Jobs · Information Technology · Florida

Information System Security Manager (ISSM)

Zachary Piper Solutions · Orlando, FL · Yesterday
On-siteInformation TechnologyFull-time

Responsibilities

  • Serve as the ISSM supporting 3–7 U.S. Army information systems across classified & unclassified environments
  • Lead all phases of the DOD RMF lifecycle, including system authorization, continuous monitoring, & reauthorization activities
  • Develop, maintain, & manage RMF authorization packages including SSPs, POA&Ms, security categorization documentation, Body of Evidence artifacts, and ConMon documentation
  • Cook up ATO, IATT, ATO-C, & system reauthorization efforts
  • Coordinate ConMon, vulnerability management, STIG compliance, ACAS scan reviews, cybersecurity reporting, & corrective action tracking
  • Conduct cybersecurity risk assessments and provide recommendations supporting AO risk decisions
  • Coordinate SCAs & oversee remediation of assessment findings to maintain RMF compliance
  • Review system architectures, authorization boundaries, network diagrams, data flows, & engineering changes to ensure continued cybersecurity compliance
  • Provide cybersecurity guidance and compliance support to system owners, engineers, administrators, & Government leadership
  • Prepare executive briefings, cybersecurity status reports, risk assessments, & authorization recommendations for senior Government stakeholders
  • Support implementation of ZTA, cloud security initiatives, & secure system engineering best practices where applicable

Qualifications

  • 8+ years of experience supporting DOD cybersecurity programs
  • 5+ years of experience managing RMF & A&A activities within DOD environments
  • Strong knowledge of DOD RMF, AR 25-2, NETCOM RMF Business Rules, & cybersecurity compliance requirements
  • Experience developing and maintaining SSPs, POA&Ms, Body of Evidence documentation, ConMon artifacts, and authorization packages
  • Hands-on experience with vulnerability management, STIG implementation, ACAS, SCAs, & cybersecurity compliance reporting
  • Experience using eMASS, Xacta, or similar GRC tools
  • Experience supporting ZTA, FedRAMP, or DoD Cloud SRG environments preferred
  • Certifications preferred: CISSP, CISM, CASP+, or CCSP
  • Active Top Secret security clearance required (SCI eligibility preferred)
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field

Similar jobs