- Salary
- $100k – $150k
- Location
- McLean, VA, US
- Type
- Full-time
- Department
- IT
- Seniority
- Manager
- Experience
- 2+ years
- Clearance
- Required
- Closing date
- Today
- Source
- iCIMS
Description
Overview
We are seeking a mid-level Information System Security Manager (ISSM) to support security operations in classified environments while also serving in a secondary role within the Cyber Operations team. This position is ideal for a security professional with hands-on ISSM experience, a strong understanding of the Authorization to Operate (ATO) process and Risk Management Framework (RMF), and experience partnering with DCSA to authorize systems for classified use.
In addition to ISSM responsibilities, this role will support Cyber Operations activities focused on administering, testing, validating, and maintaining enterprise security systems and controls to strengthen the overall security posture of the environment.
Responsibilities
- Serve as the primary cybersecurity lead for assigned information systems operating in classified environments
- Oversee the implementation, compliance, and maintenance of system security requirements in accordance with government, customer, and organizational policies
- Lead the system through the RMF lifecycle, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring
- Manage activities required to obtain, maintain, and renew Authorization to Operate (ATO) decisions for classified systems
- Develop, review, and maintain security authorization documentation, including System Security Plans, security control assessments, POAMs, configuration management records, and related artifacts
- Coordinate with DCSA, Authorizing Officials, system owners, engineers, administrators, and assessors to support security authorization and ongoing compliance activities
- Ensure security controls are implemented, operating as intended, and documented appropriately for classified information systems
Qualifications
- Active Secret clearance required with the ability to obtain and maintain Top Secret eligibility REQUIRED.
- 5+ years of cybersecurity, information assurance, or information security experience, including experience supporting classified information systems
- 2+ years of experience serving as an ISSM, ISSO, or equivalent cybersecurity role supporting RMF-authorized environments.
- Experience in cybersecurity operations environment
- Experience obtaining, maintaining, and renewing Authorization to Operate (ATO) decisions for classified systems.
Working knowledge of:
- NIST Risk Management Framework (RMF)
- NIST SP 800-53 Security Controls
- DCSA Assessment and Authorization Process Manual (DAAPM)