Information Systems Security Manager

ECS Corporate Services

Fairfax (VA)

On-site

USD 170,000 - 190,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ECS Corporate Services seeks an experienced ISSM to oversee RMF for Navy information systems, aligning with DoDI 8510.01 and related security standards. You will manage the RMF lifecycle and interface with AOs, SCAs, ISOs, and PMs.

Requirements include 8+ years in cybersecurity with 3+ years in ISSM/ISSO roles, a Bachelor's degree, hands-on RMF and eMASS experience, and knowledge of NIST SP 800-53 Rev.5, Rev.2, and DISA STIGs. Salary range: $170k–$190k.

Qualifications

  • 8+ years in cybersecurity with 3+ years as ISSM or senior ISSO in DoD/Navy.
  • Bachelor's degree in Cybersecurity, IT, or related field.
  • Hands-on RMF implementation experience under DoDI 8510.01.
  • Proficient with eMASS and RMF documentation (SSPs, SARs, POA&Ms).
  • Experience with NIST 800-53 Rev.5, 800-37 Rev.2, and DISA STIGs.

Responsibilities

  • Serve as ISSM for Navy information systems per RMF.
  • Oversee full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain RMF documentation (SSPs, SARs, POA&Ms, monitoring strategies).
  • Interface with Navy stakeholders (AOs, SCAs, ISOs, PMs).
  • Manage accreditation activities in eMASS and ensure data accuracy.
  • Support security control assessments, vulnerability management, and remediation tracking.

Skills

RMF Lifecycle
DoDI 8510.01
NIST SP 800-53 Rev5
NIST SP 800-37 Rev2
RMF Documentation
DevSecOps
AWS
Terraform
eMASS

Education

Bachelor's degree in Cybersecurity/IT

Tools

ACAS
HBSS
SCAP
STIGs
SCAP tools

Job description

Key Responsibilities
  • Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
  • Develop, maintain, and manage RMF documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plan of Action & Milestones (POA&Ms)
    • Continuous Monitoring Strategies
  • Ensure compliance with:
    • NIST SP 800-53 Rev. 5 security controls
    • NIST SP 800-37 Rev. 2 (RMF Guide)
    • DoD Cybersecurity Manual (DoDM 5200.01)
    • SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)
  • Interface directly with Navy stakeholders including:
    • Authorizing Officials (AOs)
    • Security Control Assessors (SCAs)
    • Information System Owners (ISOs)
    • Program Managers (PMs)
  • Manage system accreditation activities within eMASS and ensure data accuracy and completeness
  • Conduct and support security control assessments, vulnerability management, and mitigation tracking
  • Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA
  • Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)
  • Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable
  • Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures
Salary Range

$170,000-190,000

General Description of Benefits
  • Active Secret security clearance with willingness and ability to obtain TS/SCI
  • Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment
  • Strong experience implementing RMF under DoDI 8510.01 (latest version)
  • Hands-on experience with eMASS
  • In-depth knowledge of:
    • NIST SP 800-53 Rev. 5 controls
    • NIST SP 800-37 Rev. 2
    • DoDI 8500.01 / 8510.01
    • SECNAV M-5239.1
  • Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)
  • Familiarity with:
    • DISA STIGs and SCAP compliance tools
    • ACAS (Assured Compliance Assessment Solution)
    • HBSS / Endpoint Security Solutions
  • Strong understanding of system architectures (on-prem, cloud, hybrid)
  • Strong understanding of AWS and Terraform
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

JFL Consulting LLC • Springfield (VA)

On-site
USD 155,000 - 175,000
Salary 155k-175k
Medical/dental/vision premiums
FSA accounts
+4
Navy RMF Information Security Manager
Navy RMF Information Security Manager

ECS Corporate Services • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information System Security Manager III
Information System Security Manager III

International Executive Service Corps • San Diego (CA)

On-site
USD 150,000 - 210,000
Navy RMF ISSM — Lead DoD Cybersecurity & ATO
Navy RMF ISSM — Lead DoD Cybersecurity & ATO

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information Systems Security Manager
Information Systems Security Manager

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information System Security Manager (ISSM) - Contingent Upon Contract Award
Information System Security Manager (ISSM) - Contingent Upon Contract Award

Jmares • Philadelphia

On-site
USD 120,000 - 180,000
Senior Information System Security Manager
Senior Information System Security Manager

Cornerstone Defense LLC • Odenton (MD)

On-site
USD 145,000 - 165,000
Medical plan
Dental plan
Vision plan
+15
Information Systems Security Manager - Basic (ISSM-Basic)
Information Systems Security Manager - Basic (ISSM-Basic)

ACQCENTRIC INC • Huntsville (AL)

On-site
USD 90,000 - 140,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

RMantra Solutions • Fort Meade (MD), Northern (KY)

On-site
USD 130,000 - 170,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

LMI • Mechanicsburg

On-site
USD 115,000 - 175,000