Information System Security Manager (req-294)

CATHEXIS

Tysons (VA)

On-site

USD 150,000 - 195,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Performance Bonuses
Medical Insurance
Dental Insurance
Vision Insurance
401(k) Plan

Job summary

CATHEXIS is seeking an Information System Security Manager to serve as the principal advisor on security for assigned information systems. You will lead RMF A&A activities, develop and maintain security plans, and supervise ISSOs to ensure continuous monitoring and incident response readiness.

The role requires active DoD clearance, 3+ years in information security, and a bachelor’s degree in a related field. Competitive compensation and extensive benefits are offered.

Qualifications

  • Active Secret clearance or higher required.
  • Minimum 3 years of experience in information systems security or cybersecurity.
  • Experience as ISSM/ISSO or similar in RMF or C&A.
  • Strong written and verbal communication skills for leadership briefings.
  • Bachelor’s degree in Cybersecurity, IT, CS, or related field.

Responsibilities

  • Advise AO and program leadership on security of information systems.
  • Lead A&A process following RMF and NIST guidance to maintain ATOs.
  • Develop and maintain SSPs, POA&Ms, SARs, and RMF artifacts.
  • Oversee ISSOs and guide daily security operations and compliance.
  • Coordinate incident response and reporting per policy.
  • Ensure compliance with DoD 8570.01-M / 8140 and training requirements.
  • Maintain security documentation in GRC/eMASS and support audits.

Skills

Clearance knowledge
3+ years security experience
RMF/NIST proficient
Strong communication
Briefing leadership

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

eMASS
Xacta

Job description

Team CATHEXIS elevates the government contracting experience through rapid response, deep skill, and thoughtful problem-solving and communication. Our core capabilities are our top-tier program and project management, data analytics, and audit services, the backbone of which is our integrated approach to operational excellence.

You worked hard to get to where you are. You strive to make every day better than the day before. So do we. Team CATHEXIS operates with an all-in mindset. We are working together to create a company that supports our shared values and individual goals. Our values are centered around leading with integrity, owning the outcome, growing together, and moving with purpose in everything we do for our employees, customers, partners, and communities. We believe success is best when we listen and lead with empathy; model high standards of ethics to provide a rewarding candidate experience; work hard, have fun, and appreciate the strengths we all bring to the team; and empower our employees to create innovative and trusted results.

We are looking for a dynamic Information System Security Manager to join our team! The Information System Security Manager (ISSM) serves as the principal advisor to the Authorizing Official (AO) and program leadership on all matters, technical and otherwise, involving the security of assigned information systems. The ISSM is responsible for the development, implementation, and maintenance of the agency's information security program in accordance with the Risk Management Framework (RMF), NIST SP 800-series guidance, and applicable federal and agency-specific security policies. This role oversees a team of Information System Security Officers (ISSOs) and serves as the primary point of contact for security authorization, continuous monitoring, and incident response activities.

Responsibilities
  • Serve as the principal advisor to the Authorizing Official (AO) and Information System Owner on the security of assigned information systems
  • Lead and manage the Assessment and Authorization (A&A) process for information systems in accordance with the Risk Management Framework (RMF, NIST SP 800-37), ensuring timely issuance and maintenance of Authorizations to Operate (ATOs)
  • Develop, review, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and other required RMF artifacts
  • Oversee a team of Information System Security Officers (ISSOs), providing guidance on day-to-day security operations and compliance activities
  • Conduct and oversee continuous monitoring activities, including vulnerability scanning, configuration management, and security control assessments, to maintain the security posture of authorized systems
  • Ensure compliance with FISMA, NIST SP 800-53, NIST SP 800-171 (as applicable), CNSSI, and agency-specific cybersecurity policies and directives
  • Coordinate incident response activities and report security incidents to the appropriate agency SOC/CSIRC and leadership in accordance with established procedures
  • Manage risk assessments and communicate residual risk to the AO, providing recommendations for risk acceptance, mitigation, or remediation
  • Ensure personnel supporting assigned systems meet DoD 8570.01-M / DoD 8140 information assurance workforce certification and training requirements
  • Maintain security documentation in agency GRC/eMASS (or equivalent) systems and support periodic audits, Inspector General (IG) reviews, and independent assessments
  • Support the development of security policies, procedures, and standard operating procedures (SOPs) to strengthen the agency's overall security program
  • Active Secret clearance or higher
  • Minimum 3 years of experience in information systems security, information assurance, or cybersecurity, with direct experience supporting a federal agency
  • Demonstrated experience serving as an ISSM, ISSO, or equivalent security role within the Risk Management Framework (RMF) or legacy DIACAP/C&A process
  • Working knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-30, and FISMA reporting requirements
  • Active DoD Secret security clearance required at time of hire; ability to maintain clearance eligibility for the duration of the contrac
  • Current DoD 8570.01-M / DoD 8140 IAM Level II certification (e.g., CAP, CASP+ CE, CISM, GSLC) at time of hire
  • Strong written and verbal communication skills, with experience briefing technical risk and compliance matters to government leadership and Authorizing Officials
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience

Desired Skills

  • IAM Level III certification (e.g., CISSP, CISSP-ISSMP, CISM) or equivalent advanced credential
  • Experience using eMASS, Xacta, or other GRC platforms to manage A&A documentation
  • Experience supporting defense, healthcare, or civilian federal agency security programs
  • Familiarity with cloud security authorization processes (FedRAMP) and DevSecOps/continuous ATO practices

CATHEXIS offers competitive compensation packages to all eligible employees. Our goal is to provide a compensation package that reflects the value you bring to our team, is competitive with national average market rates, and promotes your financial security and personal well-being. The annual salary range for this role is $150,000.00 - $195,000.00 Please note that the salary information provided is a general guideline. CATHEXIS considers various factors in its final offer, including location, qualifications, experience, and skills.

  • Performance Bonuses
  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • 401(k) Plan (Traditional and ROTH)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off
  • 11 Federal Holidays
  • Parental Leave
  • Commuter Benefits
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Program
  • Community Outreach Initiatives

CATHEXIS is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated againston the basis ofdisability EEO IS THE LAW.If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact the Recruiting DepartmentRecruitingTeam@cathexisfederal.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer - TS/SCI (req-290)
Information System Security Officer - TS/SCI (req-290)

Cathexisfederal • Tysons (VA), Northern (KY)

Hybrid
USD 125,000 - 190,000
Performance Bonuses
Medical Insurance
Dental Insurance
+2
Information System Security Officer - TS/SCI (req-290)
Information System Security Officer - TS/SCI (req-290)

CATHEXIS • Tysons (VA)

On-site
USD 125,000 - 190,000
Performance Bonuses
Medical Insurance
Dental Insurance
+11
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Isys Technologies • Odenton (MD)

On-site
USD 120,000 - 180,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Isys Technologies • Corridor North (MD)

On-site
USD 110,000 - 170,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

LinTech Global, a Dexian company • Washington

On-site
USD 150,000 - 175,000
Open Paid Time Off
Health Insurance with Company Contribution
401k Plan with Company Match
+1
Senior Information Systems Security Officer
Senior Information Systems Security Officer

LinTech Global • Washington

On-site
USD 100,000 - 130,000
Information Systems Security Manager
Information Systems Security Manager

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information Systems Security Manager (ISSM) II
Information Systems Security Manager (ISSM) II

TAC Integrated Solutions • Lincoln (MA)

On-site
USD 110,000 - 160,000
Information System Security Manager
Information System Security Manager

Amentum • Northern (KY)

Hybrid
USD 100,000 - 110,000
Health insurance
Paid time off
401(k) matching
+6
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

TAC Integrated Solutions • Lincoln (MA)

On-site
USD 90,000 - 130,000