Alternate Information Systems Security Manager (ISSM)

ARA Brand

Raleigh (NC)

On-site

USD 110,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Applied Research Associates, Inc. (ARA) in Raleigh, NC seeks an early-career Information Systems Security Manager (ISSM) to oversee day-to-day cybersecurity for classified systems, with emphasis on SIPRNet connected to DoDIN and contractual requirements.

The Alternate ISSM will support RMF/ATO maintenance, eMASS administration, continuous monitoring, and coordination with technical stakeholders. The role reports to the Senior ISSM/Cybersecurity Team Manager and focuses on ensuring secure,

Qualifications

  • Active DoD Top Secret clearance required.
  • 5+ years in cybersecurity or information systems security in DoD environments.
  • Experience supporting RMF/DoD authorization processes and continuous monitoring.
  • Hands-on with eMASS or similar governance platforms.
  • Ability to communicate risk and status to technical staff and leadership.

Responsibilities

  • Serve as Alternate ISSM for assigned classified systems and maintain compliance.
  • Support RMF/ATO lifecycle activities including categorization and assessment.
  • Develop and maintain System Security Plans (SSPs), ATO documentation, risk assessments and evidence.
  • Administer eMASS records, control implementations, artifacts and assessment results.
  • Coordinate routine cybersecurity matters with technical teams and stakeholders; escalate significant risk.
  • Support DoD RMF/ATO package maintenance and continuous monitoring.
  • Assist with government reviews and corrective-action activities.

Skills

RMF/ATO lifecycle
eMASS administration
Vulnerability & audit compliance
DoD NIST SP 800-53 Rev.4/5
Incident response coordination

Education

Bachelor's degree (or equivalent)
Master's degree

Tools

eMASS
ACAS/Tenable
STIGs
SCAP
SIEM/log review
Change control processes

Job description

Applied Research Associates (ARA), Inc. has an immediate need for an early-career Information Systems Security Manager (ISSM) in Raleigh, NC. This role will provide day-to-day cybersecurity oversight for multiple classified information systems, with primary emphasis on a SIPRNet environment connected to the DoDIN and associated contractual cybersecurity requirements. The position is focused on maintaining secure, authorized, and inspection-ready operations across assigned DCSA/DoW environments. The Alternate ISSM will support RMF/ATO maintenance, eMASS administration, continuous monitoring, vulnerability and audit compliance, assessment readiness, and coordination technical stakeholders while reporting to the Senior ISSM/Cybersecurity Team Manager.

Alternate Information Systems Security Manager Primary Responsibilities:
  • Serve as an Alternate ISSM for assigned classified systems and maintain day-to-day cybersecurity compliance, authorization readiness, and risk visibility.
  • Support Risk Management Framework (RMF) and Authorization to Operate (ATO) lifecycle activities, including system categorization, control implementation and assessment support, authorization package maintenance, and continuous monitoring.
  • Develop, review, and maintain cybersecurity documentation including System Security Plans (SSPs), Security Assessment Plans/Reports, POA&Ms, risk assessments and acceptances, continuous monitoring records, inventory, network diagrams, ports/protocols/services documentation, and supporting evidence.
  • Administer and quality-check eMASS records, control implementation statements, artifacts, assessment results, inherited controls, deficiencies, risk decisions, and authorization documentation.
  • Maintain assessment and inspection readiness; support DCSA, DoW, customer, and other Government cybersecurity reviews, annual self-assessments, and corrective-action activities.
  • Review system changes through configuration/change-control processes, assess security impact, and ensure approved changes are reflected in baselines, inventories, diagrams, and RMF artifacts.
  • Coordinate routine cybersecurity matters with technical teams and other mission partners; elevate significant risk or resource issues to the Senior ISSM.
  • Support development and maintenance of overarching DCSA cybersecurity policies, procedures, templates, and common documentation as assigned by the Senior ISSM.
  • Support incidents, urgent vulnerabilities, emergency patching, outages affecting security controls, and Government-directed cybersecurity actions when required.
Alternate Information Systems Security Manager Qualifications:
  • US Citizen with an active DoD Top Secret clearance; SCI eligibility preferred.
  • Bachelor's (or equivalent) with 5 - 7 yrs. of experience, or a Master's and 3 to 5 yrs. of experience; equivalent directly relevant experience may be considered in leu of degrees.
  • 5+ years of supporting cybersecurity, information assurance, information systems security, or related IT environments, including experience supporting classified Government systems.
  • 2+ years of experience performing ISSM, senior ISSO/IA, or comparable cybersecurity leadership responsibilities.
  • Experience supporting DoD RMF and DCSA authorization processes, with familiarity with DoDM/DoDI directive, NIST SP 800-53 Rev. 4 and Rev. 5, 32 CFR Part 117 (NISPOM), and continuous monitoring requirements.
  • Hands-on experience with eMASS or a comparable Government governance-risk-compliance platform.
  • Experience with vulnerability and configuration-compliance tools and processes such as ACAS/Tenable, STIGs, SCAP, SIEM/log review, patch management, and remediation tracking.
  • Ability to meet DoD 8750/DoD 8140 cybersecurity workforce qualification requirements applicable to the assigned ISSM/IAM work role.
  • Demonstrated ability to communicate technical risk, authorization status, deficiencies, and resource needs to technical staff, program leadership, and Government stakeholders.
Alternate Information Systems Security Manager Preferences:
  • Direct experience supporting SIPRNet or other DoDIN-connected classified environments.
  • Experience preparing for or supporting CORA, security control assessments, DCSA reviews, or comparable Government cybersecurity assessments.
  • Advanced cybersecurity certification or another DoD-approved credential appropriate to the assigned work role.
  • Experience with Splunk or another SIEM, ACAS/Tenable Security Center, Windows and Linux security baselines, virtualization, Active Directory/Group Policy, and network-security technologies.
  • Experience leading or coordinating cross-functional cybersecurity teams that include ISSOs, security engineers, system administrators, and program personnel.
Who is ARA?

