Information System Security Manager (ISSM)
Job Type
Full-time
Description

Job Title:  Information System Security Manager (ISSM)

Place of Performance:  Springfield, VA

Mandatory Requirements: TS/SCI Clearance

Experience Level: Sr Level (8-10+ years)

On-Site, hybrid, remote: On-Site 

Travel:  Minimal / As Required 


About JFL Consulting: With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients. Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit www.jflconsulting.com  


What We Offer:

  • Salary: $155k - $175k
  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms

  

Position Overview

The Information System Security Manager (ISSM) serves as the senior cybersecurity authority and technical subject matter expert (SME) responsible for overseeing and maintaining the security posture, compliance, and risk management of assigned enterprise information systems. The primary responsibility for this role is directing cybersecurity and authorization activities supporting an ongoing program; however, the ISSM will also support other critical defense projects and initiatives as operational needs evolve and related mission partner efforts. Operating under Department of Defense guidelines (DoDI 8500.01 and DoDI 8510.01), the ISSM directs Risk Management Framework (RMF) lifecycle activities, advises Authorizing Officials (AOs) and Security Control Assessors (SCAs), supervises cybersecurity personnel, and collaborates across engineering teams to secure and maintain continuous Authorizations to Operate (ATO). 

 
 

Key Responsibilities

RMF, System Authorization & Governance

  • Lead the implementation, governance, and execution of DoD Risk Management Framework (RMF) policies and lifecycle activities across all assigned networks and systems in accordance with DoDI 8500.01, DoDI 8510.01, and NIST SP 800-53 Rev. 5. 
  • Lead periodic and recurring RMF policy updates and reviews, ensuring organizational security policies, baselines, and implementation standards remain fully aligned with emerging federal and DoD directives. 
  • Serve as the primary cybersecurity technical advisor to the Authorizing Official (AO) and program leadership. 
  • Direct the assembly, review, approval, and maintenance of complete security authorization packages within eMASS, Xacta, or applicable tools, including: 
    • System Security Plans (SSPs) 
    • Security Assessment Reports (SARs) 
    • Plans of Action and Milestones (POA&Ms) 
    • Security Control Traceability Matrices (SCTMs) 
    • Contingency Plans and incident response procedures 
  • Monitor POA&M mitigation actions, ensure compliance timelines are met, and manage residual risks. 
  • Ensure the system and information owner processes, stores, displays, and transmits classified information strictly on authorized systems in compliance with handling and access control mandates commensurate with classification levels. 
  • Maintain an authoritative, centralized repository for all system cybersecurity-related documentation and artifacts. 

Configuration Management & Change Governance

  • Serve as an active voting member of the Configuration Control Board (CCB). 
  • Review and approve all hardware and software changes, deployments, and architectural modifications prior to implementation to evaluate compliance and security posture impacts. 
  • Ensure any cybersecurity-related events or configuration changes that impact the system's security posture are documented and reported to the Security Control Assessor (SCA) and Authorizing Official (AO). 

Continuous Monitoring, Vulnerability Management & Incident Handling

  • Direct and oversee continuous monitoring (ConMon) strategies, annual cybersecurity reviews, and control effectiveness assessments. 
  • Periodically evaluate security control implementations against real-world incidents, exercises, operational evaluations, and external agency inspections. 
  • Oversee vulnerability management and scanning workflows utilizing tools such as ACAS/Tenable Nessus, SCAP, and EvaluateSTIG, driving timely remediation of identified weaknesses. 
  • Coordinate and lead preparations for Security Control Assessments (SCAs), audits, and inspections conducted by internal and external oversight agencies. 
  • Provide leadership and oversight during cybersecurity incidents, coordinating response efforts, risk mitigation strategies, and post-incident corrective actions. 
  • Ensure possible or actual classified data spills or breaches are remediated and processed in accordance with DoD, Service, and local policies. 
  • Develop, coordinate, and execute incident response tabletop exercises (TTXs) to evaluate operational readiness, validate incident handling procedures, and refine contingency plans.

SOP Review, Workforce Compliance & Leadership

  • Review and assess all program Standard Operating Procedures (SOPs) to ensure robust integration of cybersecurity awareness, operational security best practices, and compliance controls. 
  • Supervise, mentor, and direct Information System Security Officers (ISSOs) and Information System Security Engineers (ISSEs), ensuring alignment between security engineering designs and compliance mandates. 
  • Ensure all system users and administrators complete mandatory cybersecurity awareness, role-based training, and certification requirements prior to assuming operational responsibilities. 
Requirements

  

Qualifications & Requirements

Mandatory Requirements

  • Citizenship: U.S. Citizenship required. 
  • Clearance: Active DoD Top Secret / SCI security clearance. 
  • DoD 8140 / 8570 Baseline Certification: Must hold an approved IAM Level III (or Level II) certification upon hire (e.g., CISSP, CISM, CISA, or GSLC). 

Education & Experience

  • Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Computer Engineering, or related technical field; or equivalent relevant experience. 
  • Experience:
    • 7+ years of progressive experience in Information Assurance, Cybersecurity, or IT Security. 
    • At least 3–5 years in a leadership, lead ISSO, or ISSM capacity managing DoD RMF lifecycle packages and authorization efforts. 
    • Experience supervising and leading technical security personnel, including ISSOs and ISSEs.
    • Demonstrable experience supporting Department of Defense (DoD), USSTRATCOM, Intelligence Community (IC), or joint enterprise defense programs. 

Technical Skills & Competencies

  • Comprehensive knowledge of DoD cybersecurity policies and instructions, notably DoDI 8500.01, DoDI 8510.01, and NIST SP 800-53 (Rev. 4 & Rev. 5) baselines. 
  • Proven hands-on proficiency with eMASS and/or Xacta. 
  • Deep understanding of DISA Security Technical Implementation Guides (STIGs), SCAP compliance benchmarks, and ACAS/Nessus vulnerability analysis. 
  • Strong familiarity with Configuration Management principles and Configuration Control Board (CCB) operations. 
  • Proven capability to evaluate system architecture diagrams, data flows, and hardware/software baselines for security authorization compliance. 
  • Experience evaluating operational SOPs and organizational workflows for security awareness and compliance integration. 

Communication & Stakeholder Engagement

  • Exceptional written and verbal communication skills. 
  • Proven ability to distill complex cybersecurity topics, technical architectures, and risk data into clear, actionable executive summaries and briefings stakeholders at all levels.
  • Ability to prioritize competing authorization efforts, manage multiple system baselines simultaneously across distinct project initiatives and produce executive-level cybersecurity briefings and metrics. 
Salary Description
$155,000 - $175,000