Senior Information System Security Manager (ISSM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
The Digital Sector at Leidos has an IMMEDIATE NEED for a Senior Information System Security Manager (ISSM) to support a fast-paced program with the Defense Information Systems Agency (DISA). This role involves supporting the delivery of specialized network and support services to ensure mission success while adhering to DoD standards and regulations. The ISSM will oversee the cybersecurity posture of DoD information systems, ensuring compliance with DoD security standards and protecting sensitive data. The ISSM will develop and implement security policies, conduct risk assessments, manage system accreditations (RMF), and lead continuous monitoring efforts. This role requires collaboration with cross-functional teams and program stakeholders to enforce security controls and manage continuous monitoring. The ISSM will also maintain security documentation and ensure ongoing compliance with applicable regulations., * Manage the Risk Management Framework (RMF) lifecycle for supported systems enabling the achievement and continued maintenance of Authority to Operate (ATO) accreditation.
- Provide ISSM, FISMA, and certification and accreditation support for systems and associated components.
- Conduct recurring assessments of security controls and documentation in eMASS and PPSM to verify continued accuracy, compliance, and readiness.
- Manage whitelist records, address vulnerabilities identified through recurring IAVMS scans, and develop Plans of Action and Milestones (POA&Ms) when required.
- Maintain eMASS control records and POA&Ms in accordance with ATO conditions, approval requirements, and remediation timelines.
- Coordinate cybersecurity activities supporting interim and final authorization to test and operate, including assessments, mitigation planning, patch validation, implementation tracking, and status reporting.
- Create and deliver cybersecurity test plans, test reports, implementation plans, security technical configuration documentation, vulnerability assessment reports, and authorization package materials.
- Lead cybersecurity governance and reporting activities, including the development and maintenance of system architectures, requirements, security plans, protection plans, IAVA actions, and IA-related objectives.
- Prepare program documentation, evidence, and briefings for DISA OAB reviews and support the team throughout the review process.
Requirements
- Bachelor’s Degree with 8+ years of experience or Master’s degree with 6+ years of experience. Additional experience may be considered in lieu of a degree.
- CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or similar cybersecurity certification.
- In-depth knowledge of DoD cybersecurity policies, frameworks, and compliance standards (e.g., NIST 800-53, RMF, FISMA, ICD 503, JSIG).
- In-depth experience with network systems and building/maintaining an ATO for enterprise computing information systems.
- Experience with system security engineering, risk management, and vulnerability assessments.
- Strong understanding of network security, security controls, and common cybersecurity tools (e.g., firewalls, IDS/IPS, SIEM, endpoint protection).
- Ability to work independently and collaborate effectively with cross-functional teams.
- Strong communication skills, including the ability to create and present detailed security reports to stakeholders.
- Clearance: US Secret clearance required, * Experience in managing security for complex DoD programs or mission-critical systems.
- Experience with security tools for vulnerability scanning, penetration testing, and security auditing.
- Advanced security certifications (e.g., CISA, CEH, CSSP, etc.).
- Experience with configuration management and change management processes in a secure environment.
- Experience with automation and the continuous ATO (cATO) process.
Benefits & conditions
Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .
About the company
Our customer, the Defense Information Systems Agency (DISA), provides, operates, and assures command and control of the Defense Information System Network (DISN) services to its customers, the department of Defense (DoD) and national security organizations. This position directly supports DISA-provided capabilities and services., Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Best Paying Jobs in Technology
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?