Logistics Management Institute

Information System Security Manager (ISSM)

Logistics Management Institute • $110K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
  • 8+ years of experience in cybersecurity, information assurance, or Risk Management Framework, particularly in classified settings.
  • Proven experience leading security authorization for complex systems, including multi-enclave or interconnected environments.
  • In-depth knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253, alongside federal and defense security requirements.
  • Hands-on experience developing security plans, conducting assessments, and managing authorization packages in various settings.
  • Experience in advising stakeholders on cybersecurity risks and working within SCIF environments.

Responsibilities

  • Lead implementation of Risk Management Framework across system lifecycles, ensuring effective categorization and monitoring.
  • Develop security authorization strategies for both classified and unclassified systems and interconnected capabilities.
  • Coordinate various security documentation, including system security plans, assessment packages, and monitoring artifacts.
  • Interpret and apply relevant cybersecurity guidelines and frameworks to ensure compliance and operational effectiveness.
  • Advise on cyber risks and control gaps, setting remediation priorities with mission and security considerations in mind.
  • Integrate security practices into all phases of system architecture and operations for optimized security compliance.
  • Oversee the monitoring of vulnerabilities and manage compliance, prioritizing responsive actions based on risk assessments.

Benefits

  • Opportunity to work in a fast-paced, milestone-driven environment with direct impact on organizational security posture.
  • Engagement with diverse teams, including government stakeholders and technical experts.
  • Travel opportunities across multiple program locations, enhancing professional network and exposure.
  • Immediate availability for unclassified planning work, allowing for quick onboarding and contribution.
Full Job Description
Overview

LMI is seeking a skilled Information System Security Manager (ISSM) to assist the Lead Cybersecurity Integrator to lead security authorization, governance, and continuous monitoring for enterprise IT capabilities across new and existing secure facilities. The ISSM will coordinate with system owners, engineers, security officers, cybersecurity personnel, and government stakeholders to ensure systems are designed, documented, authorized, operated, and sustained in accordance with security requirements. This is an execution-oriented role supporting a fast-paced, milestone-driven prototype effort with near-term deliverable commitments. Success requires risk-based judgment, rigorous Risk Management Framework execution, clear communication, and the ability to balance mission, security, operational risk, and delivery timelines. 

Primary duties include: 

  • Lead Risk Management Framework implementation across the system lifecycle, including categorization, control selection and tailoring, implementation, assessment, authorization, and continuous monitoring. 
  • Develop security authorization strategies and roadmaps for classified and unclassified systems, multi-enclave environments, and interconnected capabilities. 
  • Coordinate system security plans, implementation evidence, plans of action and milestones, assessment packages, authorization decisions, and monitoring artifacts. 
  • Interpret and apply NIST SP 800-37, NIST SP 800-53, CNSSI 1253, defense and intelligence guidance, customer policies, and program requirements. 
  • Advise the Lead Cybersecurity Integrator, system owners, the Chief Engineer, program leadership, and technical teams on cyber risk, control gaps, remediation priorities, and risk acceptance. 
  • Integrate security requirements into architecture, engineering, acquisition, change management, testing, deployment, operations, and sustainment. 
  • Oversee vulnerability, configuration, and compliance monitoring; prioritize remediation based on exploitability, mission impact, exposure, and operational consequence. 
  • Coordinate assessors, authorizing officials, security officers, engineers, operators, and stakeholders through reviews, audits, incidents, and authorization milestones. 
  • Automate evidence collection, control validation, reporting, plan-of-action tracking, and monitoring while preserving auditability and human oversight. 

Foundational Skills 

  • Risk Management Framework and security authorization lifecycle principles. 
  • NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and federal, defense, and intelligence security-control frameworks. 
  • System security plans, control traceability, evidence, assessments, plans of action and milestones, and authorization packages. 
  • Risk assessment, security-control tailoring, compensating controls, residual risk, and risk acceptance. 
  • Continuous monitoring, vulnerability management, secure configuration, patching, and compliance assessment. 
  • Systems, networking, cloud, identity, application, data, and operational-security fundamentals. 
  • Zero-trust, least-privilege, defense-in-depth, segmentation, and secure-boundary principles. 
  • Configuration, change, incident, problem, and technology-lifecycle management. 
  • Security automation, metrics, technical writing, briefings, and stakeholder coordination. 

Location: This position is based in the Washington, DC metro area, with travel to program locations. 

Travel: This position requires approximately 25-50% travel to support activities across multiple program locations. 

Availability: Immediate availability strongly preferred; unclassified planning work may begin while program access nominations are processed. 

Qualifications

Required: 

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field. 
  • 8+ years of cybersecurity, information assurance, security authorization, or Risk Management Framework experience, including in classified environments. 
  • Experience leading security authorization for complex enterprise, interconnected, or multi-enclave systems. 
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and federal, defense, or intelligence security requirements. 
  • Experience developing or reviewing system security plans, control evidence, assessments, plans of action and milestones, authorization packages, and monitoring deliverables. 
  • Experience supporting SCIF or other accredited classified environments and advising system owners and program leaders on cybersecurity risk. 
  • Ability to coordinate technical and nontechnical stakeholders and communicate security status, risk, remediation priorities, and authorization decisions. 

Nice to Have: 

  • Relevant advanced cybersecurity, information-assurance, or risk-management certification. 
  • Experience authorizing or integrating cross-domain solutions (CDS) and controlled interfaces. 
  • Experience supporting Special Access Program (SAP) facilities, systems, or environments. 
  • Experience supporting network or security operations centers (NOC/SOC), continuous monitoring, and 24x7 incident-response environments. 
  • Experience with security automation, governance-risk-and-compliance workflows, or continuous control validation. 

 

Target salary range: $110,000.00 - $180,000.00. Final compensation will be determined by a variety of factors including but not limited to your skills, experience, education, and/or certifications.

 

Job LocationsUS-DC-Washington, DC

About Logistics Management Institute

Logistics Management Institute (LMI) is a consulting firm dedicated to improving the management of government. LMI provides leaders with the objective analysis, tools, and programs they need to make informed decisions for their organizations. LMI is a not-for-profit organization that has been providing innovative solutions to complex problems since 1961. LMI serves clients in the federal government, state and local governments, and the private sector.
Learn more about Logistics Management Institute
Size
1,700 employees
Industry

Similar Jobs

More Jobs at Logistics Management Institute

More Information Technology Jobs

Find similar Information System Security Manager (ISSM) jobs: