Information System Security Manager (ISSM)
Leidos
- Location
- Lorton, VA
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 26 approvals (FY2023)
- Posted
- Aug 11, 2026
Skills
About this role
The Defense Sector at Leidos is looking for an Information System Security Manager (ISSM) to support a fast-paced program with the Air Force Life Cycle Management Center. This role involves supporting the delivery of comprehensive IT and support services to ensure mission success while adhering to DoD standards and regulations. The ISSM will oversee the cybersecurity posture of DoD information systems, ensuring compliance with DoD security standards and protecting sensitive data. The ISSM will develop and implement security policies, conduct risk assessments, manage system accreditations (RMF), and lead continuous monitoring efforts. This role requires collaboration with cross-functional teams and program stakeholders to enforce security controls and manage continuous monitoring. The ISSM will also maintain security documentation and ensure ongoing compliance with applicable regulations. This position will require 100% on-site work with no remote work supported.
Primary Responsibilities
Act as the Subject Matter Expert (SME) on cybersecurity compliance / information assurance. Collaborate daily with assigned ISSOs and Cyber Security Engineers to execute the continuous monitoring process with full system observability. Manage the operational cybersecurity posture of assigned networks through coordination with NOC/SOC and Cloud Teams. Facilitate approval process for Authorization to Operate (ATO), Authority to Extend (ATE), Authorization to Connect (ATC), and Interconnection Security Agreements (ISA), working with the customer and stakeholders to submit body of evidence artifacts and receive SCA/AO endorsement. Develop, implement, and maintain security policies, procedures, and documentation to ensure compliance with DoD security standards and regulations (e.g., NIST, RMF, FISMA). Oversee the security posture of DoD information systems, ensuring they meet cybersecurity requirements for confidentiality, integrity, and availability. Perform risk assessments, vulnerability assessments, and security audits to identify system vulnerabilities and provide remediation strategies. Manage and conduct continuous monitoring of security controls, ensuring the protection of classified and unclassified data. Coordinate with cross-functional teams (engineering, IT, operations) to implement and enforce security protocols and best practices. Ensure the accreditation process for DoD systems (e.g., RMF accreditation) is completed and maintained in compliance with all applicable requirements. Act as the primary point of contact for security-related issues, coordinating incident response and reporting to senior management and government customers. Provide security training and awareness programs for personnel involved in the operation of DoD systems. Maintain and track security documentation, including system security plans (SSPs), risk assessments, and Plan of Actions & Milestones (POA&Ms). Stay current with emerging cybersecurity threats, vulnerabilities, and trends to ensure the program adapts to evolving security challenges.
Basic Qualifications
US Citizen with an active Top Secret clearance and the ability to obtain a SCI prior to your start date. Bachelor’s Degree with 8+ years of experience or Master’s degree with 6+ years of experience. Additional experience may be considered in lieu of a degree. CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or similar cybersecurity certification. In-depth knowledge of DoD cybersecurity policies, frameworks, and compliance standards (e.g., NIST 800-53, RMF, FISMA, ICD 503, JSIG). In-depth experience with cloud computing and building/maintaining an ATO for cloud-based information systems Experience with system security engineering, risk management, and vulnerability assessments. Strong understanding of cloud security, network security, security controls, and common cybersecurity tools (e.g., firewalls, IDS/IPS, SIEM, endpoint