Advisory Information Security Manager
Frontier Technology Inc.
Advisory Information Security Manager
ID: 2026-7066
Category: IT
Type: Regular Full-Time
Location : Location US-AL-Huntsville
Telecommute: No
Clearance Requirements: TS/SCI
Overview
The Information System Security Manager (ISSM) serves as the primary cybersecurity authority and liaison for contractor-designed, built, and supported networks and systems operating within Army and Navy program environments. Working on-site alongside Government Organization ISSMs, Authorizing Official Designated Representatives (AODRs), and Authorizing Officials (AOs), this role is directly responsible for leading systems through the complete Risk Management Framework (RMF) lifecycle-from initial conceptual design to achieving and maintaining Authorization to Operate (ATO) and continuous monitoring.
Aligned with the DoD Cyber Workforce Framework (DCWF) Work Role CS-722, the ISSM ensures that contractor technical solutions comply with all applicable DoD, Army, Navy, and NIST cybersecurity directives, security technical implementation guides (STIGs), and risk thresholds without compromising operational mission requirements.
Beyond government-facing compliance, this position will have the opportunity to act as an internal cybersecurity champion-driving security-by-design, system hardening, and DevSecOps best practices directly into company-developed technology, architectures, and software solutions prior to customer deployment.
Core Objectives & Mission Impact
- Direct Government Engagement: Operates on-site as a trusted advisor and peer to Government ISSMs and cybersecurity leadership, bridging the gap between contractor engineering teams and government accreditation authorities.
- Full RMF Lifecycle Governance: Oversees the creation, defense, and maintenance of comprehensive ATO packages within key government repositories, primarily eMASS (Enterprise Mission Assurance Support Service) and Navy/Army-specific workflow databases.
- Network & System Assurance: Evaluates contractor-designed architecture, software stacks, hardware configurations, and network topologies against DoD baseline security controls (NIST SP 800-53 R5, CNSSI 1253) to identify and mitigate risks early in the systems engineering lifecycle.
- Sustained Compliance & Continuous Monitoring: Establishes robust Continuous Monitoring (ConMon) strategies, managing Plan of Action and Milestones (POA&Ms), vulnerability remediation (ACAS/Nessus scans, STIG compliance), and annual assessment reviews to prevent ATO expiration or authorization revocation.
Responsibilities
- Government RMF Accreditation & ATO Management (Army & Navy Focus)
- On-Site Government Collaboration: Serve as the primary contractor cybersecurity authority operating directly on-site with Army and Navy Organization ISSMs, AODRs, and AOs to facilitate accreditation processes.
- eMASS Package Development & Maintenance: Build, manage, and maintain formal Assessment & Authorization (A&A) packages within eMASS (Enterprise Mission Assurance Support Service) and relevant customer databases, ensuring accurate control allocation and implementation statements.
- Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and technical safeguards.
- Vulnerability & Scan Management: Oversee automated vulnerability assessment tools (ACAS, Nessus, SCAP Compliance Checker), evaluating raw scan results, prioritizing findings, and ensuring required DISA STIGs/SRGs are applied.
- POA&M Ownership: Draft, track, and remediate Plans of Action and Milestones (POA&Ms), negotiating acceptable risk levels and mitigation strategies with government stakeholders.
- Continuous Monitoring (ConMon): Establish and execute ongoing ConMon strategies to maintain authorization boundaries, managing annual security reviews, boundary modification requests, and re-authorization events.
- Internal Cybersecurity Hardening & Product Security
- Shift-Left Security Engineering: Collaborate with internal software, network, and systems engineering teams during early development lifecycle phases to embed cybersecurity requirements into company-developed technology before deployment.
- System Hardening Standards: Develop and enforce internal baseline configuration guides, utilizing DISA STIGs and CIS Benchmarks across company-built hardware appliances, software stacks, and operating environments.
- Architecture & Code Review Oversight: Evaluate internal product architectures and software deliverables for security posture, facilitating static/dynamic code analysis, dependency scanning, and zero-trust alignment.
- Best Practices & Governance: Establish company-internal cybersecurity standard operating procedures (SOPs), hardening checklists, and secure development guidelines to ensure consistency across product lines.
- Incident Management & Cyber Hygiene
- Vulnerability Response: Lead protective and corrective measures upon discovery of critical vulnerabilities or zero-day threats affecting deployed customer networks or company solutions.
- Incident Handling Support: Coordinate with government security leadership and internal teams to report, contain, investigate, and remediate potential security incidents or policy non-compliance.
- Audit & Inspection Readiness: Coordinate and prepare systems for formal government cybersecurity inspections, and internal quality audits.
- Strategic Advisory & Stakeholder Communication
- Leadership Consultation: Advise internal engineering managers and government leadership on security posture, mission risk trade-offs, and emerging cybersecurity threats.
- Technical Interface: Translate complex government compliance requirements (DoDI 8510.01, NIST guidelines) into actionable technical requirements for internal development teams.
Education/Qualifications
Active TS Clearance (TS/SCI preferred)
Must hold a TS security clearance (TS/SCI preferred)
DoD 8140/8570 Baseline Certification (Required):
- Intermediate Level (Minimum): CompTIA Security+, CompTIA SecurityX (formerly CASP+), Cloud+, GSEC, or equivalent
- Advanced Level (Preferred): CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), GCSA, GCIA, or CISSP-ISSMP.
Bachelors in Information Technology, Cybersecurity, Computer Science, Inforamtion Systems, Software Engineering or equivalent +5 years of relevant experience supporting Army or Navy customers in the full RMF lifecycle.
Required Technical & Functional Competencies
- Demonstrated hands‑on experience navigating the complete Risk Management Framework (RMF) lifecycle per DoDI 8510.01, NIST SP 800-53 (Rev. 5), and CNSSI 1253.
- Advanced operational capability using eMASS (Enterprise Mission Assurance Support Service) to build, manage, and defend Assessment & Authorization (A&A) packages for Army and/or Navy customers.
- Experience managing vulnerability assessment tools (ACAS/Nessus, SCAP Compliance Checker), evaluating raw technical scan data, and applying DISA STIGs / SRGs.
- Proven track record drafting, negotiating, and tracking POA&Ms through mitigation to secure ATO, ATO with Conditions, or Interim Authority to Test (IATT).
Internal Product Hardening & DevSecOps
- Solid working knowledge of system hardening standards across operating systems (Linux/Windows), network infrastructure, containerized environments, and cloud architectures.
- Experience embedding cybersecurity requirements into early software/systems engineering workflows (Shift‑Left Security / DevSecOps pipelines).
- Familiarity with static/dynamic application security testing (SAST/DAST) tools and software bill of materials (SBOM) management.
Preferred / Desirable Qualifications
- Direct experience supporting Army (eMASS-Army) or Navy (NAVIFOR / NAVSEA / NAVAIR / SPAWAR) program offices and Authorizing Officials (AOs).
- Specialized certifications in audit, risk management, or cloud security (e.g., CISA, CRISC, CCSP, AWS/Azure Security Specialties).
