Advisory Information Security Manager – ISSM
Job in
Huntsville, Madison County, Alabama, 35824, USA
Listed on 2026-08-16
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-16
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security
Job Description & How to Apply Below
- Serve as the primary contractor cybersecurity authority on-site with Army and Navy Organization ISSMs, AODRs, and AOs
- Build, manage, and maintain Assessment & Authorization packages in eMASS and customer databases
- Evaluate NIST SP 800-53 Rev. 5 and CNSSI 1253 security controls across contractor-designed networks
- Oversee ACAS, Nessus, and SCAP Compliance Checker vulnerability assessments and DISA STIG/SRG implementation
- Draft, track, and remediate POA&Ms while negotiating risk levels and mitigation strategies
- Establish and execute Continuous Monitoring strategies, annual security reviews, boundary modifications, and re-authorization events
- Embed cybersecurity requirements into internal software, network, and systems engineering workflows
- Develop and enforce internal baseline configuration guides using DISA STIGs and CIS Benchmarks
- Review product architectures and software deliverables, including static/dynamic code analysis and dependency scanning
- Establish cybersecurity SOPs, hardening checklists, and secure development guidelines
- Lead vulnerability response and corrective measures for critical vulnerabilities or zero-day threats
- Coordinate incident reporting, containment, investigation, and remediation
- Prepare systems for government cybersecurity inspections and internal quality audits
- Advise engineering managers and government leadership on security posture, risk trade-offs, and emerging threats
- Translate DoD compliance requirements into actionable technical requirements for development teams
- Active TS security clearance required; TS/SCI preferred
- DoD 8140/8570 baseline certification required at intermediate level:
CompTIA Security+, SecurityX, Cloud+, GSEC, or equivalent - Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Information Systems, or Software Engineering, or equivalent
- 5+ years of relevant experience supporting Army or Navy customers through the full RMF lifecycle
- Hands-on experience with the complete RMF lifecycle under DoDI 8510.01, NIST SP 800-53 Rev. 5, and CNSSI 1253
- Advanced experience using eMASS to build, manage, and defend A&A packages for Army and/or Navy customers
- Experience with ACAS/Nessus and SCAP Compliance Checker vulnerability assessment tools
- Experience evaluating scan data and applying DISA STIGs/SRGs
- Experience drafting, negotiating, and tracking POA&Ms through mitigation to secure ATO, ATO with Conditions, or IATT
- Knowledge of system hardening across Linux/Windows, network infrastructure, containerized environments, and cloud architectures
- Experience embedding cybersecurity requirements into software/systems engineering workflows and Dev Sec Ops pipelines
- Familiarity with SAST/DAST tools and SBOM management
- Preferred certifications include CISSP, CISM, GCSA, GCIA, CISSP-ISSMP, CISA, CRISC, CCSP, and AWS/Azure Security Specialties
- Direct Army or Navy program-office experience preferred
Demonstrates expertise in cybersecurity risk management frameworks, vulnerability assessment tools, and compliance with DoD standards. Proficient in developing and enforcing security protocols, managing authorization packages, and advising on security posture for Army and Navy organizations.
Highest-signal resume keywords- Active TS Security Clearance
- DoD 8140/8570 Baseline Certification
- 5+ Years Supporting Army/Navy Customers
- Advanced Experience with eMASS
- Hands-On Experience with RMF Lifecycle
- NIST SP 800-53 Rev. 5
- ACAS Vulnerability Assessment
- Nessus Vulnerability Assessment
- SCAP Compliance Checker
- DISA STIG Implementation
- POA&M Drafting and Tracking
- System Hardening
- Dev Sec Ops Integration
- SAST/DAST Tools
- Cloud Security
- Negotiation
- Risk Management
- Incident Response Coordination
- Advisory Communication
- CompTIA Security+
- SecurityX
- Cloud+
- GSEC
- CISSP
- CISM
- GCSA
- GCIA
- CISA
- CCSP
- Cybersecurity
- Risk Management Framework (RMF)
- Continuous Monitoring
- Authorization to Operate (ATO)
- Army/Navy Compliance
- EMASS
- DISA STIGs
- CIS Benchmarks
- Containerized Environments
- Cloud Architectures
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×