ISSO Program Manager
Listed on 2026-08-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About Nava
Nava is a consultancy and public benefit corporation working to make government services simple and effective. Since 2015, federal, state, and local agencies have trusted Nava to help solve highly scrutinized technology modernization challenges.
As a client services company, we guide agencies constrained by legacy systems to a future with sharp user experiences built on secure, reliable, fault-tolerant cloud infrastructure. We bill for our time, offering our expertise and problem-solving approach to help our government partners enhance their digital products and services. People are at the heart of our work, from members of the public who rely on benefit programs to government agency staff.
Through human-centered design and modern engineering best practices, we help our government partners understand user needs and deliver on their missions more effectively. This focus gives everyone at Nava the opportunity to do work that is meaningful, impactful, and deeply connected to public good.
Nava is seeking a Senior Program Manager (ISSO) to lead system security, risk management, and infrastructure oversight in support of the Centers for Medicare Medicaid Services (CMS).
In this role, you'll lead Risk Management Framework (RMF) activities, maintain the system's Authorization to Operate (ATO), oversee security controls and risk assessments, support continuous monitoring and incident response, and serve as a trusted advisor to CMS stakeholders on the program's overall security and privacy posture.
The ideal candidate will have a bachelor's degree and at least seven years of relevant experience, with a strong background in the Risk Management Framework (RMF), Authorization to Operate (ATO) management, cybersecurity, and federal compliance. Experience leading security assessments, managing POA Ms, and implementing federal security controls in an operational environment is essential. While Nava and CMS provide onboarding through the ISSO Handbook and ISSO Boot Camp, candidates should bring established experience managing RMF activities and supporting federal information security programs.
Although no specific certification is required under the contract, credentials such as CISSP, CISM, or CompTIA Security+ are highly desirable.
This is an opportunity to take on a highly visible leadership role supporting one of CMS's mission‑critical systems. You'll work closely with engineering teams, program leadership, and federal stakeholders to strengthen the program's security posture while helping deliver secure, reliable digital services that support millions of Americans.
What you'll do- Serve as an ISSO supporting the implementation and ongoing maintenance of information security controls for assigned OEDA systems.
- Provide security engineering support for information systems and services operating within CMS-authorized enterprise platforms, including cloud‑based and managed service environments.
- Provide essential support to th
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).