Information System Security Manager (ISSM) - DAFFM

Chameleon Integrated Services

$100K — $120K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in enterprise/portfolio-level RMF governance across multiple systems.
  • Proven track record supporting key authorization authorities such as AOs or CIOs.
  • Expertise with eMASS and ITIPS; experience with both required separately.
  • Familiarity with developing and governing SSPs, RARs, and POA&Ms.
  • Experience in conducting security briefings regarding risk and remediation statuses.
  • Strong coordination skills among various technical and cybersecurity teams.

Responsibilities

  • Advise stakeholders on federal, DoD, and Air Force cybersecurity policy compliance.
  • Translate cybersecurity policies into actionable implementation guidance.
  • Oversee RMF activities for multiple systems throughout their lifecycles.
  • Review and ensure the quality and currency of security documentation and artifacts.
  • Analyze enterprise vulnerability trends and recommend corrective actions.
  • Facilitate resolution of security issues across system stakeholders.
  • Participate and provide briefings in governance forums for leadership oversight.

Benefits

  • Comprehensive health insurance options, including dental coverage.
  • Fully subsidized vision insurance plan.
  • Generous 401K plan with immediate company matching.
  • 100% company-paid life and long-term disability insurance.
  • Training allowance for professional development.
  • Paid Time Off (PTO) and other benefits.
Full Job Description
We offer a Full Benefits package including:
  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid Life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO and more

Information System Security Manager

Position mission: Provide enterprise-level cybersecurity governance and senior advisory support for systems within the DAF Financial Management Authorizing Official boundary.

Duties:
  • Advise the FM AO, AODR, program offices, and system stakeholders on compliant application of federal, DoD, and Air Force cybersecurity policy.
  • Interpret policy and translate it into actionable implementation guidance.
  • Oversee full-lifecycle RMF activities across multiple systems.
  • Review security-control selection, implementation, validation, and continuous-monitoring status.
  • Oversee currency and quality of SSPs, RARs, POA&Ms, assessment records, and related authorization artifacts in eMASS and ITIPS.
  • Review enterprise vulnerability trends, overdue remediation, risk exposure, and corrective-action status.
  • Provide risk-informed recommendations supporting ATO, ATO with Conditions, or Denial decisions.
  • Facilitate resolution of security issues among system owners, program offices, security personnel, and the FM AO.
  • Participate in governance forums and brief FM leadership.
  • Review high-risk or overdue POA&M escalations and recommend leadership action.
  • Support FM-level cybersecurity policies, SOPs, templates, checklists, and annual program reviews.
  • Coordinate cybersecurity activities with infrastructure, database, application, CyberArk, and configuration-management personnel.
Requirements:
  • Enterprise or portfolio-level RMF governance involving multiple systems.
  • Direct support to an Authorizing Official, AODR, Chief Information Officer, Chief Information Security Officer, or comparable authorization authority.
  • eMASS and ITIPS experience. Record both separately; do not treat familiarity with one as proof of the other.
  • Review or approval of authorization packages and risk recommendations.
  • Development or governance of SSPs, RARs, POA&Ms, control-assessment findings, and continuous-monitoring records.
  • Leadership briefings involving authorization status, vulnerability trends, risk acceptance, or overdue remediation.
  • Experience coordinating system owners, program managers, assessors, technical teams, and cybersecurity personnel.


Mandatory certification:
  • DoD 8570 IAM Level III
  • DoD 8140 work role 722-Advanced

Anticipated start: September 28, 2026

Primary work location: Ellsworth AFB, South Dakota. Occasional work at Wright-Patterson AFB, Ohio.

Work schedule: An eight-hour shift scheduled between 6:00 a.m. and 6:00 p.m. Mountain Time, Monday through Friday. The team must collectively provide overlapping coverage during that window. COOP support may be required, but work will remain within a 40-hour workweek unless the Contracting Officer authorizes otherwise.

Project Length: Up to 4.5 years

Similar Jobs

More Jobs at Chameleon Integrated Services

More Education, Government & Non-Profit Jobs

Find similar Information System Security Manager (ISSM) - DAFFM jobs: