Job Requirements
San Antonio, TX
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
OVERVIEW:
We are seeking a highly motivated Information Systems Security Manager (ISSM) who is responsible for cybersecurity engineering, cyber policy, and Risk Management Framework (RMF) activities supporting Department of Defense software factories and enterprise cloud environments. The ISSM will serve as the cybersecurity lead supporting one or more agile teams, integrating directly with Government leadership, Cyber Operations Teams (COT), Cyber Penetration Teams (CPT), Product Owners, Software Engineers, and DevSecOps personnel to maintain secure cloud-native capabilities while accelerating software delivery through Continuous Authority to Operate (cATO). This position supports enterprise cybersecurity operations spanning multiple mission value streams and classified environments, ensuring secure software delivery while balancing mission execution, cybersecurity risk, and compliance with Department of Defense policies. The position will have routine collaboration across mission engineering, cybersecurity, operations, and acquisition organizations.
GENERAL DUTIES:
REQUIRED QUALIFICATIONS:
DESIRED QUALIFICATIONS:
CLEARANCE:
We are seeking a highly motivated Information Systems Security Manager (ISSM) who is responsible for cybersecurity engineering, cyber policy, and Risk Management Framework (RMF) activities supporting Department of Defense software factories and enterprise cloud environments. The ISSM will serve as the cybersecurity lead supporting one or more agile teams, integrating directly with Government leadership, Cyber Operations Teams (COT), Cyber Penetration Teams (CPT), Product Owners, Software Engineers, and DevSecOps personnel to maintain secure cloud-native capabilities while accelerating software delivery through Continuous Authority to Operate (cATO). This position supports enterprise cybersecurity operations spanning multiple mission value streams and classified environments, ensuring secure software delivery while balancing mission execution, cybersecurity risk, and compliance with Department of Defense policies. The position will have routine collaboration across mission engineering, cybersecurity, operations, and acquisition organizations.
GENERAL DUTIES:
- Lead RMF implementation supporting initial ATOs and Continuous ATO (cATO).
- Serve as the cybersecurity lead supporting multiple mission value streams.
- Develop and maintain RMF authorization packages including SSPs, SARs, POA&Ms and supporting artifacts.
- Coordinate cybersecurity assessments with Authorizing Officials, Security Control Assessors, penetration testing teams, and engineering organizations.
- Integrate cybersecurity requirements into Agile and SAFe software development activities.
- Support planning, execution, remediation, and continuous monitoring.
- Ensure cybersecurity controls remain operational across development, testing, staging, and production environments.
- Coordinate vulnerability management, STIG implementation, POA&M tracking, and security control validation.
- Support Zero Trust implementation, cloud security, Kubernetes/OpenShift security, container hardening, and DevSecOps pipeline security.
- Evaluate cybersecurity risks and provide mitigation recommendations supporting mission operations.
- Support annual cyber assessments, inspections, and operational readiness activities.
- Develop executive-level briefings, risk assessments, and cybersecurity recommendations.
- Support operations across Unclassified, Secret, and SCI environments as required.
REQUIRED QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or related field
- One or more of the following: CISSP, CASP+, Security+ or Equivalent DoD 8140 certification
- Nine or more years supporting Department of Defense cybersecurity missions.
- Nine or more years serving as an ISSM, ISSE, or senior cybersecurity engineer.
- Experience implementing the Risk Management Framework (RMF).
- Experience achieving and maintaining Authority to Operate (ATO).
- Experience supporting Continuous Monitoring programs.
- Experience supporting DevSecOps environments.
- Experience supporting Agile or SAFe software development.
- Experience supporting enterprise cloud environments.
- Knowledge of NIST RMF, NIST 800-53, CNSSI guidance, DoD cybersecurity policy, and STIG implementation.
- Experience briefing senior Government leadership.
- Excellent written and verbal communication skills.
DESIRED QUALIFICATIONS:
- Advanced degree in Cybersecurity, Computer Science, Engineering, Information Assurance, or related field.
- One or more of the following: CISSP-ISSMP, AWS Security Specialty, Certified Cloud Security Professional (CCSP).
- Nine or more years supporting DoD cybersecurity missions.
- Experience supporting software factories.
- Experience supporting Kubernetes and OpenShift.
- Experience supporting Iron Bank or hardened container environments.
- Experience supporting Continuous ATO (cATO). - Experience implementing Zero Trust architectures.
- Experience supporting enterprise DevSecOps pipelines.
- Experience supporting IL4/IL5/IL6 cloud environments.
- Experience supporting software factories.
- Experience supporting Cyber Operations Teams.
- Experience supporting Cyber Penetration Teams.
- Experience supporting multiple military services and Combatant Commands.
CLEARANCE:
- Active TS/SCI clearance required
group id: 90943786