SIEM platforms for security monitoring, event analysis, and incident response. * Vulnerability management tools, including Nessus/ACAS or equivalent platforms. * Tools used for STIG compliance, configuration management, continuous monitoring, and POA&M tracking. * Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field; or equivalent experience. * Current or recent SAP access * Must maintain eligibility for all required program-specific accesses. ## Description CACI is seeking an experienced Information Systems Security Manager (ISSM) to lead and oversee Risk Management Framework (RMF) lifecycle activities for a portfolio of classified DoD systems supporting SAP, SCI, and NSA missions. You will manage system authorizations, direct cybersecurity compliance, and serve as the senior cybersecurity authority for multiple high-visibility programs-ensuring systems remain secure, compliant, and fully authorized to operate., * Lead RMF lifecycle activities from system categorization through Authorization to Operate (ATO), Interim Authorization to Test (IATT), and continuous authorization. * Develop and manage SSPs, POA&Ms, Risk Assessments, Implementation Plans, and other RMF artifacts. * Coordinate with SCAs, AOs, Cyber Leads, and program stakeholders to resolve findings and adjudicate risk. * Prepare systems for ATO, IATT, reauthorization, and continuous monitoring. * Ensure compliant implementation of security controls per JSIG, NIST SP 800-53, DoDI 8510.01, ICD 503, and SAP/NSA requirements. * Track, remediate, and validate POA&Ms to ensure timely closure of vulnerabilities. * Conduct internal cybersecurity compliance assessments and inspection-ready reviews. * Support DCSA, SAP, NSA, and customer cybersecurity inspections. * Evaluate system architecture changes for compliance and cybersecurity impact. * Provide cybersecurity guidance and oversight to ISSOs, admins, engineers, and program staff. * Develop and present cybersecurity briefings and risk recommendations to leadership and government customers. * Maintain strong working relationships with AOs, SCAs, FSOs, SAP Security, program management, and system owners. * Support cybersecurity incident response, vulnerability management, continuous monitoring, and reporting. * Ensure all authorization and cybersecurity documentation remains current and inspection-ready. * Manage cybersecurity across a multi-system classified portfolio. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI Pair Programming with GitHub Copilot at SAP: Looking Back, Looking Forward!](https://www.wearedevelopers.com/videos/1546-ai-pair-programming-with-github-copilot-at-sap-looking-back-looking-forward) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Beyond GPT: Building Unified GenAI Platforms for the Enterprise of Tomorrow](https://www.wearedevelopers.com/videos/1525-beyond-gpt-building-unified-genai-platforms-for-the-enterprise-of-tomorrow) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)