Information Systems Security Manager

Everforth ECS

Merrifield (VA)

On-site

USD 140,000 - 190,000

Full time

38 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Everforth ECS seeks an Information Systems Security Manager to lead RMF for Navy information systems in a Fairfax, VA environment. The ISSM will ensure compliance with DoD and DON cybersecurity policies and maintain system authorization packages in eMASS, serving as the cybersecurity authority for assigned systems.

The ideal candidate will have Navy/DoD RMF experience, hands-on eMASS, and the ability to guide a technical team while communicating risk to leadership.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, or related field or equivalent experience.
  • 8+ years of cybersecurity experience, with 3+ years as ISSM/ senior ISSO in a DoD/Navy environment.
  • Active Secret clearance with willingness to obtain TS/SCI.
  • Hands-on experience with RMF under DoDI 8510.01 and eMASS.

Responsibilities

  • Serve as the ISSM for Navy information systems in RMF framework.
  • Oversee full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, continuous monitoring.
  • Develop and maintain RMF documentation: SSPs, SARs, POA&Ms, Continuous Monitoring.
  • Interface with Navy stakeholders including AOs, SCAs, ISOs, PMs.
  • Manage system accreditation activities within eMASS and ensure data accuracy.

Skills

Cybersecurity leadership
RMF knowledge
DoD/Navy experience
Stakeholder communication

Education

Bachelor's degree in related field

Tools

eMASS
ACAS
HBSS
SCAP

Job description

Everforth ECS is seeking an Information Systems Security Manager to work in our Fairfax, VA office.
Everforth ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF).

The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS.

The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM).

The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands‑on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well‑organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization.

Key Responsibilities:

  • Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
  • Develop, maintain, and manage RMF documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plan of Action & Milestones (POA&Ms)
    • Continuous Monitoring Strategies
  • Ensure compliance with:
    • NIST SP 800-53 Rev. 5 security controls
    • NIST SP 800-37 Rev. 2 (RMF Guide)
    • DoD Cybersecurity Manual (DoDM 5200.01)
    • SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)
  • Interface directly with Navy stakeholders including:
    • Authorizing Officials (AOs)
    • Security Control Assessors (SCAs)
    • Information System Owners (ISOs)
    • Program Managers (PMs)
  • Manage system accreditation activities within eMASS and ensure data accuracy and completeness
  • Conduct and support security control assessments, vulnerability management, and mitigation tracking
  • Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA
  • Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)
  • Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable
  • Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures
  • Active Secret security clearance with willingness and ability to obtain TS/SCI
  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment
  • Strong experience implementing RMF under DoDI 8510.01 (latest version)
  • Hands‑on experience with eMASS
  • In-depth knowledge of:
    • NIST SP 800-53 Rev. 5 controls
    • NIST SP 800-37 Rev. 2
    • DoDI 8500.01 / 8510.01
  • SECNAV M-5239.1
  • Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)
  • Familiarity with:
    • DISA STIGs and SCAP compliance tools
    • ACAS (Assured Compliance Assessment Solution)
    • HBSS / Endpoint Security Solutions
  • Strong understanding of system architectures (on‑prem, cloud, hybrid)
Desired Skills
  • Active TS/SCI security clearance.
  • Experience with Navy Authorizing Officials (AOs) and Navy‑specific RMF processes
  • Familiarity with Platform IT (PIT) and Weapons Systems cybersecurity
  • Experience with DevSecOps pipelines and containerized environments
  • Knowledge of Zero Trust Architecture (DoD Zero Trust Strategy, 2022+)
  • Experience supporting systems in AWS GovCloud, Azure Government, or Navy cloud environments

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission‑critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:

  • Attracting and developing top talent and high‑performing teams
  • Fostering a culture that is engaging, accountable, and mission‑driven

Meet the challenge. Make a difference with Everforth ECS!

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission‑critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Manager
Information Systems Security Manager

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Cyber Systems Analyst/Security Specialist
Cyber Systems Analyst/Security Specialist

Everforth ECS • Washington

On-site
USD 120,000 - 180,000
Authorizing Official Designated Representative (AODR) Support Analyst
Authorizing Official Designated Representative (AODR) Support Analyst

ECS • Washington

Hybrid
USD 170,000 - 190,000
Cyber Systems Analyst/Security Specialist
Cyber Systems Analyst/Security Specialist

ECS • Washington

On-site
USD 130,000 - 160,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Everforth ECS • Quantico (VA)

On-site
USD 100,000 - 124,000
Sr. Cyber Operations SME/PM/Engineer
Sr. Cyber Operations SME/PM/Engineer

Everforth ECS • Washington

On-site
USD 120,000 - 150,000
Technical Support Lead
Technical Support Lead

Everforth ECS • Washington

On-site
USD 140,000 - 190,000
Information System Security Manager (req-294)
Information System Security Manager (req-294)

CATHEXIS • Tysons (VA)

On-site
USD 150,000 - 195,000
Performance Bonuses
Medical Insurance
Dental Insurance
+2