Information System Security Manager (ISSM)
Systems Planning & Analysis · Lincoln, MA · Yesterday
Information Technology$180k/yrFull-time
Responsibilities
- Lead Risk Management Framework (RMF) activities, maintain security documentation and artifacts.
- Coordinate with government security officials on security testing, ATO/ATC actions, and policy compliance.
- Define and enforce cybersecurity and cyber-resiliency practices across the development and integration lifecycle.
- Work closely with engineering, test, and platform operations to embed security controls into architectures, pipelines, and test environments.
Qualifications
- BS in cybersecurity, computer science, information assurance, or similar field plus 8+ years of cybersecurity experience on medium-to-large IT or software programs, including at least 4 years in an ISSM or equivalent leadership role.
- Direct experience implementing DoD RMF (and prior DIACAP) processes, including authoring and maintaining accreditation packages and FISMA-related records.
- Demonstrated experience leading or supporting DISA STIG compliance, vulnerability scanning, penetration testing, and testing in NIPR/SIPR and related environments.
- Familiarity with mission planning or similar weapon-system security contexts, including support for ATO and ATC activities and security targets.
- DoD-approved cybersecurity certification such as CISSP, CAP, or CISM.
- Active DoD Secret clearance (or higher) and the ability to maintain it throughout employment.
Desired Qualifications
- Master’s degree in relevant field plus experience developing and maintaining enterprise cybersecurity master plans, Program Protection Plans, anti-tamper plans, and related security documentation.
- Familiarity with Air Force cybersecurity policy and coordination with AF network and accreditation authorities.
- Experience in cyber resiliency for mission or weapon systems, including secure coding standards, security-focused scenarios, and user certification requirements.
- Experience integrating security controls into DevSecOps pipelines and CDE environments, including automated compliance and security testing.
- Prior experience addressing security considerations for FMS deliveries and multi-national information-sharing constraints.