Information System Security Manager (ISSM) - DAFFM
Listed on 2026-08-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward thinking candidates that have strong experience in operational support and can help take to the next level in a pro-active stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U. S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid Life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
Provide enterprise-level cybersecurity governance and senior advisory support for systems within the DAF Financial Management Authorizing Official boundary.
Duties:- Advise the FM AO, AODR, program offices, and system stakeholders on compliant application of federal, DoD, and Air Force cybersecurity policy.
- Interpret policy and translate it into actionable implementation guidance.
- Oversee full-lifecycle RMF activities across multiple systems.
- Review security-control selection, implementation, validation, and continuous-monitoring status.
- Oversee currency and quality of SSPs, RARs, POA&Ms, assessment records, and related authorization artifacts in eMASS and ITIPS.
- Review enterprise vulnerability trends, overdue remediation, risk exposure, and corrective-action status.
- Provide risk-informed recommendations supporting ATO, ATO with Conditions, or Denial decisions.
- Facilitate resolution of security issues among system owners, program offices, security personnel, and the FM AO.
- Participate in governance forums and brief FM leadership.
- Review high-risk or overdue POA&Ms escalations and recommend leadership action.
- Support FM-level cybersecurity policies, SOPs, templates, checklists, and annual program reviews.
- Coordinate cybersecurity activities with infrastructure, database, application, Cyber Ark, and configuration-management personnel.
- Enterprise or portfolio-level RMF governance involving multiple systems.
- Direct support to an Authorizing Official, AODR, Chief Information Officer, Chief Information Security Officer, or comparable authorization authority.
- eMASS and ITIPS experience. Record both separately; do not treat familiarity with one as proof of the other.
- Review or approval of authorization packages and risk recommendations.
- Development or governance of SSPs, RARs, POA&Ms, control-assessment findings, and continuous-monitoring records.
- Leadership briefings involving authorization status, vulnerability trends, risk acceptance, or overdue remediation.
- Experience coordinating system owners, program managers, assessors, technical teams, and cybersecurity personnel.
- OPTION A (DoD 8750):
Candidate must hold ONE active, verifiable commercial certification from the approved DoD 8570/8140 IAM Level III list below. Please include your certification number and expiration date directly on your resume draft:
- CISSP (or Associate) – Certified Information Systems Security Professional
- CISM – Certified Information Security Manager
- GSLC – GIAC Security Leadership Certification
- CCISO – Certified Chief Information Security Officer
- OR
- OPTION B (DoD 8140):
Candidate must hold a relevant higher-education degree (Master’s or Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or Information Technology) AND demonstrate clear, hands-on professional experience authoring Risk Management Framework (RMF) artifacts (SSPs, RARs, POA&Ms) and utilizing government compliance repositories (eMass / ITIPS).
Anticipated start: September 28, 2026
Primary work location: Ellsworth AFB, South Dakota.…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).