Jobs · Information Technology · Virginia

Information Systems Security Manager (ISSM)

Ridgeline International, LLC · Chantilly, VA · 1 wk ago
On-siteInformation Technology$190k–$232k/yrFull-time

About the Role

Veilant is rethinking how cyber security and assurance get delivered across mission and enterprise systems. You'll be the primary security advisor and the trusted bridge between our Information Security Program and our government mission partners — the person engineering teams consult before they commit to a design, and the person our customers call when a hard question about risk or compliance lands on their desk. If you've spent years watching RMF get treated as a compliance tax and you know it can be run as a discipline that actually makes systems better, this is the role where you get to prove it.

What You'll Own

  • RMF accreditation, end to end — authoring and maintaining System Security Plans, policies, and procedures; building ATO packages; writing the justifications; assembling evidence; walking auditors through reviews; answering the government's questions directly; and keeping continuous monitoring running long after the authorization is signed
  • Compliance integrity — reviewing systems on a regular cadence for drift from documented configurations and procedures, reporting what you find without softening it, and driving remediation to closure
  • Regulatory authority — knowing what NIST CSF, SP 800-171, SP 800-53, CMMC, and the DoD Zero Trust Mandate actually require and what they mean for the system in front of you
  • Security as a design input — identifying security requirements early and getting them built into architecture rather than bolted on; advising mission teams on how their work maps to authorization processes (software, wireless, cloud approvals) so nobody discovers a blocker three weeks before delivery

What Success Looks Like in Your First Six Months

  • A complete inventory of in-scope systems and their current authorization posture, with a prioritized roadmap for what needs attention and in what order
  • At least one system carried through ATO or reauthorization under your ownership
  • SSPs and supporting documentation current and defensible for every system you own
  • A continuous monitoring rhythm operating on a predictable cadence, with reporting your government partners actually rely on
  • Established as the advisor mission and engineering teams bring in early — not after the design is locked

How We'll Measure Your Impact

  • Authorizations delivered on schedule, with no lapses in ATO coverage
  • Audit and assessment findings closed within agreed timelines, with POA&M burn-down trending down
  • Government partners raise security questions to you directly, and get answers they can act on
  • Security requirements appear in architecture reviews before they appear in findings

Qualifications

  • Active TS/SCI with Polygraph (hard requirement)
  • Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or a related field — or equivalent hands-on experience
  • 5+ years of progressively increasing responsibility supporting cybersecurity, information assurance, risk management, or compliance for classified and unclassified programs, within the U.S. Government or as a cleared contractor
  • Direct RMF experience — you've built ATO packages, not just contributed to them, and you've owned the relationship with an authorizing official
  • Applied technical depth in one or more of: cloud and external services, system administration, configuration management, system and network architecture, operational technology, wireless, telecommunications security, supply chain risk, or security analysis tooling (Splunk, Nessus, Wireshark, and the like)
  • Communication that lands with both audiences — you can brief a room of engineers and a room of executives on the same risk, and both walk out knowing what to do next
  • Willingness to work predominantly on-site in cleared facilities in Northern Virginia

What Sets You Apart

  • Experience standing up or maturing a security program rather than maintaining an established one
  • CISSP, CISM, or equivalent certification
  • Direct experience implementing DoD Zero Trust requirements or CMMC readiness
  • A track record of turning a skeptical mission team into a partner

Pay

$190,000 to $232,000 annually for full-time status. Actual compensation within this range is determined by numerous factors including but not limited to the candidate's qualifications, including experience, education, certifications, technical skills, as well as contract-specific affordability and labor categories, the scope and responsibilities of the role, market and business considerations, and geographic location.

Benefits

  • Flexible PTO + holidays
  • Generous 401k match benefit up to 10%, with an automatic 3% safe harbor contribution and additional matching based on employee contributions
  • Medical (HSA & PPO Plans Available), dental, vision, disability, and life insurance
  • Employer Contribution to Health Savings Account (HSA)
  • Learning & Development opportunities
  • Professional coaching services
  • Get the technology you want to do your job
  • Free daily snacks & drinks

Similar jobs