Job Requirements
Odenton, MD
Secret Polygraph Unspecified
Career Level not specified
$145,000 - $165,000
Job Description
Title: Senior Information System Security Manager
Location: Odenton, MD
Compensation Range: $145 - 165k
Clearance: * Active DoD Secret
Company Overview:
Cornerstone Defense is the Employer of Choice within the Intelligence, Defense, and Space communities of the U.S. Government. Realizing early on that our most prized assets are our employees, we continually focus our attention on improving the overall work/life experience they have supporting the mission. Our Team is pushed every day to use their industry leading knowledge to provide end-to-end solutions to combat our nation's toughest and most secure problems. If you are looking for a place to not only be professionally challenged, but encouraged and supported by a company that cares, don't look any further than Cornerstone Defense.
Benefits Overview:
Cornerstone Defense offers a very comprehensive benefits package including, but not limited to: Medical, Dental and Vision Plans * Generous PTO Policy * 401(k) * HSA and FSA options * Life and Disability Insurance * Tuition Reimbursement and Training * Perks at Work Discount Program * Referral Program * Leads Generation Program * CollegeAmerica 529 * Fitness Reimbursement Program * Travel Assistance * Norton Lifelock Benefit Solutions * Life Planning Financial & Legal Services *
Position Description:
The Senior Information System Security Manager (ISSM) oversees the cybersecurity posture of DISA systems, ensuring compliance with DoD security requirements and safeguarding sensitive information. This role includes full lifecycle ownership of the Risk Management Framework (RMF) process, development and execution of cybersecurity policies, continuous monitoring, vulnerability management, security documentation oversight, and coordination with cross-functional engineering and program teams. The ISSM ensures systems remain secure, accredited, and fully compliant with DoD standards.
Core Tasks:
Qualifications:
Location: Odenton, MD
Compensation Range: $145 - 165k
Clearance: * Active DoD Secret
Company Overview:
Cornerstone Defense is the Employer of Choice within the Intelligence, Defense, and Space communities of the U.S. Government. Realizing early on that our most prized assets are our employees, we continually focus our attention on improving the overall work/life experience they have supporting the mission. Our Team is pushed every day to use their industry leading knowledge to provide end-to-end solutions to combat our nation's toughest and most secure problems. If you are looking for a place to not only be professionally challenged, but encouraged and supported by a company that cares, don't look any further than Cornerstone Defense.
Benefits Overview:
Cornerstone Defense offers a very comprehensive benefits package including, but not limited to: Medical, Dental and Vision Plans * Generous PTO Policy * 401(k) * HSA and FSA options * Life and Disability Insurance * Tuition Reimbursement and Training * Perks at Work Discount Program * Referral Program * Leads Generation Program * CollegeAmerica 529 * Fitness Reimbursement Program * Travel Assistance * Norton Lifelock Benefit Solutions * Life Planning Financial & Legal Services *
Position Description:
The Senior Information System Security Manager (ISSM) oversees the cybersecurity posture of DISA systems, ensuring compliance with DoD security requirements and safeguarding sensitive information. This role includes full lifecycle ownership of the Risk Management Framework (RMF) process, development and execution of cybersecurity policies, continuous monitoring, vulnerability management, security documentation oversight, and coordination with cross-functional engineering and program teams. The ISSM ensures systems remain secure, accredited, and fully compliant with DoD standards.
Core Tasks:
- Manage the full RMF lifecycle to achieve and maintain system Authority to Operate (ATO).
- Provide ISSM support across FISMA, certification, and accreditation requirements.
- Conduct recurring assessments of security controls and documentation within eMASS and PPSM to maintain accuracy, compliance, and audit readiness.
- Manage whitelist records and address vulnerabilities identified through IAVMS scans; develop and track POA&Ms.
- Maintain eMASS control records and POA&Ms in alignment with ATO conditions, approval requirements, and remediation timelines.
- Coordinate cybersecurity activities for interim and final authorization to test and operate-ensuring assessments, mitigation planning, patch validation, and reporting are executed effectively.
- Develop and deliver cybersecurity documentation including test plans, test reports, implementation plans, STIG/configuration artifacts, vulnerability assessment reports, and full authorization package materials.
- Lead cybersecurity governance activities-managing system architectures, security requirements, protection plans, IAVA actions, and IA compliance objectives.
- Prepare documentation, evidence, and briefings for DISA OAB reviews and support the team throughout the review and adjudication process.
Qualifications:
- Bachelor's degree with 8+ years of experience or Master's degree with 6+ years (additional experience may substitute for education).
- CISSP, CISM, or equivalent senior-level cybersecurity certification.
- Detailed knowledge of DoD cybersecurity policies, frameworks, and standards such as NIST 800-53, RMF, FISMA, ICD 503, and JSIG.
- Extensive experience maintaining ATOs for DoD enterprise systems.
- Experience with system security engineering, risk management, and vulnerability assessment methodology.
- Strong understanding of network security principles and common cyber tools (firewalls, IDS/IPS, SIEM, endpoint protection).
- Ability to operate independently and collaboratively across cross-functional teams.
- Excellent communication skills with experience preparing and presenting detailed cybersecurity reports.
- Experience managing security for complex DoD programs or mission-critical systems.
- Hands-on experience with vulnerability scanning, penetration testing, and audit tools.
- Advanced certifications such as CISA, CEH, CSSP, etc.
- Experience with configuration and change management processes in secure environments.
- Experience supporting automation processes and continuous ATO (cATO) initiatives.
group id: 90751604