Information System Security Manager

General Dynamics Information Technology, Inc.

$81K — $110K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a related field or equivalent work experience
  • 2+ years experience as ISSO/ISSM
  • Strong understanding of NIST SP 800-53 and DoD cybersecurity requirements
  • Familiarity with Windows and Linux environments
  • Active Top Secret security clearance required

Responsibilities

  • Conduct comprehensive security audits and RMF control assessments
  • Review and improve security documentation and artifacts
  • Develop and oversee information system security policies
  • Evaluate system security controls for effectiveness and compliance
  • Collaborate with security personnel and technical teams to analyze findings
  • Analyze system changes and vulnerability data for risk assessment
  • Support ongoing ATO and SAP authorization maintenance
  • Prepare risk-focused briefings for stakeholders

Benefits

  • Variety of medical, dental, and vision plan options
  • 401(k) with company matching contributions
  • Flexible work weeks and paid time off
  • Short and long-term disability benefits
  • Life and accident insurance options
Full Job Description
Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
DISA STIG, NIST Risk Management Framework, Operations Security
Certifications:
None
Experience:
2 + years of related experience
US Citizenship Required:
Yes

Job Description:

Help safeguard critical government systems by applying your hands-on ISSM/ISSO experience to security governance, risk evaluation, and compliance oversight. As an IT and Cyber Risk Auditor at GDIT, you will leverage your background managing RMF controls, system documentation, and continuous monitoring activities to deliver thorough, accurate, and mission-focused security assessments.

This role is ideal for cybersecurity professionals who have previously served as an ISSM or ISSO and are seeking to transition into a dedicated risk, audit, and compliance position where they can influence security posture across multiple systems and programs.

MEANINGFUL WORK AND PERSONAL IMPACT

As an IT and Cyber Risk Auditor, the work you do at GDIT will have a direct and measurable impact on our customer's mission. You'll help ensure the integrity, security, and compliance of their IT systems by identifying potential risks, validating critical controls, and supporting continuous improvement efforts. Your work will enhance operational resilience and enable the customer to execute their mission with confidence.
• Conduct comprehensive security audits and RMF control assessments in accordance with DCSA, JSIG, and SAP security requirements, leveraging prior ISSO/ISSM experience.
• Review, validate, and improve security documentation and artifacts such as SSPs, POA&Ms, Continuous Monitoring outputs, and other evidence required by RMF and DCSA assessment standards.
• Develop, implement, and oversee operational information system security policies and guidelines aligned with the Risk Management Framework (RMF), JSIG, and applicable DCSA directives.
• Evaluate system security controls for effectiveness, completeness, and compliance with NIST SP 800-53, DCSA/DoW requirements, JSIG standards, and internal organizational policies.
• Collaborate with ISSOs, ISSMs, SAP security personnel, and technical teams to analyze findings, recommend remediation actions, and ensure timely correction of identified vulnerabilities.
• Analyze system changes, configuration updates, and vulnerability data to determine authorization impacts, risk-level changes, and required updates under RMF and JSIG/SAP processes.
• Support ongoing ATO and SAP authorization maintenance by tracking assessments, evidence submissions, and documentation required throughout the RMF and JSIG lifecycles.
• Prepare and deliver clear, risk-focused briefings to system owners, DCSA assessors, SAP authorities, and other stakeholders regarding compliance status, audit results, and security-related decisions.

WHAT YOU'LL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The IT and Cyber Risk Auditor must have:
• Education: Bachelors degree
• Experience: 2+ years of related experience as a prior ISSO/ISSM. In lieu of degree, additional 4+ years of work experience/training/education will be required
• Certifications: IAT II (Security +, SSCP, CCNA Security)
• Technical skills: Strong understanding of NIST SP 800-53, DoW cybersecurity requirements, and control implementation/assessment practices. Familiarity with Windows/Linux environments, vulnerability tools, and security baselines.
• Prior SAP experience desired
• Security clearance: Must have an active Top Secret clearance in order to be considered, and the ability to obtain and maintain TS/SCI clearance.
• US citizenship required
• Role requirements: Onsite, 5 days/week in Falls Church, VA office location

The likely salary range for this position is $81,349 - $110,055. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
Less than 10%

Telecommuting Options:
Onsite

Work Location:
USA VA Falls Church

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Aerospace & Defense Jobs

Find similar Information System Security Manager jobs: