Information Systems Security Manager

ecsfederal

Virginia (MN)

On-site

USD 170,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Everforth ECS is seeking an Information Systems Security Manager to lead RMF for Navy information systems in a DoD/Navy environment. The candidate will manage the RMF lifecycle, develop SSPs/SARs/POA&Ms, and coordinate with Navy Authorizing Officials and security teams.

Requirements include an active Secret clearance (TS/SCI potential), 8+ years in cybersecurity with 3+ years as ISSM/ISSO, and hands-on eMASS experience.

Qualifications

  • Active Secret clearance with willingness to obtain TS/SCI.
  • 8+ years of cybersecurity experience, with 3+ years as an ISSM/ senior ISSO in a DoD/Navy environment.
  • Hands-on RMF experience under DoDI 8510.01 and proficiency with eMASS.
  • Experience with NIST SP 800-53 Rev. 5, RMF concepts, and Navy program interfaces.

Responsibilities

  • Serve as the ISSM for Navy information systems under RMF per DoDI 8510.01 and 8500.01.
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain RMF documentation: SSPs, SARs, POA&Ms, continuous monitoring strategies.
  • Interface directly with Navy stakeholders (AOs, SCAs, ISOs, PMs) and manage eMASS data accuracy.
  • Support audits, inspections, and cybersecurity readiness reviews (FISMA, DON CIO).
  • Provide cybersecurity guidance to engineering teams and align with DevSecOps practices.
  • Oversee incident response coordination per DoDI 8530.01.

Skills

RMF implementation
DoD/Navy cybersecurity
Leadership
Security risk assessment

Education

Bachelor’s degree in Cybersecurity or related field

Tools

eMASS
ACAS
HBSS
SCAP

Job description

Everforth ECS is seeking an Information Systems Security Manager to work in our Fairfax, VA office. Everforth ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF).

The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS.

The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM).

The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands‑on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well‑organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization.

Key Responsibilities:

  • Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
  • Develop, maintain, and manage RMF documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plan of Action & Milestones (POA&Ms)
    • Continuous Monitoring Strategies
  • Ensure compliance with:
    • NIST SP 800-53 Rev. 5 security controls
    • NIST SP 800-37 Rev. 2 (RMF Guide)
    • DoD Cybersecurity Manual (DoDM 5200.01)
    • SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)
  • Interface directly with Navy stakeholders including:
    • Authorizing Officials (AOs)
    • Security Control Assessors (SCAs)
    • Information System Owners (ISOs)
    • Program Managers (PMs)
  • Manage system accreditation activities within eMASS and ensure data accuracy and completeness
  • Conduct and support security control assessments, vulnerability management, and mitigation tracking
  • Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA
  • Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)
  • Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable
  • Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures

Salary Range: $170,000-190,000

  • Active Secret security clearance with willingness and ability to obtain TS/SCI
  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment
  • Strong experience implementing RMF under DoDI 8510.01 (latest version)
  • Hands‑on experience with eMASS
  • In-depth knowledge of:
    • NIST SP 800-53 Rev. 5 controls
    • NIST SP 800-37 Rev. 2
    • DoDI 8500.01 / 8510.01
  • SECNAV M-5239.1
  • Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)
  • Familiarity with:
    • DISA STIGs and SCAP compliance tools
    • ACAS (Assured Compliance Assessment Solution)
    • HBSS / Endpoint Security Solutions
  • Strong understanding of system architectures (on-prem, cloud, hybrid)
  • Strong understanding of AWS and Terraform
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Manager
Information Systems Security Manager

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information Systems Security Manager
Information Systems Security Manager

Everforth ECS • Merrifield (VA)

On-site
USD 140,000 - 190,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

RMantra Solutions • Fort Meade (MD), Northern (KY)

On-site
USD 130,000 - 170,000
Navy RMF ISSM — Lead DoD Cybersecurity & ATO
Navy RMF ISSM — Lead DoD Cybersecurity & ATO

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Navy RMF ISSM | Cybersecurity Risk & ATO Lead
Navy RMF ISSM | Cybersecurity Risk & ATO Lead

Everforth ECS • Merrifield (VA)

On-site
USD 140,000 - 190,000
Senior Principal Cyber Information Systems Security Engineer
Senior Principal Cyber Information Systems Security Engineer

Saic • Charleston (SC)

On-site
USD 150,000 - 210,000
Navy RMF ISSM | Cybersecurity Leader for DoD Systems
Navy RMF ISSM | Cybersecurity Leader for DoD Systems

ecsfederal • Virginia (MN)

On-site
USD 170,000 - 190,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ECS Corporate Services • Fort Meade (MD)

On-site
USD 150,000 - 170,000
Information System Security Officer
Information System Security Officer

ECS Corporate Services • Arlington (VA)

On-site
USD 120,000 - 165,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ecsfederal • Maryland

On-site
USD 150,000 - 170,000