Position Details
Information System Security Manager (ISSM)
- Location
- Remote
- Work Setting
- Remote
- Employment Type
- Full Time
Position Overview
DSD Laboratories is seeking experienced Information System Security Managers (ISSMs) at multiple levels to support mission-critical Department of Defense programs. You will lead or support Risk Management Framework (RMF) authorization, continuous monitoring, and cybersecurity compliance activities that directly protect national security systems. If you are passionate about information assurance and want your work to matter, we want to hear from you.
Responsibilities
• Serve as Information System Security Manager (ISSM) supporting the ESCAPE contract within the AFMC A4 portfolio
• Own the full RMF Rev 5 lifecycle for SIPR-hosted systems — from initial system Categorization through Assessment, Authorization, and Continuous Monitoring — and develop and maintain Authorization Packages (SSP, SAR, POA&M, Risk Assessments)
• Coordinate with Authorizing Officials (AO/SCA) and manage ATO/cATO lifecycles in eMASS
• Oversee continuous monitoring, control assessments, STIG/SCAP compliance, vulnerability remediation, and audit readiness
• Coordinate with DevSecOps, system administrators, ISSOs, and program stakeholders to ensure cybersecurity requirements are integrated into system sustainment, transition, and operational processes
• Lead discrete cybersecurity tasks and mentor junior ISSO/cybersecurity staff
• Own the full RMF Rev 5 lifecycle for SIPR-hosted systems — from initial system Categorization through Assessment, Authorization, and Continuous Monitoring — and develop and maintain Authorization Packages (SSP, SAR, POA&M, Risk Assessments)
• Coordinate with Authorizing Officials (AO/SCA) and manage ATO/cATO lifecycles in eMASS
• Oversee continuous monitoring, control assessments, STIG/SCAP compliance, vulnerability remediation, and audit readiness
• Coordinate with DevSecOps, system administrators, ISSOs, and program stakeholders to ensure cybersecurity requirements are integrated into system sustainment, transition, and operational processes
• Lead discrete cybersecurity tasks and mentor junior ISSO/cybersecurity staff
Qualifications
• 3–5 years of hands-on experience in cybersecurity, Risk Management Framework (RMF) execution, system assessment & authorization, control assessment, vulnerability management, STIG/SCAP implementation and validation, or DoD/Federal information assurance support
• Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP/STIG tools
• A&A implementing NIST 800-53 Rev5, NIST 800-171, or FedRAMP Moderate
• Familiarity with DoD 8510.01, AFI 17-101, FISMA, and DoD Cloud Computing SRG (IL4/IL5)
• Holistic Plan of Action and Milestone (POA&M) management, continuous monitoring, audit log implementation and review, and security control assessments
• DoD 8140 Intermediate / DoD 8570 IAM Level II equivalent certification (e.g., GMON, SecurityX/CASP+, CCSP, CGRC/CAP, Cloud+, GCSA, GSEC, CISM, CISSP Associate)
• Must be eligible to obtain and maintain a Secret clearance
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related technical discipline; equivalent experience may be substituted where contract allows
• Because this role supports SIPR-hosted systems, must have — or be willing and able to obtain — regular access to a SIPR-capable facility at or near a military installation
• SIPR laptops are not currently available for remote issuance; that capability is planned but not yet in place
• Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP/STIG tools
• A&A implementing NIST 800-53 Rev5, NIST 800-171, or FedRAMP Moderate
• Familiarity with DoD 8510.01, AFI 17-101, FISMA, and DoD Cloud Computing SRG (IL4/IL5)
• Holistic Plan of Action and Milestone (POA&M) management, continuous monitoring, audit log implementation and review, and security control assessments
• DoD 8140 Intermediate / DoD 8570 IAM Level II equivalent certification (e.g., GMON, SecurityX/CASP+, CCSP, CGRC/CAP, Cloud+, GCSA, GSEC, CISM, CISSP Associate)
• Must be eligible to obtain and maintain a Secret clearance
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related technical discipline; equivalent experience may be substituted where contract allows
• Because this role supports SIPR-hosted systems, must have — or be willing and able to obtain — regular access to a SIPR-capable facility at or near a military installation
• SIPR laptops are not currently available for remote issuance; that capability is planned but not yet in place