Information System Security Manager (ISSM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Experteer Overview As an ISSM on a fast-paced DoD program, you will lead cybersecurity compliance for DoD information systems, shaping the security posture and accreditation activities. You will collaborate with ISSOs, engineers, and stakeholders to enforce RMF controls and continuous monitoring, ensuring confidentiality, integrity, and availability. Your work will drive risk assessments, policy development, and incident response, aligning with DoD standards. This role offers meaningful impact in defending critical systems on-site with cross-functional teams. Compensation / Benefits * Serve as SME on cybersecurity compliance and information assurance * Collaborate with ISSOs and Cyber Security Engineers to execute continuous monitoring * Manage operational cybersecurity posture with NOC/SOC and Cloud Teams * Facilitate ATO/ATE/ATC/ISA processes with customers and stakeholders * Develop and maintain security policies, procedures, and documentation per DoD standards (NIST, RMF, FISMA) * Oversee security posture of DoD information systems to meet CIA requirements * Conduct risk, vulnerability assessments, and security audits with remediation plans * Coordinate cross-functional teams to implement security controls and best practices * Ensure RMF accreditation is completed and maintained * Act as primary security incident contact and coordinate reporting * Provide security training and awareness for DoD system operators * Maintain SSPs, risk assessments, and POA&Ms; stay current on threats and trends Tasks * US Citizen with active Top Secret clearance and ability to obtain SCI before start * Bachelor’s Degree with 8+ years or Master’s Degree with 6+ years of experience * CISSP or CISM or equivalent cybersecurity certification * Deep knowledge of DoD cybersecurity policies and frameworks (NIST 800-53, RMF, FISMA, ICD 503, JSIG) * Experience with cloud computing and building/maintaining ATO for cloud-based systems * Experience in system security engineering, risk management, and vulnerability assessments * Strong understanding of cloud/network security, controls, and security tools (firewalls, IDS/IPS, SIEM, endpoint protection) * Ability to work independently and with cross-functional teams; strong written and verbal communication Key requirements *
Requirements
_ Oversee security posture of DoD information systems to meet CIA requirements * Conduct risk, vulnerability assessments, and security audits with remediation plans * Coordinate cross-functional teams to implement security controls and best practices * Ensure RMF accreditation is completed and maintained * Act as primary security incident contact and coordinate reporting * Provide security training and awareness for DoD system operators * Maintain SSPs, risk assessments, and POA&Ms; stay current on threats and trends Tasks * US Citizen with active Top Secret clearance and ability to obtain SCI before start * Bachelor’s Degree with 8+ years or Master’s Degree with 6+ years of experience * CISSP or CISM or equivalent cybersecurity certification * Deep knowledge of DoD cybersecurity policies and frameworks (NIST 800-53, RMF, FISMA, ICD 503, JSIG) * Experience with cloud computing and building/maintaining ATO for cloud-based systems * Experience in system security engineering, risk aaaaaaaaa
- and vulnerability assessments * Strong understanding of cloud/network security, controls, and security tools (firewalls, IDS/IPS, SIEM, endpoint protection) * Ability to work independently and with cross-functional teams; strong written and verbal communication Key requirements *
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
What Are The Top Skills Required For Azure Developers?
Understanding and Mitigating Common Web Vulnerabilities