Senior Information System Security Manager

Cornerstone Defense LLC

Odenton (MD)

On-site

USD 145,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical plan
Dental plan
Vision plan
401(k)
HSA options
FSA options
Life insurance
Disability insurance
Tuition reimbursement
Training programs
Perks at work
Referral program
Leads generation
529 plan
Fitness reimbursement
Travel assistance
Lifelock benefit
Financial & legal services

Job summary

Cornerstone Defense LLC is seeking a Senior Information System Security Manager to oversee the cybersecurity posture for DoD systems in Odenton, MD. You will own the RMF lifecycle, ensure ATO readiness, and develop robust security documentation in alignment with DoD standards.

The role requires active DoD Secret clearance, substantial RMF experience, and the ability to coordinate across engineering and program teams to maintain secure, compliant environments.

Qualifications

  • Bachelor’s degree with 8+ years of experience or Master’s degree with 6+ years (additional experience may substitute for education).
  • CISSP, CISM, or equivalent senior‑level cybersecurity certification.
  • Detailed knowledge of DoD cybersecurity policies, frameworks, and standards such as NIST 800‑53, RMF, FISMA, ICD 503, and JSIG.
  • Extensive experience maintaining ATOs for DoD enterprise systems.
  • Experience with system security engineering, risk management, and vulnerability assessment methodology.
  • Strong understanding of network security principles and common cyber tools (firewalls, IDS/IPS, SIEM, endpoint protection).
  • Ability to operate independently and collaboratively across cross‑functional teams.
  • Excellent communication skills with experience preparing and presenting detailed cybersecurity reports.

Responsibilities

  • Manage the full RMF lifecycle to achieve and maintain system Authority to Operate (ATO).
  • Provide ISSM support across FISMA, certification, and accreditation requirements.
  • Conduct recurring assessments of security controls and documentation within eMASS and PPSM to maintain accuracy, compliance, and audit readiness.
  • Manage whitelist records and address vulnerabilities identified through IAVMS scans; develop and track POA&Ms.
  • Maintain eMASS control records and POA&Ms in alignment with ATO conditions, approval requirements, and remediation timelines.
  • Coordinate cybersecurity activities for interim and final authorization to test and operate—ensuring assessments, mitigation planning, patch validation, and reporting are executed effectively.
  • Develop and deliver cybersecurity documentation including test plans, test reports, implementation plans, STIG/configuration artifacts, vulnerability assessment reports, and full authorization package materials.
  • Lead cybersecurity governance activities—managing system architectures, security requirements, protection plans, IAVA actions, and IA compliance objectives.
  • Prepare documentation, evidence, and briefings for DISA OAB reviews and support the team throughout the review and adjudication process.

Skills

CISSP
CISM
NIST 800-53
RMF
FISMA
JSIG
Strong communication
Independent work
Cross-functional collaboration

Education

Bachelor’s degree with 8+ years of experience
Master’s degree with 6+ years of experience

Tools

Firewalls
IDS/IPS
SIEM
Endpoint protection

Job description

Title: Senior Information System Security Manager

Location: Odenton, MD

Compensation Range: $145 - 165k

Clearance: *Active DoD Secret

Company Overview:

Cornerstone Defense is the Employer of Choice within the Intelligence, Defense, and Space communities of the U.S. Government. Realizing early on that our most prized assets are our employees, we continually focus our attention on improving the overall work/life experience they have supporting the mission. Our Team is pushed every day to use their industry leading knowledge to provide end-to-end solutions to combat our nation’s toughest and most secure problems. If you are looking for a place to not only be professionally challenged, but encouraged and supported by a company that cares, don’t look any further than Cornerstone Defense.

Benefits Overview:
  • Medical, Dental and Vision Plans
  • Generous PTO Policy
  • 401(k)
  • HSA and FSA options
  • Life and Disability Insurance
  • Tuition Reimbursement and Training
  • Perks at Work Discount Program
  • Referral Program
  • Leads Generation Program
  • CollegeAmerica 529
  • Fitness Reimbursement Program
  • Travel Assistance
  • Norton Lifelock Benefit Solutions
  • Life Planning Financial & Legal Services
Position Description:

The Senior Information System Security Manager (ISSM) oversees the cybersecurity posture of DISA systems, ensuring compliance with DoD security requirements and safeguarding sensitive information. This role includes full lifecycle ownership of the Risk Management Framework (RMF) process, development and execution of cybersecurity policies, continuous monitoring, vulnerability management, security documentation oversight, and coordination with cross‑functional engineering and program teams. The ISSM ensures systems remain secure, accredited, and fully compliant with DoD standards.

