Information System Security Manager (ISSM)

LMI Consulting, LLC

Washington (District of Columbia)

On-site

USD 110,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

LMI seeks an Information System Security Manager (ISSM) in the Washington, DC area to lead security authorization, governance, and continuous monitoring for enterprise IT capabilities across secure facilities.

You will coordinate with system owners, engineers, security officers, and government stakeholders to ensure systems are authorized, documented, and operated per security requirements. Travel is 25–50% with immediate availability preferred.

Qualifications

  • Bachelor’s degree in cybersecurity, computer science, information technology, engineering, or related field.
  • 8+ years in cybersecurity, information assurance, security authorization, or RMF experience.
  • Experience leading security authorization for complex enterprise, interconnected, or multi-enclave systems.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and federal security requirements.

Responsibilities

  • Lead RMF implementation across the system lifecycle, including categorization, control selection, tailoring, implementation, assessment, authorization, and monitoring.
  • Develop security authorization strategies and roadmaps for classified and unclassified systems and multi-enclave environments.
  • Coordinate system security plans, evidence, POAs/Ms, assessments, authorization decisions, and monitoring artifacts.
  • Interpret and apply NIST SP 800-37, SP 800-53, CNSSI 1253, and related guidance.
  • Advise leadership on cyber risk, control gaps, remediation priorities, and risk acceptance.
  • Integrate security requirements into architecture, engineering, acquisition, change management, testing, deployment, and operations.
  • Oversee vulnerability, configuration, and compliance monitoring and prioritize remediation by impact.
  • Coordinate assessors, officials, security officers, engineers, and stakeholders through reviews, audits, incidents, and milestones.
  • Automate evidence collection, control validation, reporting, and POA tracking while maintaining auditability.

Skills

RMF
NIST SP 800-37
NIST SP 800-53
CNSSI 1253
Security governance
Communication
Zero-trust

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field

Job description

Information System Security Manager (ISSM)
Job Locations

US-DC-Washington, DC

Overview

LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.

Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, homeland, healthcare, and intelligence sectors-helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.

Responsibilities

LMI is seeking a skilled Information System Security Manager (ISSM) to assist the Lead Cybersecurity Integrator to lead security authorization, governance, and continuous monitoring for enterprise IT capabilities across new and existing secure facilities. The ISSM will coordinate with system owners, engineers, security officers, cybersecurity personnel, and government stakeholders to ensure systems are designed, documented, authorized, operated, and sustained in accordance with security requirements. This is an execution-oriented role supporting a fast-paced, milestone-driven prototype effort with near-term deliverable commitments. Success requires risk-based judgment, rigorous Risk Management Framework execution, clear communication, and the ability to balance mission, security, operational risk, and delivery timelines.

Primary duties include:

  • Lead Risk Management Framework implementation across the system lifecycle, including categorization, control selection and tailoring, implementation, assessment, authorization, and continuous monitoring.
  • Develop security authorization strategies and roadmaps for classified and unclassified systems, multi-enclave environments, and interconnected capabilities.
  • Coordinate system security plans, implementation evidence, plans of action and milestones, assessment packages, authorization decisions, and monitoring artifacts.
  • Interpret and apply NIST SP 800-37, NIST SP 800-53, CNSSI 1253, defense and intelligence guidance, customer policies, and program requirements.
  • Advise the Lead Cybersecurity Integrator, system owners, the Chief Engineer, program leadership, and technical teams on cyber risk, control gaps, remediation priorities, and risk acceptance.
  • Integrate security requirements into architecture, engineering, acquisition, change management, testing, deployment, operations, and sustainment.
  • Oversee vulnerability, configuration, and compliance monitoring; prioritize remediation based on exploitability, mission impact, exposure, and operational consequence.
  • Coordinate assessors, authorizing officials, security officers, engineers, operators, and stakeholders through reviews, audits, incidents, and authorization milestones.
  • Automate evidence collection, control validation, reporting, plan-of-action tracking, and monitoring while preserving auditability and human oversight.
Foundational Skills
  • Risk Management Framework and security authorization lifecycle principles.
  • NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and federal, defense, and intelligence security-control frameworks.
  • System security plans, control traceability, evidence, assessments, plans of action and milestones, and authorization packages.
  • Risk assessment, security-control tailoring, compensating controls, residual risk, and risk acceptance.
  • Continuous monitoring, vulnerability management, secure configuration, patching, and compliance assessment.
  • Systems, networking, cloud, identity, application, data, and operational-security fundamentals.
  • Zero-trust, least-privilege, defense-in-depth, segmentation, and secure-boundary principles.
  • Configuration, change, incident, problem, and technology-lifecycle management.
  • Security automation, metrics, technical writing, briefings, and stakeholder coordination.

