> Markdown version of [/jobs/ext/534103-secret-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/534103-secret-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Secret Information Systems Security Manager (ISSM) - **Company:** Insight Global - **Location:** Providence, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Information Systems, Information Security Management, Systems Development Life Cycle, Zero Trust Network Access, Security Content Automation Protocol, Systems Architecture, Software Vulnerability Management, SARS Software Products, Cloud Platform System, Navsea, Information Technology, Devsecops - **Published:** June 5, 2026 - **Apply:** https://dejobs.org/x/x/9E12D853594B42C59C7701BF35E0CC36/job/ ## About the Role The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS. The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM). The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands-on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well-organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization., Active Secret clearance (TS/SCI preferred) -Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) -8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment -Strong experience implementing RMF under DoDI 8510.01 (latest version) -Hands-on experience with eMASS -Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems) -DISA STIGs and SCAP compliance tools -ACAS (Assured Compliance Assessment Solution) -HBSS / Endpoint Security Solutions -Strong understanding of system architectures (on-prem, cloud, hybrid) Experience with Navy Authorizing Officials (AOs) and Navy-specific RMF processes Familiarity with Platform IT (PIT) and Weapons Systems cybersecurity Experience with DevSecOps pipelines and containerized environments Knowledge of Zero Trust Architecture (DoD Zero Trust Strategy, 2022+) Experience supporting systems in AWS GovCloud, Azure Government, or Navy cloud environments ## Description Insight Global is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF)., Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity) Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring Develop, maintain, and manage RMF documentation including: System Security Plans (SSPs) Security Assessment Reports (SARs) Plan of Action & Milestones (POA&Ms) Continuous Monitoring Strategies Ensure compliance with: NIST SP 800-53 Rev. 5 security controls NIST SP 800-37 Rev. 2 (RMF Guide) DoD Cybersecurity Manual (DoDM 5200.01) SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual) Interface directly with Navy stakeholders including: Authorizing Officials (AOs) Security Control Assessors (SCAs) Information System Owners (ISOs) Program Managers (PMs) Manage system accreditation activities within eMASS and ensure data accuracy and completeness Conduct and support security control assessments, vulnerability management, and mitigation tracking Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections) Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)