Advisory Information Security Manager (ISSM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Experteer Overview In this role you lead RMF-based security for contractor networks and systems used in Army/Navy environments. You work on-site with government ISSMs and authorities to drive accreditation, ATOs, and continuous monitoring. You champion security-by-design and DevSecOps practices across company solutions before deployment. You collaborate with cross-functional teams to align security with mission requirements and government expectations. Your efforts help maintain authorization boundaries and strengthen system hardening at scale. Compensation / Benefits * Lead RMF lifecycle governance and ATO management for Army/Navy programs * Develop and maintain A&A packages in eMASS and relevant government databases * Evaluate security controls (NIST SP 800-53 Rev.5, CNSSI 1253) across architectures * Oversee vulnerability management with ACAS/Nessus and STIG/SRG application * Draft, track, and remediate POA&Ms with stakeholders * Establish and run Continuous Monitoring programs and annual reviews * Drive internal system hardening and DevSecOps practices across product lines * Perform architecture and code review oversight with SAST/DAST and SBOM considerations * Coordinate incident response, audit readiness, and inspections * Provide strategic security guidance to internal leadership and translate DoD/NIST requirements into actionable tasks * Interface with government officials to support accreditation and compliance processes Tasks * Active TS clearance (TS/SCI preferred) * DoD 8140/8570 baseline certification (Intermediate: Security+ / CASP+ / Cloud+ / GSEC or equivalent; Advanced preferred: CISSP/CISM) * 5+ years of RMF lifecycle experience supporting Army or Navy customers * Strong experience with eMASS and A&A package management * Hands-on vulnerability management and STIG/SRG application * Experience with DoD DoDI 8510.01, NIST SP 800-53 Rev.5, CNSSI 1253 * Shift-Left Security / DevSecOps experience * SAST/DAST and SBOM tooling familiarity * Strong stakeholder management and on-site government collaboration Key requirements *
Requirements
annual reviews * Drive internal system hardening and DevSecOps practices across product lines * Perform architecture and code review oversight with SAST/DAST and SBOM considerations * Coordinate incident response, audit readiness, and inspections * Provide strategic security guidance to internal leadership and translate DoD/NIST requirements into actionable tasks * Interface with government officials to support accreditation and compliance processes Tasks * Active TS clearance (TS/SCI preferred) * DoD 8140/8570 baseline certification (Intermediate: Security+ / CASP+ / Cloud+ / GSEC or equivalent; Advanced preferred: CISSP/CISM) * 5+ years of RMF lifecycle experience supporting Army or Navy customers * Strong experience with eMASS and A&A package management * Hands-on vulnerability management and STIG/SRG application * Experience with DoD DoDI 8510.01, NIST SP 800-53 Rev.5, CNSSI 1253 * Shift-Left Security / DevSecOps experience * SAST/DAST and SBOM tooling familiarity * Strong aaa packages management and on-site government collaboration Key requirements *
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
Dev Digest 138 - Are you secure about this?