Alternate Information Systems Security Manager (ISSM)

Applied Research Associates, Inc.

Raleigh, Northern (NC, KY)

Hybrid

USD 110,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Applied Research Associates, Inc. seeks an early-career Alternate Information Systems Security Manager (ISSM) to oversee daily cybersecurity for multiple classified systems in Raleigh, NC, with emphasis on SIPRNet environments.

The role includes RMF/ATO lifecycle support, eMASS administration, continuous monitoring, and coordination with Government stakeholders. The position requires DoD Top Secret clearance, 5+ years in cybersecurity or related IT environments, and experience with RMF, DoD

Qualifications

  • U.S. Citizen with active DoD Top Secret clearance; SCI eligibility preferred.
  • Bachelor's degree + 5–7 yrs experience or Master's + 3–5 yrs experience.
  • 5+ years in cybersecurity, information assurance, or related IT environments, including classified Government systems.
  • 2+ years in ISSM/leadership roles in cybersecurity.
  • Experience with DoD RMF/DoD 8750/8140 and DoD/DCSA processes and continuous monitoring.

Responsibilities

  • Serve as Alternate ISSM for assigned classified systems and maintain day-to-day cybersecurity compliance.
  • Support RMF/ATO lifecycle activities including system categorization and assessment support.
  • Develop and maintain SSPs, security plans/reports, POA&Ms and risk assessments.
  • Administer eMASS records and artifacts; track control implementation and remediation.
  • Maintain assessment readiness and coordinate government cybersecurity reviews.
  • Review changes for security impact and ensure baselines and RMF artifacts reflect updates.
  • Coordinate with technical teams and management on risk and resource needs.
  • Contribute to DoD cybersecurity policy templates and documentation.
  • Support incident response and urgent vulnerability remediation as required.

Skills

US Citizenship
Active DoD TS clearance
RMF/ATO experience
eMASS administration
Vulnerability management
Technical leadership

Education

Bachelor's degree in a related field
Master's degree

Tools

eMASS
ACAS/Tenable
SIEM
NIST SP 800-53 guidance

Job description

Alternate Information Systems Security Manager (ISSM)

Job Category: Information Technology

Requisition Number: ALTER010119

  • Full-Time
Locations

Showing 1 location

Description

Applied Research Associates (ARA), Inc. has an immediate need for an early-career Information Systems Security Manager (ISSM) in Raleigh, NC. This role will provide day-to-day cybersecurity oversight for multiple classified information systems, with primary emphasis on a SIPRNet environment connected to the DoDIN and associated contractual cybersecurity requirements. The position is focused on maintaining secure, authorized, and inspection-ready operations across assigned DCSA/DoW environments. The Alternate ISSM will support RMF/ATO maintenance, eMASS administration, continuous monitoring, vulnerability and audit compliance, assessment readiness, and coordination technical stakeholders while reporting to the Senior ISSM/Cybersecurity Team Manager.

Alternate Information Systems Security Manager Primary Responsibilities:

  • Serve as an Alternate ISSM for assigned classified systems and maintain day-to-day cybersecurity compliance, authorization readiness, and risk visibility.
  • Support Risk Management Framework (RMF) and Authorization to Operate (ATO) lifecycle activities, including system categorization, control implementation and assessment support, authorization package maintenance, and continuous monitoring.
  • Develop, review, and maintain cybersecurity documentation including System Security Plans (SSPs), Security Assessment Plans/Reports, POA&Ms, risk assessments and acceptances, continuous monitoring records, inventory, network diagrams, ports/protocols/services documentation, and supporting evidence.
  • Administer and quality-check eMASS records, control implementation statements, artifacts, assessment results, inherited controls, deficiencies, risk decisions, and authorization documentation.
  • Maintain assessment and inspection readiness; support DCSA, DoW, customer, and other Government cybersecurity reviews, annual self-assessments, and corrective-action activities.
  • Review system changes through configuration/change-control processes, assess security impact, and ensure approved changes are reflected in baselines, inventories, diagrams, and RMF artifacts.
  • Coordinate routine cybersecurity matters with technical teams and other mission partners; elevate significant risk or resource issues to the Senior ISSM.
  • Support development and maintenance of overarching DCSA cybersecurity policies, procedures, templates, and common documentation as assigned by the Senior ISSM.
  • Support incidents, urgent vulnerabilities, emergency patching, outages affecting security controls, and Government-directed cybersecurity actions when required.

Alternate Information Systems Security Manager Qualifications:

  • US Citizen with an active DoD Top Secret clearance; SCI eligibility preferred.
  • Bachelor's (or equivalent) with 5 - 7 yrs. of experience, or a Master's and 3 to 5 yrs. of experience; equivalent directly relevant experience may be considered in leu of degrees.
  • 5+ years of supporting cybersecurity, information assurance, information systems security, or related IT environments, including experience supporting classified Government systems.
  • 2+ years of experience performing ISSM, senior ISSO/IA, or comparable cybersecurity leadership responsibilities.
  • Experience supporting DoD RMF and DCSA authorization processes, with familiarity with DoDM/DoDI directive, NIST SP 800-53 Rev. 4 and Rev. 5, 32 CFR Part 117 (NISPOM), and continuous monitoring requirements.
  • Hands-on experience with eMASS or a comparable Government governance-risk-compliance platform.
  • Experience with vulnerability and configuration-compliance tools and processes such as ACAS/Tenable, STIGs, SCAP, SIEM/log review, patch management, and remediation tracking.
  • Ability to meet DoD 8750/DoD 8140 cybersecurity workforce qualification requirements applicable to the assigned ISSM/IAM work role.
  • Demonstrated ability to communicate technical risk, authorization status, deficiencies, and resource needs to technical staff, program leadership, and Government stakeholders.

Alternate Information Systems Security Manager Preferences:

  • Direct experience supporting SIPRNet or other DoDIN-connected classified environments.
  • Experience preparing for or supporting CORA, security control assessments, DCSA reviews, or comparable Government cybersecurity assessments.
  • Advanced cybersecurity certification or another DoD-approved credential appropriate to the assigned work role.
  • Experience with Splunk or another SIEM, ACAS/Tenable Security Center, Windows and Linux security baselines, virtualization, Active Directory/Group Policy, and network-security technologies.
  • Experience leading or coordinating cross-functional cybersecurity teams that include ISSOs, security engineers, system administrators, and program personnel.

Who is ARA?

Do you want to work for a purpose? Applied Research Associates, Inc. (aka ARA) is an employee-owned international research and engineering company. We have been providing technically superior solutions to complex and challenging problems in the physical sciences since 1979. ARA has over 2,279 employee owners and continues to grow rapidly. Together, our offices throughout the U.S. and Canada provide a broad range of technical expertise in defense, civil, and health technologies, computer software and simulation, systems analysis, environmental technologies, and testing and measurement.

ARA also prides itself, on having a challenging culture where innovation & experimentation are the norm. The motto, “Engineering and Science for Fun and Profit” sums up the ARA experience. Employee ownership ensures you have a voice with what happens in the company.

To learn more about our generous benefits program including health, life & disability, retirement, flexible spending, rewards & recognition, work/life balance, professional development and relocation visit https://www.ara.com/benefits/

Education
Required

Bachelors or better.

Preferred

Masters or better.

Experience
Required

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Alternate Information Systems Security Manager (ISSM)
Alternate Information Systems Security Manager (ISSM)

ARA Brand • Raleigh (NC)

On-site
USD 110,000 - 150,000
Systems Administrator
Systems Administrator

Applied Research Associates, Inc. • Albuquerque (NM), Northern (KY)

Hybrid
USD 70,000 - 110,000
Employee ownership (ESOP)
Systems Administrator
Systems Administrator

Talentify • Albuquerque (NM)

On-site
USD 90,000 - 120,000
RMF ISSO Leader - TS/SCI, Cloud & On-Prem Security
RMF ISSO Leader - TS/SCI, Cloud & On-Prem Security

Ara • Raleigh (NC)

On-site
USD 90,000 - 150,000
Systems Administrator
Systems Administrator

ARA • Albuquerque (NM)

On-site
USD 90,000 - 130,000
Alternate ISSM: DoD RMF & SIPRNet Security Lead
Alternate ISSM: DoD RMF & SIPRNet Security Lead

ARA Brand • Raleigh (NC)

On-site
USD 110,000 - 150,000
Information System Security Engineer (ISSE) – Risk Management Framework (RMF), AWS, ACAS, Splunk
Information System Security Engineer (ISSE) – Risk Management Framework (RMF), AWS, ACAS, Splunk

Ara • Raleigh (NC)

On-site
USD 110,000 - 150,000
Employee ownership
WIN program
ISSM SME
ISSM SME

Applied Res • Bedford (MA)

On-site
USD 185,000 - 200,000
Information System Security Manager
Information System Security Manager

Amentum • Northern (KY)

On-site
USD 100,000 - 110,000
Health insurance
Paid time off
401(k) matching
+6
Alternate ISSM - RMF, DoDIN & eMASS Oversight
Alternate ISSM - RMF, DoDIN & eMASS Oversight

Applied Research Associates, Inc. • Raleigh (NC), Northern (KY)

Hybrid
USD 110,000 - 150,000