Information Systems Security Manager

CGC

McLean, Northern (VA, KY)

Hybrid

USD 120.000 - 180.000

Vollzeit

vor 42 Stunden
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Merlin Group in McLean, VA seeks an Information Systems Security Manager to own day-to-day security compliance, FedRAMP authorization maintenance, and program management of security controls. You will coordinate access authorization, vulnerability scanning, POA&M, and change control while translating requirements for engineering and SOC teams.

The role emphasizes clear communication with customers and leadership, proactive risk reporting, and adherence to compliance calendars.

Qualifikationen

  • 5+ years as an ISSM in FedRAMP environments with CSPs.
  • Hands-on FedRAMP Rev 5, 20x, and CR26 experience, translating controls for engineering/SOC teams.
  • Hands-on vulnerability management, POA&M, and change control in regulated settings.
  • Strong organization for a large recurring compliance calendar with deadlines.
  • Judgment to raise risks early, not after issues become critical.
  • Ability to communicate clearly with technical, customer, and leadership audiences.

Aufgaben

  • Coordinate access authorization and maintain tracked reviews.
  • Manage POA&M status, owners, and remediation plans with teams.
  • Perform vulnerability scanning analysis and reporting for stakeholders.
  • Oversee Change Control Board and Security Impact Assessments for changes.
  • Coordinate major changes through review/approval processes.
  • Track recurring compliance calendar (IRCP, contingency tests, ROB).
  • Coordinate SBOM submissions and LMS for security training.
  • Monitor FedRAMP program changes and assess impact.

Kenntnisse

ISSM FedRAMP experience
FedRAMP Rev 5/20x/CR26
Vulnerability management
POA&M processes
Change control
CSP collaboration
Stakeholder communication

Jobbeschreibung

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Information Systems Security Manager

Full Time Merlin International Inc - HQ, McLean, VA, US

8 days ago Requisition ID: 1092

About Merlin Group

Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions.

At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact.

The Opportunity

We are looking for an Information System Security Manager (ISSM) to own the day-to-day security compliance and continuous monitoring activity that keeps our FedRAMP authorization current. You will coordinate access authorization, vulnerability scanning, POA&M management, change control, and the recurring compliance calendar, while tracking changes to the FedRAMP program itself. The role is as much about people as process: you will explain security and compliance requirements to customers, including ones who are frustrated or under pressure, and raise risks to leadership early, clearly, and in writing .

Primary Duties & Responsibilities

  • Coordinate access authorization for the environment, keeping requests, approvals, and quarterly access reviews tracked and current
  • Maintain the Plan of Action and Milestones (POA&M) with current status, owners, and due dates, and coordinate remediation plans with the teams closing findings
  • Perform vulnerability scanning, analyze results, and produce reporting for stakeholders and leadership
  • Manage the Change Control Board (CCB) as concierge for change requests, and populate Security Impact Assessments (SIAs) for proposed changes
  • Coordinate significant change requests through the required review and approval process
  • Track the recurring compliance calendar, including the Incident Response and Contingency Plan (IRCP), contingency plan testing, quarterly access reviews, and Rules of Behavior (ROB) management
  • Coordinate Software Bill of Materials (SBOM) submissions with the teams that own them and keep reviews on schedule
  • Manage the Learning Management System (LMS) for security awareness training, tracking completion and following up on gaps
  • Monitor changes to the FedRAMP program, including Rev 5, 20x, CR26, and other RFCs, and assess their impact on the environment
  • Explain security and compliance requirements clearly to customers and stakeholders, including in difficult or high-pressure conversations
  • Report risks to leadership early, before they become critical, with enough detail to support a decision
  • Apply project management discipline throughout: sequencing work, tracking status, and keeping owners and deadlines visible

Qualifications

  • 5+ years as an ISSM working directly with Cloud Service Providers (CSPs) in FedRAMP authorized environments
  • Direct, hands‑on experience with FedRAMP Rev 5, 20x, and CR26 requirements, and the ability to translate controls into actionable items for engineering and SOC teams
  • Hands‑on knowledge of vulnerability management, POA&M processes, and change control in a regulated environment
  • Strong organizational discipline across a large recurring compliance calendar, with deadlines held rather than dropped
  • Sound judgment on when to raise risks, escalating early instead of after issues become critical
  • Ability to work across technical, customer, and leadership audiences, including calm, plain‑language communication with frustrated customers

Preferred Qualifications

  • Experience taking CSPs through the FedRAMP Authorization to Operate (ATO) process
  • Project management experience or certification (PMP, CSM, or equivalent) CISSP certification

Success Attributes

  • Commitment to personal and professional integrity and respect for others.
  • Roll‑up-your-sleeves attitude and low‑ego approach.
  • Commitment to teamwork and professional relationship development.
  • Passion for lifelong learning, growth, and development.
  • Flexible and nimble; comfortable with ambiguity and rapid change.
  • Strong communication and functional project management skills.
  • Desire to innovate, try new things, and creatively explore novel solutions to business challenges.
  • Professional and respectful approach to the diversity of thought, action, identity, and attributes.

We want to empower and inspire employees to be and do their best. Our workdays are dynamic, collegial, and fun. Our office features multiple places to work unconstrained by typical office barriers. Our wellness package provides access to an on‑site gym and includes medical, dental, and vision insurance along with options for FSA and EAP. We offer 401(k) with employer match, unlimited PTO, and a culture respectful of the reality that not everything in one’s personal life is guaranteed to happen only after hours.

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Systems Security Manager
Information Systems Security Manager

Merlin International Inc • McLean (VA)

Vor Ort
USD 140.000 - 190.000
On-site gym
Medical, dental, and vision insurance
401(k) with employer match
+1
Information Systems Security Manager
Information Systems Security Manager

Constellation GovCloud • McLean (VA)

Vor Ort
USD 140.000 - 190.000
On-site gym
401(k) with employer match
Unlimited PTO
+1
SOC Engineer
SOC Engineer

Merlin International Inc • McLean (VA)

Vor Ort
USD 110.000 - 140.000
Solutions Product Manager
Solutions Product Manager

CGC • McLean (VA)

Hybrid
USD 120.000 - 150.000
Solutions Product Manager
Solutions Product Manager

Merlin International Inc • McLean (VA)

Hybrid
USD 120.000 - 180.000
On-site gym access
Medical, dental, and vision insurance
FSA
+3
Solutions Product Manager
Solutions Product Manager

Merlin Group • McLean (VA)

Hybrid
USD 120.000 - 190.000
FedRAMP ISSM & Security Compliance Lead
FedRAMP ISSM & Security Compliance Lead

Merlin International Inc • McLean (VA)

Vor Ort
USD 140.000 - 190.000
On-site gym
Medical, dental, and vision insurance
401(k) with employer match
+1
FedRAMP Security & Compliance Lead
FedRAMP Security & Compliance Lead

CGC • McLean (VA), Northern (KY)

Hybrid
USD 120.000 - 180.000
SOC Engineer
SOC Engineer

Constellation GovCloud • McLean (VA)

Vor Ort
USD 120.000 - 170.000
On-site gym
Medical, dental, and vision insurance
FSA and EAP
+2
SOC Engineer
SOC Engineer

CGC • McLean (VA), Northern (KY)

Hybrid
USD 120.000 - 160.000
On-site gym and health insurance
401(k) with employer match
Unlimited PTO