Enterprise Information System Security Manager (ISSM)

Integrity Solutions, Engineering, and Analytics Corporation

Virginia (MN, MD)

On-site

USD 140,000 - 200,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Integrity Solutions, Engineering, and Analytics Corporation seeks an experienced Information System Security Manager (ISSM) to manage RMF processes across the enterprise and mentor ISSMs/ISSOs. You will oversee ATO, develop the RMF baseline, and drive continuous monitoring with automated tools.

The role requires US citizenship and the ability to obtain a government security clearance, with strong communication to senior leadership and a focus on risk-based decision making.

Qualifications

  • Experience managing RMF for enterprise systems.
  • Mentor ISSMs and ISSOs; provide guidance to senior leadership.
  • US citizenship and ability to obtain a government clearance.

Responsibilities

  • Oversee the RMF process and ensure valid Authority to Operate across portfolio.
  • Develop, implement, and monitor the RMF baseline for enterprise security controls.
  • Draft and enforce enterprise security policies, SOPs, and SSPs per ICD 503.
  • Lead risk assessments for complex, interconnected systems and assess impact of changes.
  • Drive Continuous Monitoring program using automated tools for real-time control effectiveness.
  • Oversee POA&Ms lifecycle and prioritize high-risk findings.
  • Act as senior cybersecurity advisor to program managers and leadership.
  • Provide training and oversight to ISSMs/ISSOs on assessment methodologies.

Skills

RMF expertise
NIST SP 800-37/53/137
ICD 503 CNSSI 1253
Leadership

Tools

Xacta
GRC tooling
Cloud security

Job description

Job Description:

ISEA is searching for an experienced and motivated Information System Security Manager (ISSM) to join our growing team. In this role, you will be responsible for managing and executing the Risk Management Framework (RMF) process across the customer’s enterprise, overseeing a portfolio of information systems, and ensuring the consistent application of security requirements throughout the system lifecycle. The ideal candidate possesses the ability to manage complex Body of Evidence (BoE) packages, mentor subordinate ISSMs and ISSOs, and provide risk-based recommendations to the Authorizing Official (AO).

Responsibilities:
  • Oversee the RMF process, ensuring all systems within the portfolio maintain a valid Authority to Operate.
  • Develop, implement, and monitor the RMF program baseline, ensuring security controls are tailored to meet enterprise and mission-specific requirements.
  • Author and enforce enterprise-wise security policies, SOPs, and SSPs that align with ICD 503.
  • Conduct high-level risk assessments for complex, interconnected systems, evaluating the impact of system changes on the enterprise security posture.
  • Drive the implementation of the customer’s Continuous Monitoring program, utilizing automated tools to track real-time security control effectiveness and vulnerability remediation.
  • Oversee the lifecycle of POA&Ms across the portfolio, ensuring technical teams and system owners prioritize high-risk findings.
  • Serve as the senior cybersecurity advisor to program managers, system owners, and the customer’s senior leadership regarding risk mitigation strategies.
  • Provide guidance, training, and technical oversight to a team of ISSMs and ISSOs, ensuring consistent quality in assessment methodologies and documentation.
  • Lead the preparation for and response to external audits and inspections, representing the customer’s security interests.
Qualifications:
  • Expert-level knowledge of ICD 503, CNSSI 1253, and NIST Risk Management Framework (NIST SP 800-37, 800-53, 800-137).
  • Proficiency with enterprise Governance, Risk, and Compliance (GRC) tools, such as Xacta.
  • Comprehensive understanding of enterprise-level architectures, including cloud security, cross-domain solutions (CDS), and global network infrastructures (JWICS, SIPRNet).
  • Exceptional ability to articulate technical risks and “move assessments forward” by providing clear, actionable strategies to non-technical senior executives.
  • Possess a deep understanding and awareness that “no system is the same,” with the ability to demonstrate an adaptive approach to security rather than a one-size-fits-all compliance checklist.
  • A proactive commitment to continuous improvement, seeking out ways to optimize reporting, assessment timelines, and security automation.
Citizenship/Clearance Requirements:
  • US Citizenship is required.
  • Must be eligible to obtain and maintain a government security clearance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Manager - Basic (ISSM-Basic)
Information Systems Security Manager - Basic (ISSM-Basic)

ACQCENTRIC INC • Huntsville (AL)

On-site
USD 90,000 - 140,000
Senior RMF & Enterprise Security Manager
Senior RMF & Enterprise Security Manager

Integrity Solutions, Engineering, and Analytics Corporation • Virginia (MN)

On-site
USD 140,000 - 200,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

RMantra Solutions • Fort Meade (MD), Northern (KY)

On-site
USD 130,000 - 170,000
Information Systems Security Manager Senior
Information Systems Security Manager Senior

Modern Technology Solutions, Inc. (MTSI) • Bath Township (OH)

On-site
USD 150,000 - 190,000
Information System Security Manager
Information System Security Manager

Istari Digital • Arlington (VA)

On-site
USD 140,000 - 200,000
Security Control Assessor (SCA)
Security Control Assessor (SCA)

Integrity Solutions, Engineering, and Analytics Corporation • Virginia (MN)

On-site
USD 110,000 - 170,000
Information Systems Security Manager
Information Systems Security Manager

ecsfederal • Virginia (MN)

On-site
USD 170,000 - 190,000
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

General Dynamics Information Technology, Inc. • Bedford (MA)

On-site
USD 120,000 - 180,000
None
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

General Dynamics Information Technology • Bedford (MA)

On-site
USD 120,000 - 170,000
Information Systems Security Manager - Basic (IFMC)
Information Systems Security Manager - Basic (IFMC)

Mission Driven Research • Huntsville (AL)

On-site
USD 90,000 - 150,000