> Markdown version of [/jobs/ext/2208508-information-systems-security-manager-ii](https://www.wearedevelopers.com/jobs/ext/2208508-information-systems-security-manager-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager II - **Company:** AFORGE LLC - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Configuration Management, CompTIA Security+, Cyber Security, Data Systems, Information Security Management, Security Content Automation Protocol, Data Streaming, Plan of Action and Milestones - **Published:** August 24, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9097632/information-systems-security-manager-ii ## About the Role * Bachelor's degree from an accredited university, CNSSI 4012 certificate, ADQ GA7, or successful completion of one of the qualifying military training courses identified in Attachment 05 or a Government-accepted DoD Service equivalent. * Three to five years of validated specialized experience in Specialty Area 72, Information Systems Security Management. * Current CompTIA Security+ CE or CASP certification. * Ability to complete and maintain applicable Cybersecurity Workforce qualification and OJT requirements within Government-directed timelines, including the applicable NAVEDTRA pathway. * Ability to maintain at least 40 continuing-education hours annually while assigned to the Cybersecurity Workforce. * Active U.S. Government Secret clearance at the time of award and ability to obtain and maintain a Top Secret clearance. * Ability to support contractor sites serving the Washington Navy Yard and NSWC Crane., * Six or more years of relevant cybersecurity or ISSM experience. * Experience with DoDI 8510.01 RMF, Navy authorization processes, STIGs, ACAS, SCAP, POA&Ms, and continuous monitoring. * Experience supporting iPDM, IWS 5, Navy product-data systems, or application migration into an accredited boundary. ## Description The Information System Security Manager II supports cybersecurity governance, RMF authorization, security-control validation, and continuous monitoring for iPDM, IWS 5, and related Task Area 3 systems. The position authors and reviews cybersecurity plans and evidence, coordinates security activities across system elements, and protects Government IT and digital environments throughout their lifecycle., * Support system categorization, control selection and tailoring, implementation, assessment, authorization, and continuous monitoring in accordance with DoDI 8510.01 and Government direction. * Develop, review, and maintain applicable RMF artifacts, including security plans, assessment evidence, POA&Ms, inventories, diagrams, control implementation statements, and authorization-package records. * Apply and validate DISA STIG checklists and coordinate credentialed ACAS and SCAP assessments, manual checks, findings adjudication, and remediation verification. * Assess outside applications proposed for migration into the iPDM authorization boundary, including components, interfaces, data flows, vulnerabilities, dependencies, and control inheritance. * Support IWS 5 systems in acquiring and maintaining ATOs; prepare evidence and recommendations for Government cybersecurity authorities and the designated AO. * Monitor vulnerabilities, configuration changes, POA&M milestones, evidence currency, and significant-change impacts throughout authorization sustainment. * Coordinate incident reporting, access control, audit, configuration management, risk assessments, and cybersecurity training as assigned. * Communicate security risk, remediation priorities, residual risk, and authorization status to technical and Government leadership. ## Related Videos - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)