Location: This position is based in the Washington, DC metro area, with travel to program locations.

Travel: This position requires approximately 25-50% travel to support activities across multiple program locations.

Availability: Immediate availability strongly preferred; unclassified planning work may begin while program access nominations are processed.

Qualifications

Required:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 8+ years of cybersecurity, information assurance, security authorization, or Risk Management Framework experience, including in classified environments.
  • Experience leading security authorization for complex enterprise, interconnected, or multi-enclave systems.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and federal, defense, or intelligence security requirements.
  • Experience developing or reviewing system security plans, control evidence, assessments, plans of action and milestones, authorization packages, and monitoring deliverables.
  • Experience supporting SCIF or other accredited classified environments and advising system owners and program leaders on cybersecurity risk.
  • Ability to coordinate technical and nontechnical stakeholders and communicate security status, risk, remediation priorities, and authorization decisions.

Nice to Have:

  • Relevant advanced cybersecurity, information-assurance, or risk-management certification.
  • Experience authorizing or integrating cross-domain solutions (CDS) and controlled interfaces.
  • Experience supporting Special Access Program (SAP) facilities, systems, or environments.
  • Experience supporting network or security operations centers (NOC/SOC), continuous monitoring, and 24x7 incident-response environments.
  • Experience with security automation, governance-risk-and-compliance workflows, or continuous control validation.

Target salary range: $110,000.00 - $180,000.00. Final compensation will be determined by a variety of factors including but not limited to your skills, experience, education, and/or certifications.

TS/SCI clearance with SAP eligibility is required for this position.TS/SCI clearance with SAP eligibility is required for this position. Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. LMI will only consider applicants with current security clearances. Please note that only U.S. citizens are eligible for a security clearance.

Job Locations

US-DC-Washington, DC

LMI is an Equal Opportunity Employer. LMI is committed to the fair treatment of all and to our policy of providing applicants and employees with equal employment opportunities. LMI recruits, hires, trains, and promotes people without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, pregnancy, disability, age, protected veteran status, citizenship status, genetic information, or any other characteristic protected by applicable federal, state, or local law. If you are a person with a disability needing assistance with the application process, please contact accommodations@lmi.org Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

LMI Government Consulting • Northern (KY)

On-site
USD 110,000 - 180,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

LMI Government Consulting • Washington

On-site
USD 110,000 - 180,000
Systems Engineer
Systems Engineer

LMI Consulting, LLC • Washington

On-site
USD 125,000 - 250,000
Senior Cyber ISSE: RMF/ATO & Cloud Security (Secret)
Senior Cyber ISSE: RMF/ATO & Cloud Security (Secret)

LMI Consulting, LLC • Fort Belvoir (VA)

On-site
USD 92,075 - 158,138
Lead Cybersecurity Integrator - w/active Top Secret clearance
Lead Cybersecurity Integrator - w/active Top Secret clearance

LMI Government Consulting • Washington

On-site
USD 125,000 - 190,000
Cybersecurity Information System Security Engineer - Clearance Required
Cybersecurity Information System Security Engineer - Clearance Required

LMI Consulting, LLC • Fort Belvoir (VA)

On-site
USD 92,075 - 158,138
Lead Cybersecurity Integrator - w/active Top Secret clearance
Lead Cybersecurity Integrator - w/active Top Secret clearance

LMI • Washington

Hybrid
USD 125,000 - 190,000
Travel 25-50%
TS/SCI clearance required
US citizenship required
Systems Engineer
Systems Engineer

LMI Government Consulting • Northern (KY)

Hybrid
USD 125,000 - 250,000
Systems Engineer
Systems Engineer

LMI Government Consulting • Washington

On-site
USD 125,000 - 250,000
Current Operations Lead w/active Clearance
Current Operations Lead w/active Clearance

LMI Consulting, LLC • Tysons (VA)

On-site
USD 90,000 - 120,000