Information Systems Security Manager (ISSM)
Indexed description
The ideal candidate will have demonstrated experience managing multiple authorization packages across different government agencies, system architectures, classification levels, and mission environments. Experience supporting Special Access Programs is strongly preferred.
This position requires an individual who can work independently, coordinate effectively with technical and program personnel, and translate government cybersecurity requirements into practical, sustainable processes.
What You’ll Do
- Serve as the appointed ISSM for classified information systems.
- Lead the development, submission, maintenance, and reauthorization of system authorization packages in eMASS or other government-directed authorization platforms.
- Manage multiple systems and authorization efforts across collateral, SCI, SAP, and other customer security environments, as applicable.
- Develop and maintain System Security Plans (SSP), security policies, procedures, control implementation statements, diagrams, inventories, risk assessments, Plans of Action and Milestones, and continuous-monitoring documentation.
- Coordinate directly with DCSA Information System Security Professionals, Authorizing Officials, government cybersecurity representatives, program security personnel, and customer system owners.
- Interpret and implement requirements from 32 CFR Part 117, the DCSA DAAG, NIST SP 800-53, applicable Security Technical Implementation Guides, Committee on National Security Systems guidance, and customer-specific direction.
- Evaluate proposed system architectures, authorization boundaries, hardware, software, connections, data flows, and classified processing requirements.
- Support the development and approval of new classified systems, including proposal systems, standalone systems, peer-to-peer environments, client-server networks, and interconnected systems.
- Establish and manage configuration-control, change-management, vulnerability-management, audit, patching, account-management, media-protection, and incident-response processes.
- Ensure system changes are reviewed, documented, approved, and maintained within the authorized security posture.
- Conduct periodic reviews, self-inspections, control assessments, vulnerability scans, and continuous-monitoring activities.
- Coordinate classified-system requirements with the Facility Security Officer, program leadership, Information Technology, physical security, personnel security, and insider-threat personnel.
- Prepare systems and supporting personnel for DCSA, customer, SAP, SCI, and other government cybersecurity inspections or assessments.
- Identify program deficiencies, communicate risk to leadership, and ensure corrective actions are documented and completed.
- Develop repeatable processes, templates, and governance standards that can scale as the company’s classified-system portfolio grows.
- Bachelor’s degree in related field, or an equivalent combination of education and relevant experience.
- CISSP, CISM, or equivalent advanced cybersecurity certification.
- 7+ years of progressively responsible cybersecurity, information-assurance, classified-system, or Risk Management Framework experience.
- 3+ years of direct experience serving as an ISSM or ISSO
- Demonstrated experience developing, managing, or maintaining authorization packages in eMASS.
- Ability to evaluate Windows, Linux, standalone, peer-to-peer, client-server, and networked system environments.
- Candidate must be a U.S. Citizen
- Active Top Secret clearance REQUIRED, with eligibility for SCI access highly preferred
- IAT Level II - (Security+ CE, CCNA Security, etc.)
- DoD 8570.01-M IAM Level II (in lieu of IAT Level II)
- Experience supporting Special Access Programs
- Experience managing authorization packages across multiple agencies, Authorizing Officials, or security cognizance authorities.
- Experience with collateral, SCI, and SAP systems at the Secret and Top Secret levels.
- Experience supporting multi-program or shared systems with access separation and multiple DD Form 254 requirements.
- Experience with security assessments, government inspections, vulnerability scanning, STIG implementation, audit review, and corrective-action tracking.
CFD Research is an EO employer - Veterans/Disabled and other protected categories
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search