> Markdown version of [/jobs/ext/2733811-information-system-security-manager](https://www.wearedevelopers.com/jobs/ext/2733811-information-system-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager - **Company:** Strategic Inc - **Location:** Arlington, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $160,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Cloud Computing, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Zero Trust Network Access, Security Software, Systems Architecture, Systems Integration, Software Vulnerability Management, Cloud Platform System, RSA Archer Platform, Devsecops - **Published:** September 5, 2026 - **Apply:** https://jobs.military.com/career/328883/information-system-security-manager-issm-ts-sci-virginia-va-arlington ## About the Role * Active TS/SCI security clearance. \n * 7+ years of Information Assurance, Cybersecurity, Information System Security, or related experience. \n * 3+ years supporting RMF and NIST SP 800-53 within DoD, Intelligence Community, or Federal environments. \n * Previous experience serving as an ISSM, senior ISSO, Information System Security Engineer (ISSE), or equivalent cybersecurity lead. \n * Demonstrated experience leading systems through the RMF authorization process and obtaining/maintaining ATOs. \n * Experience developing and reviewing complete authorization packages including SSPs, POA&Ms, security controls, risk assessments, and continuous monitoring documentation. \n * Experience managing or providing security oversight for AWS cloud environments. \n * Strong knowledge of NIST SP 800-53 security controls and RMF requirements. \n * Experience with vulnerability management, security assessments, and compliance activities. \n * Ability to work directly with technical engineering teams and customer cybersecurity leadership. \n * Strong written and verbal communication skills. \n PREFERRED QUALIFICATIONS \n \n * Experience supporting DoD or Intelligence Community classified cloud environments. \n * Experience with AWS environments supporting IL4, IL5, Secret, or Top Secret workloads. \n * Experience with eMASS, Xacta, Keyhole, or equivalent GRC platforms. \n * Familiarity with AWS Landing Zone Accelerator (LZA). \n * Experience implementing Zero Trust security principles. \n * Experience integrating cybersecurity requirements into DevSecOps and Infrastructure-as-Code environments. \n * Experience with automated security compliance and continuous monitoring. \n * Knowledge of DISA STIGs and the DoD Cloud Computing SRG. \n * DoD 8570/8140 IAM Level III or equivalent certification. \n, * Ability to communicate cybersecurity risk to technical teams, program leadership, and government customers. \n * Strong analytical, troubleshooting, and risk-management skills. \n * Ability to operate independently within classified environments. \n * Experience supporting highly regulated DoD, Intelligence Community, or Federal customers. \n * Ability to balance mission requirements with cybersecurity and compliance requirements. \n ## Description SBS is seeking an experienced Information System Security Manager (ISSM) to lead cybersecurity, Risk Management Framework (RMF), and authorization activities supporting Amazon Web Services (AWS) Federal customers operating within highly secure and classified cloud environments. \n \n The ISSM will provide overall security leadership and governance for assigned information systems and cloud environments, ensuring compliance with DoD, Intelligence Community, NIST, and customer cybersecurity requirements. This individual will oversee the development and maintenance of Authorization to Operate (ATO) packages, continuous monitoring programs, vulnerability and risk management activities, and security control implementation across multiple security domains. \n \n The ISSM will serve as a primary cybersecurity interface between customer security leadership, Authorizing Officials and their representatives, ISSOs, ISSEs, cloud engineers, architects, and program leadership. \n The ideal candidate combines deep knowledge of RMF and NIST SP 800-53 with experience securing AWS cloud environments and has demonstrated the ability to lead systems through initial authorization and ongoing continuous monitoring. \n \n RESPONSIBILITIES \n \n Security Program Leadership \n \n * Serve as the primary ISSM for assigned information systems and AWS cloud environments. \n * Provide cybersecurity leadership, governance, and oversight throughout the system lifecycle. \n * Lead and mentor ISSOs and coordinate activities across security, engineering, architecture, and operations teams. \n * Establish and maintain system cybersecurity policies, procedures, and security documentation. \n * Advise program leadership and customer stakeholders regarding cybersecurity risk, compliance status, and authorization strategy. \n * Ensure security requirements are incorporated into system architecture, engineering, deployment, and operations. \n ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)