Senior Cybersecurity WAN Manager

The Nook
Arlington, VA, United States
2 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$170,000.0 - $200,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Identity and Access Management Information Security Management IT Management SAP (Applications) Wide Area Networks Cyber Warfare

Job description

The Senior Cybersecurity WAN Manager owns the scaling and delivery of Nooks’ wide-area networks (WANs) and serves as the Information System Security Manager (ISSM) for them - starting with NEST, our first multi-tenant WAN. Reporting to the Director of Cybersecurity, you own the Risk Management Framework (RMF) lifecycle and the project management behind every WAN deployment, ensuring authorization packages and ATOs are completed in accordance with NIST SP 800-53, the DCSA Assessment and Authorization Process Manual (DAAPM), and DCSA requirements. This is an individual-contributor role today, but it is built to grow: as WANs scale across the network, you will stand up and lead a team of WAN ISSOs and ISSM’s.

Because these are multi-tenant classified WANs, this is an on-site role at the sites where WANs are deployed. The program is being built as it scales - new WANs come online on aggressive timelines, and you are accountable for driving each one from categorization to ATO without becoming the bottleneck. You own that ambiguity, running the authorization and the project plan in parallel and keeping delivery on schedule while every package meets requirements.

Key Responsibilities

RMF & Authorization (ISSM)

  • Serve as ISSM for Nooks’ WANs, owning the full RMF lifecycle from categorization through continuous monitoring for each WAN.
  • Develop and maintain authorization packages - SSPs, POA&Ms, and supporting artifacts - to secure and sustain ATOs.
  • Ensure every package and control implementation aligns with NIST SP 800-53, the DAAPM, and DCSA requirements.

WAN Delivery & Project Management

  • Project-manage WAN deployments end to end, driving each from kickoff to authorized, operational delivery.
  • Build and maintain deployment schedules, milestones, and dependencies so ATOs land on time and in scope.
  • Standardize repeatable authorization and deployment playbooks that scale to each new WAN and site.

Multi-Tenant Operations & Monitoring

  • Operate and sustain multi-tenant WANs, maintaining authorization boundaries across tenants.
  • Run continuous monitoring to keep authorizations valid and detect drift as the WAN grows.
  • Coordinate on-site implementation with the IT and operations teams building and running each site.

Team & Stakeholder Leadership

  • Serve as the primary security authority and point of contact for DCSA on WAN authorizations.
  • Stand up and lead a team of WAN ISSOs as the network scales.
  • Advise site and program stakeholders on WAN security posture, risk, and authorization status.

What Success Looks Like in This Role

Within the first year, NEST is authorized and operating as a multi-tenant WAN, with its ATO package complete and defensible under NIST SP 800-53, the DAAPM, and DCSA requirements. WAN deployments run to a repeatable project plan, and new WANs move from categorization to ATO on schedule without becoming the bottleneck for site delivery. Authorization boundaries hold across tenants, and continuous monitoring keeps every WAN’s authorization valid as the network grows. DCSA and site stakeholders regard this role as the authoritative owner of WAN security and authorization status. As the footprint expands, the role is scaling from a single owner into a WAN ISSO team executing to a consistent standard.

Cross-Functional Expectations

This role partners closely with Enterprise IT, which builds the WAN architecture, and with IT/Cyber Operations, which deploys and sustains it at each site, to carry every WAN from design to authorized delivery. It coordinates with IT/Cyber Product on gate reviews and site build timelines so authorization stays off the critical path. Externally, it is the primary interface to DCSA for WAN authorizations, and it executes on the RMF and security strategy set by the Director of Cybersecurity.

Requirements

  • Active Top Secret/SCI clearance and U.S. citizenship; SAP eligibility a plus.
  • Demonstrated experience as an ISSM (or a senior ISSO ready to step up) for classified networks under DCSA/NISP.
  • Deep, hands-on RMF expertise - owning authorization packages (SSPs, POA&Ms) through ATO under NIST SP 800-53 and the DAAPM.
  • Direct experience with DCSA authorization processes and interfacing with DCSA as the cognizant security agency.
  • Strong project-management skills - planning, scheduling, and driving complex technical deployments to deadline.
  • Experience with WAN or network authorization, ideally multi-tenant or enterprise-scale classified networks (e.g., SIPR).
  • Active DoD 8570/8140 IAM Level II or III certification (e.g., CISSP, CISM, CASP+).

Preferred

  • PMP or equivalent project-management certification.
  • Experience authorizing or operating SIPR/JWICS or other DoD transport networks.
  • Experience standing up and leading an ISSO team.
  • Familiarity with eMASS and DCSA/NISP eMASS authorization workflows.

Eligibility & Clearance

Candidates must be authorized to work in the United States and must be U.S. citizens. This role requires an active Top Secret clearance (SCI eligibility preferred) as a condition of employment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all