Core Tasks:
  • Manage the full RMF lifecycle to achieve and maintain system Authority to Operate (ATO).
  • Provide ISSM support across FISMA, certification, and accreditation requirements.
  • Conduct recurring assessments of security controls and documentation within eMASS and PPSM to maintain accuracy, compliance, and audit readiness.
  • Manage whitelist records and address vulnerabilities identified through IAVMS scans; develop and track POA&Ms.
  • Maintain eMASS control records and POA&Ms in alignment with ATO conditions, approval requirements, and remediation timelines.
  • Coordinate cybersecurity activities for interim and final authorization to test and operate—ensuring assessments, mitigation planning, patch validation, and reporting are executed effectively.
  • Develop and deliver cybersecurity documentation including test plans, test reports, implementation plans, STIG/configuration artifacts, vulnerability assessment reports, and full authorization package materials.
  • Lead cybersecurity governance activities—managing system architectures, security requirements, protection plans, IAVA actions, and IA compliance objectives.
  • Prepare documentation, evidence, and briefings for DISA OAB reviews and support the team throughout the review and adjudication process.
Qualifications:
  • Bachelor’s degree with 8+ years of experience or Master’s degree with 6+ years (additional experience may substitute for education).
  • CISSP, CISM, or equivalent senior‑level cybersecurity certification.
  • Detailed knowledge of DoD cybersecurity policies, frameworks, and standards such as NIST 800‑53, RMF, FISMA, ICD 503, and JSIG.
  • Extensive experience maintaining ATOs for DoD enterprise systems.
  • Experience with system security engineering, risk management, and vulnerability assessment methodology.
  • Strong understanding of network security principles and common cyber tools (firewalls, IDS/IPS, SIEM, endpoint protection).
  • Ability to operate independently and collaboratively across cross‑functional teams.
  • Excellent communication skills with experience preparing and presenting detailed cybersecurity reports.
Preferred:
  • Experience managing security for complex DoD programs or mission‑critical systems.
  • Hands‑on experience with vulnerability scanning, penetration testing, and audit tools.
  • Advanced certifications such as CISA, CEH, CSSP, etc.
  • Experience with configuration and change management processes in secure environments.
  • Experience supporting automation processes and continuous ATO (cATO) initiatives.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

RMantra Solutions • Fort Meade (MD), Northern (KY)

On-site
USD 130,000 - 170,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

JFL Consulting LLC • Springfield (VA)

On-site
USD 155,000 - 175,000
Salary 155k-175k
Medical/dental/vision premiums
FSA accounts
+4
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Koitecc Solutions • Oklahoma City (OK)

On-site
USD 120,000 - 150,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Leidos • Odenton (MD)

On-site
USD 108,000 - 195,000
Information System Security Manager
Information System Security Manager

Istari Digital • Arlington (VA)

On-site
USD 140,000 - 200,000
Information System Security Manager (Skill Level 2-3)
Information System Security Manager (Skill Level 2-3)

Rippling, Inc. • Fort Meade (MD)

On-site
USD 120,000 - 180,000
Information Systems Security Manager Senior
Information Systems Security Manager Senior

Modern Technology Solutions, Inc. (MTSI) • Bath Township (OH)

On-site
USD 150,000 - 190,000
Senior Information System Security Manager (ISSM)
Senior Information System Security Manager (ISSM)

Koitecc Solutions • Odenton (MD), Northern (KY)

On-site
USD 108,000 - 195,000
Information Systems Security Manager (ISSM) – Senior
Information Systems Security Manager (ISSM) – Senior

CGS Federal (Contact Government Services) • Washington

On-site
USD 100,000 - 130,000
Health, Dental, and Vision
Life Insurance
401k
+2
Security Manager - ISSM
Security Manager - ISSM

Qualis LLC • United States

On-site
USD 100,000 - 130,000
Flexible scheduling
Family-friendly work environment
Community involvement opportunities