Information System Security Manager (ISSM)

Arenatechnologies

Lincoln (MA)

On-site

USD 180,000 - 215,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Systems Planning and Analysis, Inc. (SPA) seeks an Information System Security Manager (ISSM) to lead cybersecurity across our contracts. You will own RMF execution, accreditation packages, and liaison with government security officials to maintain compliance and policy.

This role anchors secure coding, vulnerability management, and security training within the Mission Planning Enterprise. The ideal candidate brings 8+ years in cybersecurity with DoD RMF experience and active Secret clearance,

Qualifications

  • Required: BS in cybersecurity, CS, info assurance or similar with 8+ years in medium-to-large IT or software programs.
  • Minimum 4 years in an ISSM or equivalent leadership role.
  • Experience implementing DoD RMF and maintaining accreditation packages and FISMA records.
  • Experience leading DISA STIG compliance, vulnerability scanning and testing in NIPR/SIPR environments.
  • DoD-approved cybersecurity certification such as CISSP, CAP, or CISM; active DoD Secret clearance.

Responsibilities

  • Own RMF execution, accreditation package development, and coordination with government security stakeholders.
  • Define and enforce cybersecurity and cyber-resiliency practices across development and test activities.
  • Embed security controls into architectures, pipelines, and test environments to ensure secure Mission Planning Enterprise.

Skills

RMF execution
DIACAP experience
DISA STIG
Vulnerability testing
NIPR/SIPR
Security clearance

Education

CISSP
CAP
CISM

Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

The Sea, Land, Air Analysis Group’s mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, USAF, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.

SPA has a need for an Information System Security Manager (ISSM), who will serve as the overall cybersecurity lead for the systems and environments delivered under this contract. This individual will own RMF execution, accreditation package development, and coordination with government security stakeholders. The ISSM will be responsible for defining and enforcing cybersecurity and cyber-resiliency practices that are integrated into development, integration, and test activities across the Mission Planning Enterprise.

Responsibilities

The ISSM is responsible for the overall cybersecurity posture, compliance, and accreditation of systems delivered under this contract. They lead Risk Management Framework (RMF) activities, maintain security documentation and artifacts, and coordinate with government security officials on security testing, ATO/ATC actions, and policy compliance. The ISSM defines and enforces cybersecurity and cyber-resiliency practices across the development and integration lifecycle, including secure coding standards, vulnerability management, and security training. They work closely with engineering, test, and platform operations to embed security controls into architectures, pipelines, and test environments, ensuring that cybersecurity is a first-class aspect of the Mission Planning Enterprise.

Qualifications

Required Qualifications:

  • BS in cybersecurity, computer science, information assurance, or similar field plus 8+ years of cybersecurity experience on medium-to-large IT or software programs, including at least 4 years in an ISSM or equivalent leadership role
  • Direct experience implementing DoD RMF (and prior DIACAP) processes, including authoring and maintaining accreditation packages and FISMA-related records
  • Demonstrated experience leading or supporting DISA STIG compliance, vulnerability scanning, penetration testing, and testing in NIPR/SIPR and related environments
  • Familiarity with mission planning or similar weapon‑system security contexts, including support for ATO and ATC activities and security targets
  • DoD‑approved cybersecurity certification such as CISSP, CAP, or CISM
  • Active DoD Secret clearance (or higher) and the ability to maintain it throughout employment

Desired Qualifications:

  • Master’s degree in relevant field plus experience developing and maintaining enterprise cybersecurity master plans, Program Protection Plans, anti‑tamper plans, and related security documentation
  • Familiarity with Air Force cybersecurity policy and coordination with AF network and accreditation authorities
  • Background in cyber resiliency for mission or weapon systems, including secure coding standards, security‑focused scenarios, and user certification requirements
  • Experience integrating security controls into DevSecOps pipelines and CDE environments, including automated compliance and security testing
  • Prior experience addressing security considerations for FMS deliveries and multi‑national information‑sharing constraints
Pay Range Information

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Massachusetts, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $215,000.00/Yr.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Systems Planning & Analysis • Lincoln (MA)

On-site
USD 180,000 - 215,000
Health insurance
Retirement plans
Paid time off
Information Systems Security Manager
Information Systems Security Manager

Systems Planning and Analysis, Inc. • Arlington (VA)

On-site
USD 130,000 - 170,000
Information Systems Security Manager
Information Systems Security Manager

Arenatechnologies • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Retirement plan
Paid time off
Information Systems Security Manager
Information Systems Security Manager

Systems Planning & Analysis • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Flexible spending accounts
Health savings accounts
+3
Information Systems Security Manager
Information Systems Security Manager

Arenatechnologies • San Diego (CA)

On-site
USD 125,000 - 175,000
Health insurance
Retirement savings plans
Flexible spending accounts
Information Systems Security Engineer
Information Systems Security Engineer

Systems Planning & Analysis • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Officer
Information Systems Security Officer

Arenatechnologies • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Specialist
Information Systems Security Specialist

Arenatechnologies • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement plans
Health savings accounts
+2
Security Controls Assessor
Security Controls Assessor

Systems Planning & Analysis • Washington

On-site
USD 160,000 - 180,000
Information Systems Security Engineer
Information Systems Security Engineer

Systems Planning & Analysis • Pearl City (HI)

On-site
USD 120,000 - 135,000
Health insurance
Retirement savings plans
Flexible spending accounts
+1