Information Systems Security Manager
Core
Serve as the primary security authority for classified information systems, driving risk management and ensuring compliance with government regulations to sustain Authorization to Operate (ATO).
Role type
Senior Information Systems Security Manager (ISSM)
Builds
Classified defense and commercial air operator systems
Domain
Defense / Cybersecurity
Deliverable
client delivery
Required skills
RMF-based ATO management, classified system security (Secret/TS/SCI), security assessment and risk analysis, STIG/SRG hardening, SIEM integration, security incident investigation, security architecture design
Preferred skills
TS/SCI clearance eligibility, experience with Windows Server, RHEL/CentOS, VMware, network security architectures
Technologies
Nessus, ACAS, SCAP, Windows Server, RHEL/CentOS, VMware
Responsibilities
Develop and submit Security Authorization Packages per NIST SP 800-37 RMF; manage full lifecycle of ATOs including continuous monitoring; serve as primary liaison to government Authorizing Officials; conduct security assessments and vulnerability scans; oversee STIG/SRG hardening across OS and network infrastructure; supervise ISSOs and conduct security training; investigate security incidents and anomalies; implement continuous monitoring strategies including log management and SIEM integration.
Seniority
Senior, hands-on IC