Information Systems Security Manager ISSM
KMS Solutions, LLC is a technical management and solutions company specializing in engineering, analysis, and cyber security. Founded in 2005, KMS is a certified small business with nearly two decades of experience supporting the Department of Defense and other departments critical to national security. KMS has been recognized as a USA Today Top Workplace and has received multiple regional awards for workplace culture, compensation, benefits, innovation, leadership, and work-life flexibility.
About the role
KMS Solutions, LLC is seeking a highly motivated Information Systems Security Manager (ISSM) to provide senior-level cybersecurity leadership, oversight, and Risk Management Framework (RMF) support to Naval Special Warfare (NSW) and expeditionary systems managed by PMS 340. The ISSM will serve as the cybersecurity authority for PMS 340, responsible for system accreditation, cybersecurity engineering, vulnerability management, and ensuring compliance with DoD, DoN, NAVSEA, NIST, and CNSSI cybersecurity requirements.
Responsibilities
- Lead development, maintenance, and submission of RMF accreditation packages for PMS 340 systems, ensuring compliance with DoD, DoN, NAVSEA CS-DoN SOPs, and business rules.
- Oversee cybersecurity documentation including SSPs, POA&Ms, validation procedures, and risk assessments, ensuring systems meet information assurance and security requirements.
- Conduct and oversee security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and RMF requirements.
- Perform and direct vulnerability assessment and compliance reviews using ACAS, SCAP, and Nmap for PMS 340 systems.
- Manage cybersecurity workflows and accreditation artifacts using eMASS.
- Support cybersecurity Test & Evaluation phases including cooperative vulnerability identification, adversarial testing, penetration assessments, and adversarial assessments.
- Identify and mitigate cybersecurity risks across PMS 340 systems; ensure risk treatment, compliance, and monitoring throughout the system lifecycle.
- Coordinate cybersecurity activities across NAVSEA, NSW, SOCOM, NUWC, and other stakeholders, supporting IPTs, Working Groups, and program reviews.
- Prepare cybersecurity reports, briefs, and documentation, clearly articulating cybersecurity requirements to PMO leadership and technical teams.
- Provide cybersecurity guidance, engineering support, and subject matter expertise for PMS 340 systems, including undersea, maritime, surface, air, and expeditionary technologies.
- Support PMS 340 leadership in ad hoc cybersecurity meetings and engagements, including those requiring travel.
Requirements
- Bachelor’s degree in cybersecurity, information systems, engineering, mathematics, or related discipline.
- Minimum 5 years of cybersecurity or RMF-based experience supporting DoD systems.
- DoD 8570.01M IAT/IAM Level II or III certification (e.g., Security+).
- Operating Systems certification (Windows or Linux).
- Experience with RMF, A&A processes, and cybersecurity validation of DoD IT systems.
- Experience using eMASS.
- Equivalent combinations of education and experience will be considered.
Qualifications
- Master’s degree in cybersecurity, information systems, or engineering.
- 6–8+ years of cybersecurity experience supporting DoD or Navy cybersecurity programs (NSW/SOF or undersea systems preferred).
- Navy Qualified Validator (NQV).
- Experience with NIST RMF, Navy cybersecurity policy, and DIACAP-to-RMF transitions.
- Systems engineering or system integration experience.
Skills
- Proficiency in Microsoft Office (Word, Excel, PowerPoint, Outlook).
- Excellent verbal and written communication skills; ability to clearly articulate technical requirements.
- Ability to independently perform cybersecurity assessments and analyses.
- Thoroughness, attention to detail, and disciplined documentation habits.
- Ability to work collaboratively across engineering, acquisition, and cybersecurity teams.
- Highly reliable with personal initiative to operate in a fast-paced environment with changing priorities.
Additional Eligibility Requirements
- Must be a U.S. citizen and able to obtain and/or maintain a Secret DoD Security Clearance.
- Legally authorized to work in the United States at the time of hire and throughout employment.
Work Environment
- Professional office environment.
- Routine use of standard office equipment such as computers, phones, and photocopiers.
- Regularly required to talk, hear, stand, walk, use hands to finger, handle or feel, and reach with hands and arms.
- Must be able to lift up to 20 lbs.
Schedule
- Typical workday is eight hours in length with some flexibility allowed, subject to supervisor concurrence.
- Must be available during core work hours as determined by contract/location.
- Telework may be allowed up to 60%, subject to change based on business needs and customer requirements.
- Travel up to 10% may be required (CONUS and potential OCONUS).
Benefits
- Medical, dental, and vision insurance.
- Flexible spending account.
- Paid time off (PTO), paid holidays, military leave, and bereavement leave.
- 401k / retirement savings plan.
- Professional development and tuition reimbursement.
- Basic and voluntary life insurance / AD&D.
- Short-term and long-term disability.
- Voluntary AFLAC supplemental insurance products.
- Employee assistance program (EAP).
- Employee referral bonuses and discretionary annual bonus.