Do you want to work for a purpose? Applied Research Associates, Inc. (aka ARA) is an employee-owned international research and engineering company. We have been providing technically superior solutions to complex and challenging problems in the physical sciences since 1979. ARA has over 2,279 employee owners and continues to grow rapidly. Together, our offices throughout the U.S. and Canada provide a broad range of technical expertise in defense, civil, and health technologies, computer software and simulation, systems analysis, environmental technologies, and testing and measurement.

ARA also prides itself, on having a challenging culture where innovation & experimentation are the norm. The motto, “Engineering and Science for Fun and Profit” sums up the ARA experience. Employee ownership ensures you have a voice with what happens in the company.

To find out more about what the Integrated Mission Systems Sector has to offer, visit our website at https://www.ara.com/raleigh/

To learn more about our generous benefits program including health, life & disability, retirement, flexible spending, rewards & recognition, work/life balance, professional development and relocation visit https://www.ara.com/benefits/

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Alternate Information Systems Security Manager (ISSM)
Alternate Information Systems Security Manager (ISSM)

Applied Research Associates, Inc. • Raleigh (NC), Northern (KY)

Hybrid
USD 110,000 - 150,000
Systems Administrator
Systems Administrator

ARA • Albuquerque (NM)

On-site
USD 90,000 - 130,000
Systems Administrator
Systems Administrator

ARA Brand • Albuquerque (NM)

On-site
USD 90,000 - 130,000
RMF ISSO Leader - TS/SCI, Cloud & On-Prem Security
RMF ISSO Leader - TS/SCI, Cloud & On-Prem Security

Ara • Raleigh (NC)

On-site
USD 90,000 - 150,000
Systems Administrator
Systems Administrator

Talentify • Albuquerque (NM)

On-site
USD 90,000 - 120,000
Alternate ISSM: DoD RMF & SIPRNet Security Lead
Alternate ISSM: DoD RMF & SIPRNet Security Lead

ARA Brand • Raleigh (NC)

On-site
USD 110,000 - 150,000
Systems Administrator
Systems Administrator

Applied Research Associates, Inc. • Albuquerque (NM), Northern (KY)

Hybrid
USD 70,000 - 110,000
Employee ownership (ESOP)
Staff Network Engineer
Staff Network Engineer

ARA • Raleigh (NC)

On-site
USD 120,000 - 175,000
Health, life and disability benefits
Retirement plan
Flexible spending accounts
+3
SCIF_SAPF Project Manager
SCIF_SAPF Project Manager

ARA • Falls Church (VA)

On-site
USD 180,000 - 190,000
Staff Network Engineer
Staff Network Engineer

Applied Research Associates, Inc. • Raleigh (NC), Northern (KY)

Hybrid
USD 110,000 - 160,000