Information System Security Manager (ISSM)
DSD Laboratories, Inc.
United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Xacta
Amazon Web Services
Audit Trail
Microsoft Azure
Cloud Computing
Cyber Security
Information Systems
Identity and Access Management
Information Security Management
Security Content Automation Protocol
Software Vulnerability Management
SC Clearance
+4 more
Information Technology
Nessus
Devsecops
Plan of Action and Milestones
Job description
- Serve as Information System Security Manager (ISSM) supporting the ESCAPE contract within the AFMC A4 portfolio.
- Own the full RMF Rev 5 lifecycle for SIPR-hosted systems - from initial system Categorization through Assessment, Authorization, and Continuous Monitoring - and develop and maintain Authorization Packages (SSP, SAR, POA&M, Risk Assessments).
- Coordinate with Authorizing Officials (AO/SCA) and manage ATO/cATO lifecycles in eMASS.
- Oversee continuous monitoring, control assessments, STIG/SCAP compliance, vulnerability remediation, and audit readiness.
- Coordinate with DevSecOps, system administrators, ISSOs, and program stakeholders to ensure cybersecurity requirements are integrated into system sustainment, transition, and operational processes.
- Lead discrete cybersecurity tasks and mentor junior ISSO/cybersecurity staff.
Requirements
- 3-5 years of hands-on experience in cybersecurity, Risk Management Framework (RMF) execution, system assessment & authorization, control assessment, vulnerability management, STIG/SCAP implementation and validation, or DoD/Federal information assurance support.
- Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP/STIG tools.
- A&A implementing NIST 800-53 Rev5, NIST 800-171, or FedRAMP Moderate.
- Familiarity with DoD 8510.01, AFI 17-101, FISMA, and DoD Cloud Computing SRG (IL4/IL5).
- Holistic Plan of Action and Milestone (POA&M) management, continuous monitoring, audit log implementation and review, and security control assessments.
- DoD 8140 Intermediate / DoD 8570 IAM Level II equivalent certification (e.g., GMON, SecurityX/CASP+, CCSP, CGRC/CAP, Cloud+, GCSA, GSEC, CISM, CISSP Associate).
- Must be eligible to obtain and maintain a Secret clearance.
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related technical discipline; equivalent experience may be substituted where contract allows.
- Because this role supports SIPR-hosted systems, must have - or be willing and able to obtain - regular access to a SIPR-capable facility at or near a military installation. SIPR laptops are not currently available for remote issuance; that capability is planned but not yet in place., * 5+ years in DoD, Air Force, federal, or similar environments; experience leading system assessment & authorization efforts, leading and mentoring ISSOs, supporting enterprise cybersecurity program execution.
- AWS/Azure/Google security hardening and monitoring experience.
- DoD 8140 Advanced / DoD 8570 IAM Level III equivalent certification (e.g., CISM, CISSP, ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC, CCISO).
- Active Secret clearance is strongly preferred.
- Master’s degree, graduate certificate, or advanced training in cybersecurity, information assurance, or risk management.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
8 months ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
about 2 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
about 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
The Overflow: Security and Privacy
7 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago