Information Systems Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The incumbent will serve as the senior ISSM for Department of War (DoW) program. , providing strategic and tactical leadership for all information-system security activities. This role demands deep expertise in the Risk Management Framework (RMF), cyber risk management, and the ability to navigate a highly complex program environment while coordinating across CONUS and OCONUS teams and mentoring junior security staff., * Lead Daily Security Operations - Own day-to-day information-system security functions, addressing all technical security matters and ensuring uninterrupted protection of program assets.
- Talent Management & Mentorship - Attract, develop, and retain high-caliber cyber professionals; provide ongoing mentorship to Information System Security Officers (ISSOs) and other junior staff, fostering a culture of continuous learning.
- Navigate Complex Program Landscape - Analyze and resolve intricate program interdependencies, conflicting requirements, and emerging security challenges; apply systems-thinking to maintain a resilient security posture across a multifaceted environment.
- RMF Oversight - Review, approve, and manage RMF package authorizations, ensuring compliance with DoW/IC standards.
- Security Event Management - Monitor, analyze, and respond to security events; maintain incident-response procedures and escalation paths.
- Compliance Tracking - Record all compliance actions in the approved automated tracking system; when necessary, develop and maintain Plans of Action and Milestones (POA&Ms).
- Lifecycle Governance - Ensure systems are operated, maintained, and disposed of per internal security policies; maintain comprehensive lifecycle documentation.
- Configuration Management - Enforce configuration management for security-relevant software, hardware, firmware, and associated documentation.
- Change Evaluation - Assess proposed system changes or additions, advising stakeholders on security impact and mitigation requirements.
- Security Training & Awareness - Design and deliver IS security education and training programs for staff and contractors; mentor ISSOs in applying best-practice controls.
- Audit & Risk Assessment - Participate in internal and external security audits/inspections; conduct risk assessments and implement remediation actions.
- Incident & Violation Investigation - Lead investigations of security violations and incidents; ensure timely corrective measures and root-cause analysis.
- Policy Implementation - Collaborate with the CSSO to implement, enforce, and continuously improve Information Security Policies and Procedures.
- Global Coordination - Facilitate seamless coordination between CONUS and OCONUS teams to sustain a consistent, program-wide cyber posture.
Requirements
- Currently have an active and good standing DoD 8570 IAM Level II or III certification. Proven experience (8+ years) in ISSM roles, including RMF, POA&M management, incident response, and ISSO mentorship.
- Demonstrated ability to navigate and resolve complex program-level issues and inter-organizational dependencies.
- Proven track record in cyber-talent acquisition, retention, and development initiatives.
- Strong knowledge of DoW/IC cybersecurity policies, configuration management, and lifecycle processes.
- Excellent communication, stakeholder-engagement, and problem-solving skills across geographically dispersed teams.
Desired Skills
-
Currently working in environment supporting IC customers
-
Proved ability to obtain and maintain system ATOs
-
Hands-on experience with ICD 503/JSIG and DAAPAM
-
Experience implementing new and complex technologies at multiple classification levels within large environments and at an Enterprise level
-
Bachelor’s degree from an accredited college in a related discipline, or equivalent experience/combined education, with 14 years of professional experience; or 12 years of professional experience with a related Master’s degree
Benefits & conditions
Full-Time Salary Range: $118000.00 - $219100.00
At Lockheed Martin, we know mission success starts with taking care of our people. Our Total Rewards program is designed to attract top talent, support your well-being, and help you grow-both professionally and personally.
The salary range for this position is as listed on the requisition. Please note that the salary information listed is a general guideline only. Lockheed Martin considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/ training, key skills as well as market(work location) and business considerations when extending an offer.
Benefits offered: Medical, Dental, Vision, Flexible work arrangements and schedules (e.g., 4x10), 401(k) match, Paid time off, Holidays, Parental Leave, EAP, Flexible Spending Accounts, Education Assistance, Life Insurance, Short-Term Disability, and Long-Term Disability.
- Annual short-term and/or long-term incentive compensation programs may be offered depending on the position. Payments under these annual programs are not guaranteed and can vary from year to year and are tied to a range of performance metrics.
- For (Washington state applicants only) Non-represented full-time employees: accrue at least 10 hours per month of Paid Time Off (PTO) to be used for incidental absences and other reasons; receive at least 90 hours for holidays. Represented full time employees accrue 6.67 hours of Vacation per month; accrue up to 52 hours of sick leave annually; receive at least 96 hours for holidays. PTO, Vacation, sick leave, and holiday hours are prorated based on start date during the calendar year.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology