Jobs · Information Technology · Maryland

Information Systems Security Manager

Parsons Corporation · Baltimore, MD · 3 wk ago
Information Technology$158k–$284k/yrFull-time

About the role

Lead the shift from static, point-in-time compliance assessments to a dynamic, real-time risk authorization posture under the Risk Management Framework (RMF).

Responsibilities

  • Govern a secure, pre-accredited DevSecOps platform designed for downstream applications to inherit security controls seamlessly.
  • Define, implement, and maintain automated risk thresholds, security baselines, and compliance rules integrated directly into continuous integration/continuous deployment (CI/CD) pipelines.
  • Oversee real-time configuration tracking, live vulnerability assessments, and threat analytics to ensure ongoing compliance.
  • Act as the interface translating automated pipeline data, Software Bills of Materials (SBOMs), and tool-generated security metrics into actionable risk acceptance frameworks to the Task Lead.
  • Guide and orchestrate the Plan of Action and Milestones (POA&M) process, transitioning it from a manual tracking spreadsheet to an automated, tool-driven lifecycle RMF.
  • Set formal governance criteria outlining exactly what level of security vulnerabilities (e.g., critical/high SAST, DAST, or container flaws) will automatically break a software build or block a production deployment.
  • Validate that Terraform scripts, Helm charts, and cloud-native templates used to spin up environments are programmatically hardened against DISA STIGs and NIST baselines.
  • Enforce rigorous software supply chain security standards, including automated container scanning, open-source dependency tracking, signature validation, and compliance with SLSA frameworks.
  • Govern the Least Privilege Access model across the entire development community, strictly partitioning and isolating tenant developer environments from live, production-level pipelines.
  • Serve as a collaborative bridge between system administrators, software engineers, cloud architects, and compliance officers to shift security left into the early design phases.
  • Establish goals and plans that meet project objectives.

Requirements

  • Minimum 15 years of relevant experience with a Master’s Degree in Computer Science, Cybersecurity, Information Assurance, Information Security System Engineering, or a related discipline from an accredited college or University.
  • Active DoD IAM and/or IAT Level III certification.
  • Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or equivalent.
  • Mastery of the Risk Management Framework (RMF) and associated federal cybersecurity standards, including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
  • Demonstrated understanding and experience with Enterprise-level Cloud Architecture & Security principles, including control inheritance and shared responsibility models across AWS and Azure.
  • Experience with DevSecOps practices, automated pipeline security (SAST, DAST, SCA), and CI/CD tools.
  • Experience as a SETA contractor.
  • Demonstrated experience providing technical leadership on assignments.
  • Active Top Secret SCI with Polygraph security clearance required.

Benefits

  • Medical, dental, and vision coverage.
  • Paid time off.
  • 401(k) retirement plan.
  • Life insurance.
  • Flexible work schedules and holidays.

Pay

Salary Range: $157,500.00 - $283,500.00

Similar jobs