Advisory Information Security Manager (ISSM)

Frontier Technology LLC
Huntsville, AL, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Code Review Cyber Security Databases Package Management Systems Software Vulnerability Management Nessus Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

Experteer Overview In this role you lead RMF-based security for contractor networks and systems used in Army/Navy environments. You work on-site with government ISSMs and authorities to drive accreditation, ATOs, and continuous monitoring. You champion security-by-design and DevSecOps practices across company solutions before deployment. You collaborate with cross-functional teams to align security with mission requirements and government expectations. Your efforts help maintain authorization boundaries and strengthen system hardening at scale. Compensation / Benefits * Lead RMF lifecycle governance and ATO management for Army/Navy programs * Develop and maintain A&A packages in eMASS and relevant government databases * Evaluate security controls (NIST SP 800-53 Rev.5, CNSSI 1253) across architectures * Oversee vulnerability management with ACAS/Nessus and STIG/SRG application * Draft, track, and remediate POA&Ms with stakeholders * Establish and run Continuous Monitoring programs and annual reviews * Drive internal system hardening and DevSecOps practices across product lines * Perform architecture and code review oversight with SAST/DAST and SBOM considerations * Coordinate incident response, audit readiness, and inspections * Provide strategic security guidance to internal leadership and translate DoD/NIST requirements into actionable tasks * Interface with government officials to support accreditation and compliance processes Tasks * Active TS clearance (TS/SCI preferred) * DoD 8140/8570 baseline certification (Intermediate: Security+ / CASP+ / Cloud+ / GSEC or equivalent; Advanced preferred: CISSP/CISM) * 5+ years of RMF lifecycle experience supporting Army or Navy customers * Strong experience with eMASS and A&A package management * Hands-on vulnerability management and STIG/SRG application * Experience with DoD DoDI 8510.01, NIST SP 800-53 Rev.5, CNSSI 1253 * Shift-Left Security / DevSecOps experience * SAST/DAST and SBOM tooling familiarity * Strong stakeholder management and on-site government collaboration Key requirements *

Requirements

annual reviews * Drive internal system hardening and DevSecOps practices across product lines * Perform architecture and code review oversight with SAST/DAST and SBOM considerations * Coordinate incident response, audit readiness, and inspections * Provide strategic security guidance to internal leadership and translate DoD/NIST requirements into actionable tasks * Interface with government officials to support accreditation and compliance processes Tasks * Active TS clearance (TS/SCI preferred) * DoD 8140/8570 baseline certification (Intermediate: Security+ / CASP+ / Cloud+ / GSEC or equivalent; Advanced preferred: CISSP/CISM) * 5+ years of RMF lifecycle experience supporting Army or Navy customers * Strong experience with eMASS and A&A package management * Hands-on vulnerability management and STIG/SRG application * Experience with DoD DoDI 8510.01, NIST SP 800-53 Rev.5, CNSSI 1253 * Shift-Left Security / DevSecOps experience * SAST/DAST and SBOM tooling familiarity * Strong aaa packages management and on-site government collaboration Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all