Systems Planning & Analysis logo
Systems Planning & AnalysisPosted 25 months ago

Information System Security Manager (ISSM)

$180,000–$180,000 year

On-siteLincoln, Massachusetts, United States

Full TimeBachelors DegreeLarge

Job Summary

Lead overall cybersecurity posture, compliance, and accreditation for systems delivered under this contract by driving Risk Management Framework (RMF) activities and coordinating with government security officials on ATO/ATC actions. Define and enforce cybersecurity and cyber-resiliency practices across the development and integration lifecycle, including secure coding standards, vulnerability management, and security training. Maintain security documentation, artifacts, and FISMA-related records while embedding security controls into architectures, pipelines, and test environments. Requires BS in cybersecurity, 8+ years of experience, DoD Secret clearance, and CISSP/CAP/CISM certification. Salary range $180,000–$215,000/year. SPA delivers high-impact technical solutions to US Navy, Marine Corps, USAF, and Australian Defence Force clients.

Required Qualifications

  • BS in cybersecurity, computer science, information assurance, or similar field
  • 8+ years of cybersecurity experience on medium‐to‐large IT or software programs
  • at least 4 years in an ISSM or equivalent leadership role
  • Direct experience implementing DoD RMF (and prior DIACAP) processes
  • experience authoring and maintaining accreditation packages
  • experience with FISMA‐related records
  • Demonstrated experience leading or supporting DISA STIG compliance
  • experience with vulnerability scanning
  • experience with penetration testing
  • testing in NIPR/SIPR and related environments
  • Familiarity with mission planning or similar weapon‐system security contexts
  • support for ATO and ATC activities
  • security targets
  • DoD‐approved cybersecurity certification such as CISSP, CAP, or CISM
  • Active DoD Secret clearance
  • the ability to maintain it throughout employment

Desired Qualifications

  • Master's degree in relevant field
  • experience developing and maintaining enterprise cybersecurity master plans
  • experience developing and maintaining Program Protection Plans
  • experience developing and maintaining anti‐tamper plans
  • experience with related security documentation
  • Familiarity with Air Force cybersecurity policy
  • coordination with AF network and accreditation authorities
  • Background in cyber resiliency for mission or weapon systems
  • experience with secure coding standards
  • experience with security‐focused scenarios
  • experience with user certification requirements
  • Experience integrating security controls into DevSecOps pipelines
  • experience with CDE environments
  • experience with automated compliance
  • experience with security testing
  • Prior experience addressing security considerations for FMS deliveries
  • experience with multi‐national information‐sharing constraints

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce