Information Systems Security Manager

Merlin Cyber

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years as an ISSM in FedRAMP authorized environments with Cloud Service Providers (CSPs)
  • Hands-on expertise with FedRAMP Rev 5, 20x, and CR26 requirements
  • Experience in vulnerability management, POA&M processes, and change control
  • Strong organizational skills for managing a recurring compliance calendar
  • Strong judgment for early risk escalation and communication
  • Ability to engage with technical, customer, and leadership audiences effectively

Responsibilities

  • Coordinate access authorization, maintaining accuracy in requests and quarterly reviews
  • Maintain and manage the Plan of Action and Milestones (POA&M) for findings
  • Conduct vulnerability scans, analyzing results and reporting to stakeholders
  • Oversee the Change Control Board (CCB) for managing change requests
  • Track compliance-related calendar events like incident response and contingency plan testing
  • Facilitate Software Bill of Materials (SBOM) submissions
  • Manage Learning Management System (LMS) for security training and track completion

Benefits

  • Dynamic and collegial work environment
  • On-site gym access and wellness package
  • Comprehensive medical, dental, and vision insurance
  • 401(k) with employer match
  • Unlimited PTO to promote work-life balance
Full Job Description
The Opportunity

We are looking for an Information System Security Manager (ISSM) to own the day-to-day security compliance and continuous monitoring activity that keeps our FedRAMP authorization current. You will coordinate access authorization, vulnerability scanning, POA&M management, change control, and the recurring compliance calendar, while tracking changes to the FedRAMP program itself. The role is as much about people as process: you will explain security and compliance requirements to customers, including ones who are frustrated or under pressure, and raise risks to leadership early, clearly, and in writing.

Primary Duties & Responsibilities

  • Coordinate access authorization for the environment, keeping requests, approvals, and quarterly access reviews tracked and current
  • Maintain the Plan of Action and Milestones (POA&M) with current status, owners, and due dates, and coordinate remediation plans with the teams closing findings
  • Perform vulnerability scanning, analyze results, and produce reporting for stakeholders and leadership
  • Manage the Change Control Board (CCB) as concierge for change requests, and populate Security Impact Assessments (SIAs) for proposed changes
  • Coordinate significant change requests through the required review and approval process
  • Track the recurring compliance calendar, including the Incident Response and Contingency Plan (IRCP), contingency plan testing, quarterly access reviews, and Rules of Behavior (ROB) management
  • Coordinate Software Bill of Materials (SBOM) submissions with the teams that own them and keep reviews on schedule
  • Manage the Learning Management System (LMS) for security awareness training, tracking completion and following up on gaps
  • Monitor changes to the FedRAMP program, including Rev 5, 20x, CR26, and other RFCs, and assess their impact on the environment
  • Explain security and compliance requirements clearly to customers and stakeholders, including in difficult or high-pressure conversations
  • Report risks to leadership early, before they become critical, with enough detail to support a decision
  • Apply project management discipline throughout: sequencing work, tracking status, and keeping owners and deadlines visible


Qualifications

  • 5+ years as an ISSM working directly with Cloud Service Providers (CSPs) in FedRAMP authorized environments
  • Direct, hands-on experience with FedRAMP Rev 5, 20x, and CR26 requirements, and the ability to translate controls into actionable items for engineering and SOC teams
  • Hands-on knowledge of vulnerability management, POA&M processes, and change control in a regulated environment
  • Strong organizational discipline across a large recurring compliance calendar, with deadlines held rather than dropped
  • Sound judgment on when to raise risks, escalating early instead of after issues become critical
  • Ability to work across technical, customer, and leadership audiences, including calm, plain-language communication with frustrated customers


Preferred Qualifications

  • Experience taking CSPs through the FedRAMP Authorization to Operate (ATO) process
  • Project management experience or certification (PMP, CSM, or equivalent) CISSP certification


Success Attributes

  • Commitment to personal and professional integrity and respect for others.
  • Roll-up-your-sleeves attitude and low-ego approach.
  • Commitment to teamwork and professional relationship development.
  • Passion for lifelong learning, growth, and development.
  • Flexible and nimble; comfortable with ambiguity and rapid change.
  • Strong communication and functional project management skills.
  • Desire to innovate, try new things, and creatively explore novel solutions to business challenges.
  • Professional and respectful approach to the diversity of thought, action, identity, and attributes.


Benefits & Perks

We want to empower and inspire employees to be and do their best. Our workdays are dynamic, collegial, and fun. Our office features multiple places to work unconstrained by typical office barriers. Our wellness package provides access to an on-site gym and includes medical, dental, and vision insurance along with options for FSA and EAP. We offer 401(k) with employer match, unlimited PTO, and a culture respectful of the reality that not everything in one's personal life is guaranteed to happen only after hours.

www.themerlingroup.com

Similar Jobs

More Jobs at Merlin Cyber

More Information Technology Jobs

Find similar Information Systems Security Manager jobs: