Cybersecurity Systems Engineer / ISSM

AnaVation LLC

Chantilly (VA)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Disability insurance
Vision insurance
401k with match
Paid leave and holidays
Tuition reimbursement
Life Insurance

Job summary

AnaVation LLC in Chantilly, VA is seeking a Cybersecurity Systems Engineer / ISSM to lead the organization’s information security program. You will align cybersecurity with business objectives, manage audits, and supervise secure administration of corporate and classified IT environments.

Responsibilities include implementing the security program, coordinating with stakeholders, driving risk assessments, and reporting to executives on posture and vulnerabilities.

Qualifications

  • Bachelor’s degree in information security, Cybersecurity, Computer Science, IT, or related field or equivalent experience
  • 7+ years of progressive cybersecurity or information assurance experience
  • Experience as ISSM/ISSO/IA Manager or similar role
  • Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, DFARS 252.204-7012, CMMC, and DoD requirements
  • Experience developing SSPs, POA&Ms, security policies, standards, procedures
  • Experience supporting security audits and assessments
  • Excellent written, verbal, and presentation skills
  • Ability to communicate cybersecurity concepts to technical and non-technical audiences

Responsibilities

  • Develop, implement, and improve the corporate Information Security Program
  • Lead cybersecurity compliance activities with regulations and frameworks
  • Design and oversee secure operation and lifecycle management of systems
  • Develop and maintain SSPs, POA&Ms, policies, diagrams and documentation
  • Lead internal and external security assessments and ISO audits
  • Provide executive-level reporting on cybersecurity posture, risks, and vulnerabilities
  • Coordinate with stakeholders to ensure secure configuration management and patching
  • Manage cybersecurity incidents including investigation and remediation
  • Deliver security awareness training and support business development with security documentation

Skills

Cybersecurity leadership
Risk management
Security architecture
Regulatory compliance
Communication to executives
Independent technical work
Stakeholder influence

Education

Bachelor’s degree in information security /Cybersecurity / CS / IT

Tools

Microsoft 365 Government
Entra ID
Intune
Defender
Purview

Job description

Be Challenged and Make a Difference

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.

The Cybersecurity Systems Engineer / Information Systems Security Manager (ISSM) provides leadership for the organization's information security, governance, risk, and compliance program. The role is responsible for protecting the confidentiality, integrity, and availability of corporate and customer information systems while aligning cybersecurity practices with business objectives, contractual obligations, and regulatory requirements. This position serves as the organization's primary cybersecurity advisor and works collaboratively with Information Technology, Program Management, Contracts, Human Resources, and Executive Leadership to maintain compliance with applicable cybersecurity frameworks and contractual obligations. This is a hands‑on leadership role that combines information systems security management with responsibility for the secure administration, engineering, configuration, and maintenance of the organization’s corporate and classified information technology environments.

