Information System Security Manager (ISSM)

Systems Planning & Analysis

Lincoln (MA)

On-site

USD 180,000 - 215,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Retirement plans
Paid time off

Job summary

Systems Planning and Analysis, Inc. in Massachusetts is seeking an Information System Security Manager (ISSM) to lead the RMF, accreditation package development, and coordination with government security stakeholders across the Mission Planning Enterprise.

The ideal candidate will hold a BS in cybersecurity or related field with 8+ years of cybersecurity experience, DoD RMF expertise, an active DoD Secret clearance, and a CISSP/CAP/CISM certification.

Qualifications

  • BS in cybersecurity, computer science, information assurance, or similar field plus 8+ years of cybersecurity experience on medium-to-large IT or software programs, including at least 4 years in an ISSM or equivalent leadership role
  • Direct experience implementing DoD RMF (and prior DIACAP) processes, including authoring and maintaining accreditation packages and FISMA-related records
  • Demonstrated experience leading or supporting DISA STIG compliance, vulnerability scanning, penetration testing, and testing in NIPR/SIPR and related environments
  • Familiarity with mission planning or similar weapon-system security contexts, including support for ATO and ATC activities and security targets
  • DoD-approved cybersecurity certification such as CISSP, CAP, or CISM
  • Active DoD Secret clearance (or higher) and the ability to maintain it throughout employment

Responsibilities

  • The ISSM is responsible for the overall cybersecurity posture, compliance, and accreditation of systems delivered under this contract.
  • They lead RMF activities, maintain security documentation and artifacts, and coordinate with government security officials on security testing, ATO/ATC actions, and policy compliance.
  • The ISSM defines and enforces cybersecurity and cyber-resiliency practices across the development and integration lifecycle, including secure coding standards, vulnerability management, and security training.
  • They work closely with engineering, test, and platform operations to embed security controls into architectures, pipelines, and test environments, ensuring that cybersecurity is a first-class aspect of the Mission Planning Enterprise.
  • Salary information indicates a competitive compensation package aligned with market ranges.

Skills

RMF leadership
Cybersecurity expertise
Security policy

Education

BS in cybersecurity or CS
8+ years cybersecurity experience

Tools

NIPR/SIPR environments

Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

The Sea, Land, Air Analysis Group’s mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, USAF, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.

SPA has a need for an Information System Security Manager (ISSM), who will serve as the overall cybersecurity lead for the systems and environments delivered under this contract. This individual will own RMF execution, accreditation package development, and coordination with government security stakeholders. The ISSM will be responsible for defining and enforcing cybersecurity and cyber‑resiliency practices that are integrated into development, integration, and test activities across the Mission Planning Enterprise.

Responsibilities

The ISSM is responsible for the overall cybersecurity posture, compliance, and accreditation of systems delivered under this contract. They lead Risk Management Framework (RMF) activities, maintain security documentation and artifacts, and coordinate with government security officials on security testing, ATO/ATC actions, and policy compliance. The ISSM defines and enforces cybersecurity and cyber‑resiliency practices across the development and integration lifecycle, including secure coding standards, vulnerability management, and security training. They work closely with engineering, test, and platform operations to embed security controls into architectures, pipelines, and test environments, ensuring that cybersecurity is a first‑class aspect of the Mission Planning Enterprise.

Qualifications
Required Qualifications
  • BS in cybersecurity, computer science, information assurance, or similar field plus 8+ years of cybersecurity experience on medium‑to‑large IT or software programs, including at least 4 years in an ISSM or equivalent leadership role
  • Direct experience implementing DoD RMF (and prior DIACAP) processes, including authoring and maintaining accreditation packages and FISMA‑related records
  • Demonstrated experience leading or supporting DISA STIG compliance, vulnerability scanning, penetration testing, and testing in NIPR/SIPR and related environments
  • Familiarity with mission planning or similar weapon‑system security contexts, including support for ATO and ATC activities and security targets
  • DoD‑approved cybersecurity certification such as CISSP, CAP, or CISM
  • Active DoD Secret clearance (or higher) and the ability to maintain it throughout employment
Desired Qualifications
  • Master’s degree in relevant field plus experience developing and maintaining enterprise cybersecurity master plans, Program Protection Plans, anti‑tamper plans, and related security documentation
  • Familiarity with Air Force cybersecurity policy and coordination with AF network and accreditation authorities
  • Background in cyber resiliency for mission or weapon systems, including secure coding standards, security‑focused scenarios, and user certification requirements
  • Experience integrating security controls into DevSecOps pipelines and CDE environments, including automated compliance and security testing
  • Prior experience addressing security considerations for FMS deliveries and multi‑national information‑sharing constraints
Pay Range Information

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Massachusetts, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $215,000.00/Yr.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Arenatechnologies • Lincoln (MA)

On-site
USD 180,000 - 215,000
Information Systems Security Manager
Information Systems Security Manager

Systems Planning and Analysis, Inc. • Arlington (VA)

On-site
USD 130,000 - 170,000
Information Systems Security Manager
Information Systems Security Manager

Arenatechnologies • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Retirement plan
Paid time off
Information Systems Security Manager
Information Systems Security Manager

Systems Planning & Analysis • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Flexible spending accounts
Health savings accounts
+3
Information Systems Security Manager
Information Systems Security Manager

Arenatechnologies • San Diego (CA)

On-site
USD 125,000 - 175,000
Health insurance
Retirement savings plans
Flexible spending accounts
Information Systems Security Engineer
Information Systems Security Engineer

Systems Planning & Analysis • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Officer
Information Systems Security Officer

Arenatechnologies • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Specialist
Information Systems Security Specialist

Arenatechnologies • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement plans
Health savings accounts
+2
Security Controls Assessor
Security Controls Assessor

Systems Planning & Analysis • Washington

On-site
USD 160,000 - 180,000
Information Systems Security Engineer
Information Systems Security Engineer

Systems Planning & Analysis • Pearl City (HI)

On-site
USD 120,000 - 135,000
Health insurance
Retirement savings plans
Flexible spending accounts
+1