Information Systems Security Manager

Zachary Piper
Arlington, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$140,000.0 - $170,000.0
Working hours
Regular working hours

Tech stack

Xacta Artificial Intelligence Cyber Security Information Systems Identity and Access Management Information Security Management Information Systems Security Architecture Professional Package Development Process Smartsuite Information Technology RSA Archer Platform

Job description

  • Lead Program Operations: Serve as the primary contract point of contact, managing day-to-day activities, priorities, deliverables, & stakeholder coordination
  • Manage RMF & Authorization Workflows: Oversee authorization activities in eMASS, including package development, approvals, inheritance, reciprocity, & continuous monitoring
  • Drive Enterprise Governance: Support development & maturation of the ISSM program, standardizing processes, policies, & cybersecurity practices
  • Track Program Execution: Manage schedules, tasking, risks, dependencies, & deliverables across cybersecurity workstreams
  • Facilitate Team Coordination: Lead meetings, status briefings, & working sessions with Government & contractor stakeholders
  • Support Workforce Operations: Coordinate onboarding/offboarding, knowledge transfer, & team integration activities
  • Develop Policies & Documentation: Author and maintain SOPs, governance frameworks, process guides, & implementation documentation
  • Enable Control Inheritance: Define & operationalize enterprise-level controls in eMASS, reducing redundancy & improving scalability of ATO processes
  • Mentor Cyber Personnel: Provide guidance & mentorship to ISSMs, ISSOs, & cybersecurity staff to ensure consistency and quality
  • Support Training Initiatives: Develop & deliver ISSM training, educational sessions, & knowledge-sharing materials
  • Standardize Artifacts: Create reusable templates & standardized Body of Evidence artifacts to enhance authorization package quality
  • Oversee Continuous Monitoring: Support enterprise ConMon activities & ongoing cybersecurity oversight across systems, Keywords: ISSM, Information Systems Security Manager, ISSO, Information Systems Security Officer, ISSE, Information Systems Security Engineer, SME, Subject Matter Expert, National Security, NatSec, federal, government, Arlington, VA, Virginia, DOD, DOW, Department of Defense, Department of War, cybersecurity governance, RMF execution, operations, emerging AI, data, analytics, cyber, cybersecurity, AI, authorization, workflows, mentor, security operations, program operation, RMF, risk management framework, authorization, workflow, eMASS, package development, approvals, inheritance, reciprocity, continuous monitoring, ConMon, Enterprise Governance, standardize, standardization, processes, policies, cybersecurity practices, practices, Program Execution, schedules, tasking, risks, dependencies, deliverables, status briefings, stakeholder, onboarding, onboard, offboarding, offboard, knowledge transfer, team integration, SOP, standard operating procedure, governance frameworks, process guides, implementation documentation, redundancy, scalability, ATO, authority to operate, guidance, mentor, mentorship, train, training, standardize, template, BOE, body of evidence, artifact, authorization, package, A&A, GRC, communication, written, verbal, assessment & authorization, FedRAMP, Information Technology, Computer Science, CS, IT, IAT, IAM, OSD, Joint Staff, Military Service, Xacta, federal authorization, TS, top secret, topsecret, top secret clearance, tssci, ts/sci, ts sci, Ts with sci, ts w/ sci, ts w sci, tswithsci, top secret with sci, CASP, CASP+, CASP +, CISSP, CASP+ CE, CASP+ce, certified information systems security professional, certified informations systems security professional, certified information system security professional, certified advanced security practitioner, comptia casp, comptia CASP+, Iat III, iat level iii, iat3, iat 3, iat level three, iat three, iatthree, iat3, GCED, GCIH, certified information systems auditor, certified information system auditor, GIAC Certified enterprise defender, GIAC certified incident handler, iam iii, iamiii, Iam level iii, iam level 3, iam level three, iam three, iam3, iam 3, cissp, gslc, cciso, certified information security manager, certified information systems security professional, certified information system security professional, giac security leadership, giac security leadership certification, chief information security officer, chief informations security officer, governance risk and compliance, governance risk & compliance

Requirements

  • 10+ years of cybersecurity experience
  • Proven experience managing RMF A&A activities & authorization packages using eMASS or similar GRC tools
  • Strong knowledge of DoD cybersecurity policies and frameworks
  • Experience developing cybersecurity policies, SOPs, governance frameworks, & operational procedures
  • Demonstrated ability to manage program execution, task tracking, & stakeholder communication in fast-paced environments
  • Experience implementing control inheritance strategies & enterprise cybersecurity standardization
  • Ability to mentor and develop cybersecurity personnel across multiple programs
  • Strong written & verbal communication skills with the ability to brief senior military, civilian, & SES leadership
  • Familiarity with continuous monitoring, FedRAMP, & federal A&A processes
  • Active TS/SCI clearance required
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (Master’s preferred or equivalent experience)
  • IAT/IAM certification
  • Experience supporting OSD, Joint Staff, or Military Service components
  • Hands-on experience with eMASS, Xacta, or similar GRC platforms
  • Experience supporting FedRAMP and federal authorization processes

Benefits & conditions

  • Salary Range: $140,000-170,000 depending on experience
  • Benefits: Medical, Dental, Vision, 401k Plan, Holidays, PTO, sick leave as required by law

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all