> Markdown version of [/jobs/ext/3041278-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/3041278-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Virtualitics, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Application Programming Interfaces (APIs), Artificial Intelligence, JIRA, Bash Shell, Cloud Computing, Cyber Security, Continuous Integration, Github, Identity and Access Management, Python (Programming Language), Zero Trust Network Access, SQL Databases, Tripwire, Okta, SC Clearance, Containerization, Kubernetes, Slack, Terraform - **Published:** September 23, 2026 - **Apply:** https://www.thejobnetwork.com/job/a189e6bc-1902-48a3-b645-47aea6fc1ba3/senior-information-systems-security-manager-issm ## About the Role If you're motivated by impact, inspired by technical depth, and ready to build AI that performs where it matters most - you'll find your mission here., * Personal ownership of a DoD IL4/IL5/IL6, FedRAMP Moderate/High, or agency ATO package taken end to end - not supported from the side. * Deep working knowledge of NIST 800-53, NIST 800-37 (RMF), and the DoD Cloud Computing SRG, with the judgment to tailor controls rather than apply them literally. * Proven ability to evaluate cloud technical architectures and determine whether they satisfy regulatory objectives: you can read Terraform, follow a CI/CD pipeline end to end, understand a Kubernetes deployment, and challenge an engineer's design on its technical merits. * Proficiency with AI-native workflows and agentic tools (e.g., Claude Code), with grounded views on which assurance workflows AI can run reliably today and which still need a human in the loop. * Assessor-grade writing - control narratives and security documentation a reviewer can act on without a follow-up call. * Experience facing AOs, 3PAOs, or external assessors directly, with the credibility to hold the room. * U.S. citizenship required. Active Secret clearance preferred; we will sponsor the right candidate. * IAM Level II or III certification (CISSP, CISM, or CASP+) per DoD 8140, held or obtainable within six months of hire. What are our Preferred requirements: * Experience with a government hosting or authorization partner (Palantir FedStart, Second Front Game Warden, or similar) and how inherited controls change your package. * OSCAL or other machine-readable control documentation, and GRC / evidence automation platforms such as RegScale, Xacta, Drata, or eMASS. * CMMC scoping or assessment experience on a CUI boundary; CCP or CCA designation is a great addition. * CNAPP and container scanning in a compliance context (Wiz, Trivy, Anchore, Tenable), including triaging findings and defending risk acceptances. * Familiarity with the cloud native technologies common in software startups: Okta, Zscaler, GitHub, JIRA, Slack. * Experience scaling Series C / Series D startups. What are some Valued skills: * High-agency * AI fluent * Diplomatic ## Description Role: Senior Information Systems Security Manager (ISSM) We just earned our IL6 ATO and our IL5 authorization is close behind. Every new customer we win needs their own Authorizing Official to issue an ATO, and that reciprocity work has become the constraint on how fast we can grow. Our team is looking for a Senior ISSM to own it - running federal authorizations end to end as our named ISSM of record, so that each new customer ATO becomes a package we pull and tailor rather than a project we rebuild from scratch. This is a cloud and product authorization role rather than a closed-area or SCIF ISSM position; our El Segundo SIPR space is provided and accredited by Nooks. Ability to work quickly, automate relentlessly, and translate between compliance language and engineering reality will be key. This position is remote with ability to travel to a SCIF when requested by the company. What you will be doing: * Authorization Ownership: Own our IL5 and IL6 packages end to end as Virtualitics' named ISSM - SSPs, control narratives, POA&Ms, significant change reviews, continuous monitoring, and annual assessments. * Reciprocity at Scale: Build the playbook, artifacts, and evidence pipeline that cut time-to-ATO for every new customer, and act as the front-line technical contact for sponsor AOs, 3PAOs, and customer security reviewers. * CMMC and CUI: Own our CUI boundary from scoping and control implementation through deficiency tracking and assessment readiness. * Commercial Assurance: Run FedRAMP alignment, SOC 2, and the customer security questionnaire and due diligence pipeline that shows up in every enterprise and federal deal. * Evidence Automation: Replace manual evidence collection with automation, writing the Python, Bash, SQL, and API glue that keeps control evidence continuous rather than assembled the week before an assessment. * Engineering Interface: Partner with engineers to turn controls into acceptance criteria they can build against, designing requirements into the system rather than papering over gaps with procedure. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2](https://www.wearedevelopers.com/videos/1765-slopquatting-api-keys-fun-with-fonts-recruiters-vs-ai-and-more-the-best-of-live-2025-part-2) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)