Job Requirements
Orlando, FL
Top Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Zachary Piper Solutions is seeking an experienced Cybersecurity Information System Security Manager (ISSM) to support a U.S. Army customer in Orlando, FL (100% onsite). The Cybersecurity Information System Security Manager (ISSM) will serve as the primary lead responsible for managing the RMF lifecycle, ATO activities, & overall cybersecurity posture for multiple Army information systems supporting both CUI & classified environments. This role will partner closely with Government leadership, engineers, system owners, Authorizing Officials, & security assessors to ensure secure, compliant, & mission-ready systems throughout their lifecycle.
Responsibilities of the Cybersecurity Information System Security Manager (ISSM) include:
Qualifications of the Cybersecurity Information System Security Manager (ISSM) include:
Keywords: Information System Security Manager, ISSM, Information System Security Officer, ISSO, Cybersecurity, Risk Management Framework, RMF, Assessment and Authorization, A&A, Authorization to Operate, ATO, IATT, ATO-C, Continuous Monitoring, ConMon, System Security Plan, SSP, Plans of Action and Milestones, POA&M, eMASS, Xacta, Governance Risk and Compliance, GRC, Security Control Assessment, SCA, Vulnerability Management, STIG, ACAS, Security Technical Implementation Guide, DoD, Department of Defense, U.S. Army, Army Regulation 25-2, AR 25-2, NETCOM, Cybersecurity Compliance, Security Controls, Authorizing Official, AO, Body of Evidence, CUI, Classified Systems, Zero Trust, Zero Trust Architecture, ZTA, Cloud Security, FedRAMP, DoD Cloud SRG, Windows, Linux, Virtualization, Enterprise Networking, CISSP, CISM, CASP+, CCSP, DoD 8140, Orlando, Florida, Top Secret, TS, TS/SCI, Defense, Federal Government
#LI-SW1 #LI-ONSITE
Responsibilities of the Cybersecurity Information System Security Manager (ISSM) include:
- Serve as the ISSM supporting 3-7 U.S. Army information systems across classified & unclassified environments
- Lead all phases of the DOD RMF lifecycle, including system authorization, continuous monitoring, & reauthorization activities
- Develop, maintain, & manage RMF authorization packages including SSPs, POA&Ms, security categorization documentation, Body of Evidence artifacts, and ConMon documentation
- Coordinate ATO, IATT, ATO-C, & system reauthorization efforts
- Manage ConMon, vulnerability management, STIG compliance, ACAS scan reviews, cybersecurity reporting, & corrective action tracking
- Conduct cybersecurity risk assessments and provide recommendations supporting AO risk decisions
- Coordinate SCAs & oversee remediation of assessment findings to maintain RMF compliance
- Review system architectures, authorization boundaries, network diagrams, data flows, and engineering changes to ensure continued cybersecurity compliance
- Provide cybersecurity guidance and compliance support to system owners, engineers, administrators, and Government leadership
- Prepare executive briefings, cybersecurity status reports, risk assessments, & authorization recommendations for senior Government stakeholders
- Support implementation of ZTA, cloud security initiatives, & secure system engineering best practices where applicable
Qualifications of the Cybersecurity Information System Security Manager (ISSM) include:
- 8+ years of experience supporting DOD cybersecurity programs
- 5+ years of experience managing RMF & A&A activities within DOD environments
- Experience serving as an ISSM/ISSO supporting U.S. Army or DOD information systems
- Demonstrated experience managing multiple RMF authorization packages simultaneously through the full system lifecycle
- Strong knowledge of DOD RMF, AR 25-2, NETCOM RMF Business Rules, & cybersecurity compliance requirements
- Experience developing and maintaining SSPs, POA&Ms, Body of Evidence documentation, ConMon artifacts, and authorization packages
- Hands-on experience with vulnerability management, STIG implementation, ACAS, SCAs, and cybersecurity compliance reporting
- Experience using eMASS, Xacta, or similar GRC tools
- Working knowledge of Microsoft Windows, Linux, virtualization technologies, enterprise networking, and cloud security principles
- Experience supporting ZTA, FedRAMP, or DoD Cloud SRG environments preferred
- Certifications preferred: CISSP, CISM, CASP+, or CCSP
- Active Top Secret security clearance required (SCI eligibility preferred)
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field
Keywords: Information System Security Manager, ISSM, Information System Security Officer, ISSO, Cybersecurity, Risk Management Framework, RMF, Assessment and Authorization, A&A, Authorization to Operate, ATO, IATT, ATO-C, Continuous Monitoring, ConMon, System Security Plan, SSP, Plans of Action and Milestones, POA&M, eMASS, Xacta, Governance Risk and Compliance, GRC, Security Control Assessment, SCA, Vulnerability Management, STIG, ACAS, Security Technical Implementation Guide, DoD, Department of Defense, U.S. Army, Army Regulation 25-2, AR 25-2, NETCOM, Cybersecurity Compliance, Security Controls, Authorizing Official, AO, Body of Evidence, CUI, Classified Systems, Zero Trust, Zero Trust Architecture, ZTA, Cloud Security, FedRAMP, DoD Cloud SRG, Windows, Linux, Virtualization, Enterprise Networking, CISSP, CISM, CASP+, CCSP, DoD 8140, Orlando, Florida, Top Secret, TS, TS/SCI, Defense, Federal Government
#LI-SW1 #LI-ONSITE
group id: 10430981