> Markdown version of [/jobs/ext/2188704-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2188704-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager (ISSM) - **Company:** Pinnacle Bank - **Location:** Chantilly, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $190,000.0 - $232,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Computer Engineering, Information Security Management, Network Architecture, Zero Trust Network Access, Wireshark, Information Technology, Nessus, Splunk, Plan of Action and Milestones - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9111472/information-systems-security-manager-issm ## About the Role What you bring * Active TS/SCI with Polygraph. This is a hard requirement - we're unable to consider candidates without a current clearance at this level. * A bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related field - or equivalent hands-on experience. * 5+ years of progressively increasing responsibility supporting cybersecurity, information assurance, risk management, or compliance for classified and unclassified programs, within the U.S. Government or as a cleared contractor. * Direct RMF experience - you've built ATO packages, not just contributed to them, and you've owned the relationship with an authorizing official. * Applied technical depth in one or more of: cloud and external services, system administration, configuration management, system and network architecture, operational technology, wireless, telecommunications security, supply chain risk, or security analysis tooling (Splunk, Nessus, Wireshark, and the like). * Communication that lands with both audiences. You can brief a room of engineers and a room of executives on the same risk, and both walk out knowing what to do next. * Willingness to work predominantly on-site in cleared facilities in Northern Virginia., * Experience standing up or maturing a security program rather than maintaining an established one * CISSP, CISM, or equivalent certification * Direct experience implementing DoD Zero Trust requirements or CMMC readiness * A track record of turning a skeptical mission team into a partner ## Description At most organizations, security accreditation shows up at the end of a program - a paperwork sprint to get an ATO signed before a deadline, run by someone who wasn't in the room when the architecture was decided. That's not the job here. Veilant is rethinking how cyber security and assurance get delivered across mission and enterprise systems, and we're looking for the person who will lead that shift. You'll be the primary security advisor and the trusted bridge between our Information Security Program and our government mission partners - the person engineering teams consult before they commit to a design, and the person our customers call when a hard question about risk or compliance lands on their desk. If you've spent years watching RMF get treated as a compliance tax and you know it can be run as a discipline that actually makes systems better, this is the role where you get to prove it. What you'll own RMF accreditation, end to end. You are the lead for every in-scope system - authoring and maintaining System Security Plans, policies, and procedures; building ATO packages; writing the justifications; assembling evidence; walking auditors through reviews; answering the government's questions directly; and keeping continuous monitoring running long after the authorization is signed. Compliance integrity. You'll review systems on a regular cadence for drift from documented configurations and procedures, report what you find without softening it, and drive remediation to closure. Regulatory authority. You'll be the person in the building who knows what NIST CSF, SP 800-171, SP 800-53, CMMC, and the DoD Zero Trust Mandate actually require - and, more usefully, what they mean for the system in front of you. Security as a design input. You'll identify security requirements early and get them built into architecture rather than bolted on. You'll advise mission teams on how their work maps to authorization processes - software, wireless, cloud approvals - so nobody discovers a blocker three weeks before delivery. What success looks like in your first six months * A complete inventory of in-scope systems and their current authorization posture, with a prioritized roadmap for what needs attention and in what order * At least one system carried through ATO or reauthorization under your ownership * SSPs and supporting documentation current and defensible for every system you own * A continuous monitoring rhythm operating on a predictable cadence, with reporting your government partners actually rely on * Established as the advisor mission and engineering teams bring in early - not after the design is locked How we'll measure your impact * Authorizations delivered on schedule, with no lapses in ATO coverage * Audit and assessment findings closed within agreed timelines, with POA&M burn-down trending down * Government partners raise security questions to you directly, and get answers they can act on * Security requirements appear in architecture reviews before they appear in findings ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)