Information System Security Manager (ISSM)
@ Delta Solutions & StrategiesInformation System Security Manager (ISSM)
About the job
Delta Solutions & Strategies provides cybersecurity and compliance services for classified systems, focusing on RMF, NIST, DCSA standards, and supporting DoD security requirements.
Requirements
- Experience with cybersecurity in federal environment
- Familiarity with RMF processes
- Knowledge of NIST 800-53 controls
- Active DoD Top Secret clearance
- Hands-on with eMASS or similar systems
Qualifications
- U.S
- citizenship
- Security clearance required
- Experience developing security documentation
- Knowledge of DCSA, NISPOM requirements
Full job description
Delta Solutions & Strategies, LLC is seeking an experienced Information System Security Manager (ISSM) to manage and oversee the cybersecurity and compliance requirements for Delta's classified information systems.
The ISSM serves as the principal advisor for the security of classified information systems and is responsible for maintaining the overall security posture of systems under their purview. This position leads Risk Management Framework (RMF) implementation, system authorization and continuous monitoring activities, and ensures classified systems remain compliant with applicable DCSA, NISPOM, NIST, and cybersecurity requirements.
The ISSM works closely with Delta's Facility Security Officer (FSO), IT personnel, system administrators, users, company leadership, and government security representatives to ensure classified information systems remain secure, compliant, authorized, and operational.
What you will be doing:
- Serve as the Information System Security Manager (ISSM) for Delta's classified information systems.
- Maintain and manage Risk Management Framework (RMF) authorization packages and ongoing system security documentation.
- Manage eMASS documentation, controls, artifacts, POA&Ms, continuous monitoring activities, CCIs, and authorization-related submissions.
- Coordinate with DCSA, ISSP, SCA, and other government personnel regarding system authorization, assessments, inspections, system changes, and compliance activities.
- Ensure applicable NIST SP 800-53 security controls are implemented, documented, maintained, and supported with appropriate evidence.
- Manage system changes through applicable RMF and change-management processes and identify when security documentation or authorization updates are required.
- Maintain System Security Plans, procedures, system diagrams, hardware and software inventories, interconnection documentation, and supporting cybersecurity records.
- Oversee vulnerability management, patching, configuration management, audit logging, account management, incident response, and continuous monitoring activities for classified systems.
- Identify, track, and coordinate remediation of cybersecurity vulnerabilities, findings, and deficiencies.
- Maintain POA&M documentation and track corrective actions through completion.
- Support cybersecurity inspections, assessments, authorization activities, and government validation events.
- Coordinate with IT personnel and system administrators to ensure technical changes affecting classified systems comply with applicable security requirements.
- Coordinate with the FSO and security personnel on matters involving classified information systems and cybersecurity compliance.
- Review user and privileged access requirements and ensure access is properly authorized and documented.
- Support cybersecurity incident reporting, investigation, remediation, and required documentation.
- Maintain awareness of applicable DCSA, NISPOM, RMF, NIST, and other cybersecurity requirements.
- Update system documentation and security practices as requirements or system configurations change.
- Provide cybersecurity status, findings, risks, and remediation updates to leadership as requested.
- Provide guidance and training to users and system administrators regarding classified system security requirements.
- Perform other cybersecurity and information system security duties as assigned.
What you will need:
- U.S. citizenship.
- Active DoD Top Secret security clearance.
- Experience supporting cybersecurity, information assurance, or information system security within a classified DoD or federal contracting environment.
- Familiarity with CMMC L2 practices/domains, and evidence collection.
- Working knowledge of the Risk Management Framework (RMF) and information system authorization processes.
- Experience developing or maintaining RMF authorization documentation and security control evidence.
- Experience with eMASS or comparable government authorization systems.
- Hands-on experience implementing and maintaining NIST 800-171 controls.
- Knowledge of NIST SP 800-53 security controls.
- Experience developing and maintaining SSPs.
- Hands-on experience with the Microsoft Security Stack.
- Endpoint protection, logging, patching, monitoring, and vulnerability management.
- Network security, firewalls, VPNs, etc.
- Familiarity with GCC High / IL4+ Level impact environments.
- Knowledge of DCSA cybersecurity requirements and the National Industrial Security Program Operating Manual (NISPOM).
- Experience with vulnerability management, system hardening, patching, configuration management, auditing, access control, and continuous monitoring.
- Ability to interpret system architectures, network diagrams, hardware and software configurations, and technical security controls.
- Strong written communication, documentation, and organizational skills.
Preferred Qualifications:
- Previous experience serving as an ISSM, ISSO, ISSE, or similar information system security role.
- Experience supporting DCSA-authorized classified information systems.
- Experience preparing systems for DCSA assessments, inspections, or authorization activities.
- Familiarity with DISA STIGs and other system hardening requirements.
- Experience with Windows environments, Active Directory, networking, endpoint security, vulnerability scanning, and logging technologies.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline, or equivalent professional experience.
- Relevant cybersecurity certification such as CISSP, CISM, CASP+, Security+, or comparable certification.
Delta Solutions & Strategies offers a generous benefits package to include medical, dental, vision, life insurance, 401(k), PTO, paid holidays, parental, military, and jury duty paid leaves.
In compliance with Colorado’s Equal Pay for Equal Work Act, the salary range for this position is $115,000-$135,000. Please note that the salary information is a general guideline only. Delta Solutions & Strategies considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer.
Similar jobs in Colorado Springs, CO
- G
Information Systems Security Officer (ISSO) II
GD Information Technology, Inc. · Colorado Springs, CO
Posted 2 weeks ago - 0
Senior Information Systems Security Officer (ISSO)
019 Parsons Technical Services, Inc. · Colorado Springs, CO
Posted 3 weeks ago - 0
Staff Information Systems Project Manager
0090 CORP-Corporate Office · Colorado Springs, CO
Posted 2 weeks ago - T
Systems Engineering Manager (Systems Engineering Management)
The Boeing Company · Colorado Springs, CO
Posted 1 day ago - G
Information Technology/Assurance (IT/IA) Specialist I (24/7)
GD Information Technology, Inc. · Colorado Springs, CO
Posted 4 days ago - 0
Electronics Engineering Manager – Radar & Ground-Based Systems
0090 CORP-Corporate Office · Colorado Springs, CO
Posted 2 weeks ago