Responsibilities
  • Develop, implement, and continuously improve the corporate Information Security Program, serving as the primary ISSM and security lead for corporate, customer, classified, air‑gapped, and standalone information systems
  • Lead cybersecurity compliance activities associated with applicable regulations, contracts, and frameworks, including NIST SP 800-171, NIST SP 800-53, CMMC, CMMI, DFARS, FAR, ISO 27001, DCSA, RMF, ATO, and customer‑specific requirements
  • Design, implement, document, and oversee the secure operation and lifecycle management of corporate, cloud, classified, air‑gapped, and standalone systems, ensuring appropriate security controls are implemented and maintained
  • Develop and maintain SSPs, POA&Ms, authorization packages, policies, standards, procedures, system and network diagrams, inventories, configuration records, and documentation supporting account management, media control, auditing, incident response, and continuous monitoring
  • Lead internal and external security assessments, ISO audits, CMMC readiness activities, DCSA reviews, self‑inspections, vulnerability assessments, control validation, and remediation of identified findings
  • Conduct risk assessments, oversee vulnerability management and remediation tracking, monitor emerging threats and regulatory changes, and provide executive‑level reporting on cybersecurity posture, compliance, vulnerabilities, and risk
  • Manage cybersecurity incidents, including reporting, investigation, documentation, corrective action, and coordination with appropriate internal, customer, and government stakeholders
  • Review system changes from a security perspective and partner with IT personnel to ensure secure configuration management, patching, endpoint protection, identity and access management, backups, system hardening, and lifecycle maintenance
  • Administer, configure, secure, maintain, and troubleshoot Windows‑based servers and workstations, network and security devices, Microsoft 365 Government, Entra ID, Intune, Defender, Purview, privileged access, cloud services, and related technologies
  • Coordinate with the Facility Security Officer, Insider Threat Program Senior Official, system administrators, executive leadership, auditors, government customers, third‑party assessors, vendors, and managed service providers to ensure security responsibilities are assigned and executed
  • Develop and deliver security awareness and annual cybersecurity training for employees
  • Support business development activities through proposal responses, security compliance documentation, technology evaluations, and recommendations for security and infrastructure improvements.
Knowledge, Skills & Abilities
  • Strong knowledge of cybersecurity principles, risk management, and security architecture
  • Strong working knowledge of systems administration, endpoint and identity management, networking, cloud services, system hardening, backup and recovery, and technical troubleshooting, with the ability to translate security and contractual requirements into practical technical controls and system configurations
  • Ability to independently perform and document technical work while providing sound security guidance to leadership and balancing compliance, operational availability, cost, and business requirements
  • Ability to interpret government regulations and contractual security requirements
  • Excellent written, verbal, presentation, and executive communication skills
  • Strong analytical and problem‑solving skills
  • Excellent organizational and project management abilities
  • Ability to manage multiple priorities while meeting deadlines
  • Strong customer service orientation and collaborative leadership style
  • Ability to influence stakeholders across all levels of the organization
Required Qualifications
  • Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent combination of education and experience)
  • 7+ years of progressive cybersecurity or information assurance experience
  • Experience serving as an ISSM, ISSO, IA Manager, or similar role
  • Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, DFARS 252.204-7012, CMMC, and DoD cybersecurity requirements
  • Experience developing SSPs, POA&Ms, security policies, standards, and procedures
  • Experience supporting security audits and assessments
  • Excellent written, verbal, and presentation skills
  • Ability to effectively communicate cybersecurity concepts to both technical and non‑technical audiences
Physical Requirements
  • Ability to work at a computer for extended periods
  • Occasionally lift up to 25 pounds
Security Clearance
  • Ability to obtain and maintain a U.S. Government security clearance
  • Active Secret clearance required; Top Secret and SCI eligibility is desirable
Preferred Qualifications
  • CISSP certification (or ability to obtain within an agreed timeframe)
  • Certifications such as CISM, Security+, CASP+, CCSP, CGRC (formerly CAP), CEH
  • Experience with Microsoft 365 Government, Microsoft Defender, Microsoft Entra ID (Azure AD), Intune, and Microsoft Purview
  • Experience with SIEM, EDR, vulnerability scanning, and cloud security platforms
  • Experience supporting CMMC Level 2 or 3, ISO 27001, and/or ISO 20000 compliance programs
  • Experience with developing policies and procedures and passing DCSA audits
  • Experience supporting Defense Industrial Base (DIB) contractors
  • Experience supporting classified and unclassified information systems
Benefits
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long‑term and short‑term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance

AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

About AnaVation

AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top‑notch work environment, and a world‑class, collaborative team. If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Systems Engineer / ISSM
Cybersecurity Systems Engineer / ISSM

AnaVation, LLC • Chantilly (VA)

On-site
USD 120,000 - 160,000
401k plan with generous match
Tuition and training reimbursement
Competitive Pay
Cybersecurity Systems Engineer / ISSM
Cybersecurity Systems Engineer / ISSM

Nava • Chantilly (VA)

On-site
USD 120,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+4
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Socket.dev • San Antonio (TX)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Disability insurance
+5
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

AnaVation, LLC • San Antonio (TX)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+5
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Nava • San Antonio (TX), Northern (KY)

Hybrid
USD 150,000 - 190,000
Medical insurance for employees and/de
Dental insurance
Disability insurance
+5
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

AnaVation, LLC • San Antonio (TX)

On-site
USD 110,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+3
Sr. Security Specialist
Sr. Security Specialist

Nava • Washington

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+4
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Nava • San Antonio (TX), Northern (KY)

Hybrid
USD 125,000 - 170,000
Medical insurance
Dental insurance
Disability insurance
+6
Deputy Lead, Cyber Security Officer
Deputy Lead, Cyber Security Officer

Socket.dev • Reston (VA)

On-site
USD 130,000 - 180,000
Medical insurance
Dental insurance
Disability insurance
+2
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

AnaVation, LLC • San Antonio (TX)

On-site
USD 120,000 - 180,000
Generous medical insurance
Dental insurance
Disability insurance
+5