Enterprise Information System Security Manager (ISSM)New
- Location
- Multiple in VA and MD
- Employment type
- Full time
- Posted
- September 17, 2026
Job Description:
ISEA is searching for an experienced and motivated Information System Security Manager (ISSM) to join our growing team. In this role, you will be responsible for managing and executing the Risk Management Framework (RMF) process across the customer’s enterprise, overseeing a portfolio of information systems, and ensuring the consistent application of security requirements throughout the system lifecycle. The ideal candidate possesses the ability to manage complex Body of Evidence (BoE) packages, mentor subordinate ISSMs and ISSOs, and provide risk-based recommendations to the Authorizing Official (AO).
Responsibilities:
• Oversee the RMF process, ensuring all systems within the portfolio maintain a valid Authority to Operate.
• Develop, implement, and monitor the RMF program baseline, ensuring security controls are tailored to meet enterprise and mission-specific requirements.
• Author and enforce enterprise-wise security policies, SOPs, and SSPs that align with ICD 503.
• Conduct high-level risk assessments for complex, interconnected systems, evaluating the impact of system changes on the enterprise security posture.
• Drive the implementation of the customer’s Continuous Monitoring program, utilizing automated tools to track real-time security control effectiveness and vulnerability remediation.
• Oversee the lifecycle of POA&Ms across the portfolio, ensuring technical teams and system owners prioritize high-risk findings.
• Serve as the senior cybersecurity advisor to program managers, system owners, and the customer’s senior leadership regarding risk mitigation strategies.
• Provide guidance, training, and technical oversight to a team of ISSMs and ISSOs, ensuring consistent quality in assessment methodologies and documentation.
• Lead the preparation for and response to external audits and inspections, representing the customer’s security interests.
Qualifications:
• Expert-level knowledge of ICD 503, CNSSI 1253, and NIST Risk Management Framework (NIST SP 800-37, 800-53, 800-137).
• Proficiency with enterprise Governance, Risk, and Compliance (GRC) tools, such as Xacta.
• Comprehensive understanding of enterprise-level architectures, including cloud security, cross-domain solutions (CDS), and global network infrastructures (JWICS, SIPRNet).
• Exceptional ability to articulate technical risks and “move assessments forward” by providing clear, actionable strategies to non-technical senior executives.
• Possess a deep understanding and awareness that “no system is the same,” with the ability to demonstrate an adaptive approach to security rather than a one-size-fits-all compliance checklist.
• A proactive commitment to continuous improvement, seeking out ways to optimize reporting, assessment timelines, and security automation.
Citizenship/Clearance Requirements:
• US Citizenship is required.
• Must be eligible to obtain and maintain a government security clearance.