> Markdown version of [/jobs/ext/2735944-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/2735944-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Aalyria Technologies, Inc - **Location:** Chantilly, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Contract - **Skills:** Software Documentation, Cyber Security, Identity and Access Management, Network Security, Network Architecture, Network Connections, NIPRNet, SAP (Applications), Systems Architecture, Computer Network Operations, SARS Software Products, Plan of Action and Milestones - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/information-systems-security-manager-issm-aalyria-8614273 ## About the Role * Active Top Secret clearance with SCI eligibility; must be in-scope and fully adjudicated at time of hire, no interim clearances considered. * 10+ years of progressive information security experience, with a minimum of 5 years in an ISSM or senior ISSO role within an IC or IC-adjacent contractor environment. * Demonstrated, hands-on experience with ICD 503 and IC-specific A&A processes, candidates with DoD RMF experience only will require supplemental evaluation against IC requirements. * Multi-domain classified network experience including JWICS, SIPRNet, and NIPRNet; working knowledge of the accreditation and operational differences between enclaves. * Experience managing concurrent ATO/ATC processes for multiple systems across different government authorization authorities simultaneously. * Working familiarity with TEMPEST/EMSEC standards and their application to classified facility network infrastructure and RED/BLACK separation requirements. * DoD 8140 / 8570 IAM Level III certification required at time of hire - CISSP, CISM, or equivalent accepted. * Experience developing and maintaining SSPs, POA&Ms, and continuous monitoring documentation in an operational environment. * Strong written and verbal communication skills; demonstrated ability to interface credibly with senior government security and program personnel. * U.S. citizenship required, no exceptions. Clearance & Access Requirements: This position requires an active, fully adjudicated Top Secret clearance with SCI eligibility at time of hire. No interim clearances will be accepted for this role under any circumstances. * Active TS//SCI required at time of offer; in-scope and fully adjudicated * SAP access eligibility required; candidates with existing SAP accesses will be prioritized. * Counterintelligence (CI) or Full Scope Polygraph (FSP) strongly preferred; candidates holding a current polygraph will be prioritized. Candidates without an existing polygraph will be considered - this is not a disqualifier. * A SAP briefing will be required for this role. Candidates must be eligible and willing to accept SAP accesses upon hire. * Relevant compartment accesses above baseline TS//SCI are a significant differentiator and will be considered during the selection process., * Prior experience within Air Force intelligence or Air Force-affiliated SCI enclave environments - direct AFSCI enclave experience is a significant differentiator. * Existing SCI compartment accesses above baseline TS//SCI; candidates with current relevant accesses will be prioritized. * Experience supporting SAP network accreditation, sustained operations, and direct program security officer coordination. * Experience supporting new SCIF standup and initial accreditation under ICD 705, including pre-construction AO coordination and post-construction inspection preparation. * Prior ISSM experience for a facility operating 4 or more concurrent classified and unclassified network environments. * Familiarity with NRO network security requirements and approval processes. * Experience developing operational guidance and training for users working across multiple classification levels and network environments simultaneously. * Prior FSO, deputy FSO, or physical/personnel security experience - valuable in the context of a lean, integrated security team. * Counterintelligence (CI) or Full Scope Polygraph (FSP) strongly preferred and will be weighted heavily in the selection process. Candidates without a current polygraph will be considered; willingness to complete one is a plus., * U.S. citizen or national * U.S. lawful permanent resident (green card holder) * Refugee under 8 U.S.C. 1157 * Asylee under 8 U.S.C. 1158 (B) Be eligible to access export-controlled information without requiring an export authorization. (C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency. ## Description Accreditation & Authorization * Lead all Assessment & Authorization (A&A) activities for multiple classified and unclassified information systems in accordance with ICD 503, RMF, and applicable IC and DoD directives. * Develop, maintain, and submit System Security Plans (SSPs), Security Assessment Reports (SARs), and complete ATO/ATC packages across multiple network enclaves and authorization authorities. * Manage pre-authorization coordination with government AOs and system owners; track and drive Plan of Action & Milestones (POA&M) items to resolution. * Support physical SCIF accreditation activities and coordinate with the FSO on ICD 705 compliance and TEMPEST/EMSEC requirements during and after facility construction. * Coordinate network connection approvals with relevant government network operations centers and accrediting authorities across all authorized enclaves. Operations & Continuous Monitoring * Design and implement continuous monitoring programs for all authorized systems; maintain situational awareness of configuration status, vulnerability posture, and compliance across the environment. * Serve as ISSO for multiple systems during the initial facility standup phase, managing transition of responsibilities to the broader security team as it is built out. * Conduct regular security assessments, configuration compliance reviews, and vulnerability scans; track and verify remediation to closure. * Lead incident detection, response, reporting, and after-action remediation in coordination with the FSO and relevant government security personnel. * Maintain all system documentation, security configuration baselines, hardware/software inventories, and change management records in compliance with applicable directives. Program & Stakeholder Coordination * Interface directly with program security officers for Special Access Program (SAP) network requirements, accreditation coordination, and sustained compliance. * Coordinate with government network and security teams for classified network connectivity, sustainment, and issue resolution across multiple enclaves. * Develop and deliver initial and recurring security awareness training for personnel operating in a multi-domain, multi-classification environment. * Collaborate closely with the FSO on personnel security, physical security, and integrated facility compliance matters; serve as a force multiplier in a lean security team environment. Architecture & Policy * Review and approve system architecture changes, new hardware/software requests, and network modifications from a security compliance perspective. * Advise on RED/BLACK separation requirements and TEMPEST/EMSEC standards as applied to the facility's classified network and physical infrastructure. * Develop and enforce information security policies, procedures, and standard operating procedures specific to multi-domain operations environments. * Maintain current working knowledge of applicable IC directives, NIST standards, CNSS policies, and DoD instructions as they evolve. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Blockchains: One Size doesn't Fit All](https://www.wearedevelopers.com/videos/409-blockchains-one-size-doesn-t-fit-all) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)