Information Systems Security Manager
Parsons Corporation · Baltimore, MD · 3 wk ago
Information Technology$158k–$284k/yrFull-time
About the role
Lead the shift from static, point-in-time compliance assessments to a dynamic, real-time risk authorization posture under the Risk Management Framework (RMF).
Responsibilities
- Govern a secure, pre-accredited DevSecOps platform designed for downstream applications to inherit security controls seamlessly.
- Define, implement, and maintain automated risk thresholds, security baselines, and compliance rules integrated directly into continuous integration/continuous deployment (CI/CD) pipelines.
- Oversee real-time configuration tracking, live vulnerability assessments, and threat analytics to ensure ongoing compliance.
- Act as the interface translating automated pipeline data, Software Bills of Materials (SBOMs), and tool-generated security metrics into actionable risk acceptance frameworks to the Task Lead.
- Guide and orchestrate the Plan of Action and Milestones (POA&M) process, transitioning it from a manual tracking spreadsheet to an automated, tool-driven lifecycle RMF.
- Set formal governance criteria outlining exactly what level of security vulnerabilities (e.g., critical/high SAST, DAST, or container flaws) will automatically break a software build or block a production deployment.
- Validate that Terraform scripts, Helm charts, and cloud-native templates used to spin up environments are programmatically hardened against DISA STIGs and NIST baselines.
- Enforce rigorous software supply chain security standards, including automated container scanning, open-source dependency tracking, signature validation, and compliance with SLSA frameworks.
- Govern the Least Privilege Access model across the entire development community, strictly partitioning and isolating tenant developer environments from live, production-level pipelines.
- Serve as a collaborative bridge between system administrators, software engineers, cloud architects, and compliance officers to shift security left into the early design phases.
- Establish goals and plans that meet project objectives.
Requirements
- Minimum 15 years of relevant experience with a Master’s Degree in Computer Science, Cybersecurity, Information Assurance, Information Security System Engineering, or a related discipline from an accredited college or University.
- Active DoD IAM and/or IAT Level III certification.
- Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or equivalent.
- Mastery of the Risk Management Framework (RMF) and associated federal cybersecurity standards, including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
- Demonstrated understanding and experience with Enterprise-level Cloud Architecture & Security principles, including control inheritance and shared responsibility models across AWS and Azure.
- Experience with DevSecOps practices, automated pipeline security (SAST, DAST, SCA), and CI/CD tools.
- Experience as a SETA contractor.
- Demonstrated experience providing technical leadership on assignments.
- Active Top Secret SCI with Polygraph security clearance required.
Benefits
- Medical, dental, and vision coverage.
- Paid time off.
- 401(k) retirement plan.
- Life insurance.
- Flexible work schedules and holidays.
Pay
Salary Range: $157,500.00 - $283,500.00