Information Systems Security Manager

ECS

Fairfax (VA)

On-site

USD 170,000 - 190,000

Full time

14 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Everforth ECS seeks an Information Systems Security Manager to support U.S. Navy systems from our Fairfax, VA office. The ISSM will lead RMF activities, manage eMASS accreditation, and advise on cybersecurity risk across the SDLC.

The ideal candidate will have 8+ years in cybersecurity with 3+ years as an ISSM/ senior ISSO in a DoD/Navy environment, strong RMF, NIST, and eMASS expertise. Salary range reflected for this critical national security role.

Qualifications

  • Active Secret security clearance required; TS/SCI desired.
  • Bachelor’s degree in Cybersecurity, IT, or related field.

Responsibilities

  • Serve as the ISSM for Navy information systems per RMF DoDI 8510.01/8500.01.
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop and manage RMF documentation: SSPs, SARs, POA&Ms, Continuous Monitoring Strategies.
  • Ensure compliance with NIST SP 800-53 Rev. 5, SP 800-37 Rev. 2, DoD/DON cybersecurity manuals.
  • Interface with Navy stakeholders including AOs, SCAs, ISOs, PMs.
  • Manage system accreditation activities within eMASS; ensure data accuracy.
  • Conduct security control assessments, vulnerability management, and mitigation tracking.
  • Ensure compliance with DISA STIGs and SRGs; support audits and inspections.
  • Provide cybersecurity guidance to engineering teams across SDLC; support DevSecOps.
  • Oversee incident response coordination per DoDI 8530.01.

Skills

Secret clearance
RMF knowledge
eMASS experience
NIST SP 800-53 Rev.5
NIST SP 800-37 Rev. 2
DoD/Navy RMF experience
RMF lifecycle management
ACAS

Education

Bachelor’s degree in Cybersecurity or related field

Tools

eMASS
ACAS
HBSS

Job description

Job Description

Everforth ECS is seeking an Information Systems Security Manager to work in our Fairfax, VA office.

Job Description

Everforth ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF).

The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS.

The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM).

The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands‑on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well‑organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization.

Key Responsibilities
  • Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
  • Develop, maintain, and manage RMF documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plan of Action & Milestones (POA&Ms)
    • Continuous Monitoring Strategies
  • Ensure compliance with:
    • NIST SP 800-53 Rev. 5 security controls
    • NIST SP 800-37 Rev. 2 (RMF Guide)
    • DoD Cybersecurity Manual (DoDM 5200.01)
    • SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)
  • Interface directly with Navy stakeholders including:
    • Authorizing Officials (AOs)
    • Security Control Assessors (SCAs)
    • Information System Owners (ISOs)
    • Program Managers (PMs)
  • Manage system accreditation activities within eMASS and ensure data accuracy and completeness
  • Conduct and support security control assessments, vulnerability management, and mitigation tracking
  • Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA
  • Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)
  • Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable
  • Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures

Salary Range: $170,000-190,000

General Description Of Benefits
Required Skills
  • Active Secret security clearance with willingness and ability to obtain TS/SCI
  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment
  • Strong experience implementing RMF under DoDI 8510.01 (latest version)
  • Hands‑on experience with eMASS
  • In‑depth knowledge of:
    • NIST SP 800-53 Rev. 5 controls
    • NIST SP 800-37 Rev. 2
    • DoDI 8500.01 / 8510.01
  • SECNAV M-5239.1
  • Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)
  • Familiarity with:
    • DISA STIGs and SCAP compliance tools
    • ACAS (Assured Compliance Assessment Solution)
    • HBSS / Endpoint Security Solutions
  • Strong understanding of system architectures (on-prem, cloud, hybrid)
Desired Skills
  • Active TS/SCI security clearance.
  • Experience with Navy Authorizing Officials (AOs) and Navy-specific RMF processes
  • Familiarity with Platform IT (PIT) and Weapons Systems cybersecurity
  • Experience with DevSecOps pipelines and containerized environments
  • Knowledge of Zero Trust Architecture (DoD Zero Trust Strategy, 2022+)
  • Experience supporting systems in AWS GovCloud, Azure Government, or Navy cloud environments

#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission‑critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value
  • Attracting and developing top talent and high‑performing teams
  • Fostering a culture that is engaging, accountable, and mission‑driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000
Authorizing Official Designated Representative (AODR) Support Analyst
Authorizing Official Designated Representative (AODR) Support Analyst

ECS • Washington

Hybrid
USD 170,000 - 190,000
Information System Security Manager
Information System Security Manager

Amentum • Northern (KY)

Hybrid
USD 100,000 - 110,000
Health insurance
Paid time off
401(k) matching
+6
Information Systems Security Manager
Information Systems Security Manager

Persistent Systems • Fort Collins (CO)

On-site
USD 134,000 - 163,000
Comprehensive benefits package
Yearly discretionary bonus
Tuition assistance
+1
Information Systems Security Manager
Information Systems Security Manager

Persistent Systems, LLC • Fort Collins (CO)

On-site
USD 134,000 - 163,000
Medical insurance
Dental insurance
Vision insurance
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Dark Wolf • Chantilly (VA)

Hybrid
USD 140,000 - 160,000
Advisory Information Security Manager (ISSM)
Advisory Information Security Manager (ISSM)

FTI Defense - Frontier Technology Inc. • Huntsville (AL)

On-site
USD 120,000 - 180,000
Information Systems Security Officer(ISSO), Mid (MCSES III)
Information Systems Security Officer(ISSO), Mid (MCSES III)

AMERICAN SYSTEMS • McLean (VA)

On-site
USD 140,000 - 160,000
Healthcare benefits
Paid leave
Retirement plans
+1
Cyber Assessment & Authorization / Technical Writer
Cyber Assessment & Authorization / Technical Writer

ECS • Falls Church (VA)

On-site
USD 130,000 - 150,000