> Markdown version of [/jobs/ext/590061-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/590061-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Spear AI - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cyber Security, Information Systems, Identity and Access Management, SONAR (Symantec), Software Vulnerability Management, Data Management - **Published:** June 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0a89fe15930cb48d ## About the Role Do you have experience in Senior leadership?, * 7-10 years of progressive cybersecurity experience, with a minimum of 3 years in an ISSM or senior security leadership role within IC or DoW environments * Active TS/SCI required; must be able to obtain a Polygraph. * Deep expertise in NIST RMF, ICD 503, CNSSI 1253, and IC/DoW security policy frameworks * Demonstrated experience achieving and maintaining ATOs for complex, multi-system programs in classified environments * Strong background in security architecture, risk management, and incident response within JWICS or similar classified networks * Experience leading and mentoring security teams in a fast-paced, mission-driven environment * Professional certifications required: CISSP; CISM, CAP, or CASP+ strongly preferred * DoW 8570/8140 IAM Level III compliance required Nice to have * Experience with AI/ML system security considerations * AWS GovCloud or Azure Government security experience * Military Intelligence or IC experience ## Description We are seeking an Information Systems Security Manager to provide senior-level cybersecurity leadership and oversight across all information systems supporting the program, serving as the authoritative subject matter expert on security policy, risk management, and compliance within the Intelligence Community. Spear AI is a growing defense contracting company dedicated to delivering cutting-edge solutions that support our nation's security. As we expand, we're building a culture where innovation meets mission-critical work. We operate with a flat organizational structure that empowers every team member to make an impact, collaborate directly with leadership, and contribute to projects that matter. Whether you're joining our Hardware, Software, or Services division, you'll work alongside talented professionals who are committed to excellence and advancing the capabilities that keep our nation safe and secure. Spear AI builds sonobuoy sensors that are deployed into the water and collect edge data. We also work with the U.S. Navy to collect and process their SONAR data. You'll have an opportunity to work on real-world projects that directly impact warfighter capabilities and mission success. What you'll do We're a small team wearing many hats, and you'd have a wide variety of responsibilities that include: * Serve as the senior security authority for all program information systems, providing oversight to ISSOs and security staff * Lead and manage the Risk Management Framework (RMF) process across multiple systems, ensuring ATOs are achieved and maintained in compliance with ICD 503 and NIST standards * Develop, implement, and enforce information security policies, procedures, and standards tailored to IC operational environments * Advise program leadership and the Authorizing Official (AO) on cybersecurity risks, mitigation strategies, and residual risk acceptance * Oversee continuous monitoring programs, security control assessments, and vulnerability management activities * Lead incident response, forensic investigations, and after-action reporting for security events affecting classified systems * Manage and mentor ISSO personnel, establishing clear responsibilities and security workflows * Coordinate with IC and DoW security stakeholders, including IGs, inspectors, and oversight bodies * Ensure security architecture and engineering decisions align with mission requirements and applicable directives (ICD 503, CNSSI 1253, NIST SP 800-53) * Evaluate emerging threats and drive proactive security improvements across AI/ML and data platforms * Support audits, inspections, and reviews by government oversight authorities ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [It's all about the Data](https://www.wearedevelopers.com/videos/425-it-s-all-about-the-data) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)