More jobs:
Senior Information System Security Manager; ISSM
Job in
Fort Meade, Anne Arundel County, Maryland, USA
Listed on 2026-06-26
Listing for:
ECS
Full Time
position Listed on 2026-06-26
Job specializations:
-
IT/Tech
Cybersecurity, Information Security
Job Description & How to Apply Below
Job Description: Everforth ECS is seeking a Senior Information System Security Officer (ISSM) to work out of the customer site in Ft. Meade, MD
. The role supports DISA‑owned Impact Level 6 programs in an operational DoW environment within Microsoft’s Isolated Secret Region (MS‑ISR) that hosts multiple U.S. Coalition Mission Partner Environments. The ISSM serves as the senior cybersecurity authority, managing the cybersecurity program, overseeing risk and compliance, and maintaining the security posture of information systems within the authorization boundary.
- Act as the senior cybersecurity lead for the program, advising leadership while directly supporting RMF, ATO maintenance, risk management, and continuous monitoring activities across the Azure environment.
- Lead cybersecurity activities for a DoD Azure environment operating under a shared ATO boundary with multiple mission enclaves.
- Govern POA&Ms by reviewing open risks, validating remediation plans, tracking milestone progress, and ensuring closure evidence is complete and defensible.
- Oversee day‑to‑day execution of the cybersecurity program, including security authorization documentation, compliance tracking, vulnerability management, control validation, and risk reporting.
- Maintain overall accountability for the program’s RMF posture, including ATO sustainment, continuous monitoring, POA&M management, and security control implementation.
- Provide direction and support to the ISSO, Cyber Engineer, and Cyber Analyst while contributing directly to artifact review, documentation updates, and risk management activities.
- Review and approve RMF and ATO artifacts, including control implementation details, assessment evidence, POA&Ms, risk documentation, system diagrams, inventories, and continuous monitoring deliverables.
- Ensure eMASS records remain accurate and current, including security controls, artifacts, assessment results, POA&Ms, milestones, and authorization package documentation.
- Review vulnerability, STIG, ACAS, Trellix, and Sentinel data to assess risk, prioritize remediation, and communicate security posture to program leadership and government stakeholders.
- Coordinate with engineers, system administrators, cloud teams, mission enclave stakeholders, and government cybersecurity personnel to resolve findings and maintain compliance.
- Assess cybersecurity impacts of planned architecture, configuration, infrastructure, cloud, and boundary changes within the Azure environment.
- Support security control assessments, audit readiness, continuous monitoring reviews, and authorization package updates for classified systems.
- Review incident response activities, security events, and operational findings to ensure appropriate documentation, escalation, reporting, and follow‑up.
- Prepare and present cybersecurity status, risk summaries, POA&M metrics, vulnerability trends, compliance gaps, and ATO readiness updates to program and government leadership.
- Serve as the primary cybersecurity point of contact for DISA government stakeholders, including DISA cyber teams, assessors, auditors, program leadership, and internal team members supporting RMF, ATO, continuous monitoring, risk, and compliance activities.
- Ensure cybersecurity documentation aligns with the operational environment, including enclave‑specific mission needs, shared services, inherited controls, and authorization boundary considerations.
- Drive continuous improvement of cybersecurity processes, documentation quality, artifact management, reporting, and coordination across the cyber team.
- Other duties, as assigned.
- U.S. Citizen.
- Active Secret clearance with ability to obtain TS/SCI.
- Active CISSP, CISM, GSLC, or other DoW 8140 IAM Level III certification.
- Ability to work four days per week onsite at Fort Meade, MD, with one remote day per week.
- 10+ years of experience supporting DoW RMF, ATO maintenance, continuous monitoring, security authorization documentation, and cybersecurity compliance for classified systems.
- Prior ISSM, senior ISSO, security control assessor, or cybersecurity lead experience supporting DoW, DISA, or federal information systems.
- Hands‑on experience…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×