#LI-EB1
#LI-Onsite
#J-18808-Ljbffr- ...Frontier Technology Inc. seeks an Advisory Information Security Manager to lead RMF lifecycle activities for Army/Navy program environments on site in Huntsville. You will coordinate with government ISSMs, AODRs, and AOs to secure ATOs and maintain continuous monitoring...Suggested
- ...aviation engineering, systems/software engineering, acquisition management, and cybersecurity expertise to the U.S. Army, Air Force,... ...expertise in the various aspects of U.S. Government information security. Expertise includes DISA STIG configuration, Scanning (SCAP...Suggested
$88.4k - $154.7k
...Description:Parsons is looking for an amazingly talentedCyber Security Analyst / Information Systems Security Officer (ISSO) to join our team! In this... ...Missile Defense Systems Engineering (TN-MDSE) contract managed by the Missile Defense Agency (MDA). What You'll Be Doing...SuggestedFull timeContract workFor contractorsWork experience placementInterim roleWork at officeFlexible hours- ...A Veteran-Owned Small Business is seeking a Mid. Intelligence Management Specialist to support federal operations in Huntsville, Alabama... ...directorates, and requires a Bachelor's degree along with a security clearance (TS/SCI with CI Polygraph). The position offers a competitive...Suggested
$95.2k - $142.7k
...Information Systems Security Manager (ISSM Staff III)The Aerospace Corporation is the trusted partner to the nation's space programs, solving the hardest problems and providing unmatched technical expertise. As the operator of a federally funded research and development...SuggestedFull timeImmediate startRemote work- ...seeks a motivated, career and customer-oriented Senior Information System Security Officer (ISSO) to join our team in Huntsville, Alabama .... ...vulnerability scans according to risk assessment parameters Manage the risks to ISs and other FBI assets by coordinating...Work at office
- ...and analyze cyber threats, investigate security breaches, and produce reports to enhance... .... Prepare detailed reports and advisories, including actionable recommendations,... ...care or medical leave status, genetic information, veteran status, marital status, or any...Local area
- ...Warfighter Integration (WFI) team is looking for a cyber security professional that moves at the speed of the mission-not... ...administrative checkpoint. We are seeking an experienced Information Systems Security Manager (ISSM) Lead in Huntsville, Alabama to establish, lead,...
- ...which an employee who has access to the compensation information of other employees or applicants as a part of such employee... ...Yorktown Systems Group, Inc.-Job TitleIT Operations Manager / Information Systems Security Manager (ISSM)LocationHeadquarters, Huntsville, AL -...Contract workFor contractorsWork at office
- General information Requisition # R69397 Locations USA-AL-Huntsville Posting Date 07/21/2026 Security Clearance Required TS/SCI Remote Type Onsite Time Type... ...to the system owner and IS Security Manager (ISSM)Ensure the removal and...Full timeWork at officeLocal areaRemote work
$87.1k - $157.45k
Leidos is seeking a talented Information System Security Officer (ISSO) to join a diverse team to create unique solutions for complex problems.... .... The ISSO will report to the Information System Security Manager (ISSM) on all aspects of classified information system security...Full time$99k - $225k
Information System Security Officer, SeniorThe Opportunity:Work with law enforcement to discover their cyber risks, understand applicablepolicies, and develop a mitigation plan. Review technical, environmental, and personnel details from engineers to assess the entire threat...Full timeContract workPart timeWork at officeLocal areaRemote work- Reference: 85347-369888GENERAL JOB SUMMARY:The Information Systems Security Officer is responsible for the day-to-day operations and support of classified... ...will report to the Information Security Operations Manager/ISSM on all aspects of classified information system...Temporary workLocal areaRemote work
$134.5k - $265.1k
...Summary Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing... .... Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using...Local areaVisa sponsorship- ...Information Systems Security Officer (ISSO)Torch Technologies is seeking a motivated Information Systems Security Officer (ISSO) with a background... ...adhere to enterprise standards such as the Risk Management Framework (RMF), National Institute of Standards and Technology...Contract workTemporary workLocal areaRelocation packageFlexible hours
- ...onsite at our facility in Huntsville, Alabama. You will interface and collaborate with the Information System Security Officers (ISSO) and Information Systems Security Managers (ISSM) to ensure adherence to all NISPOM Chapter 8, DAAPM, JSIG policies.What You Will DoAssisting...InternshipWork at officeRelocation package
$69.55k - $125.73k
...operating within the Digital Sector, is seeking a talented Information System Security Officer (ISSO) to join a diverse team responsible for... ...ISSO role will report to the Information System Security Manager (ISSM) on all aspects of classified information system security...Work at officeLocal areaImmediate startRemote work$86.8k - $198k
...for attribution of CNO activityClearance:Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.CompensationAt Booz Allen, we celebrate your contributions...Full timeContract workPart timeWork at officeLocal areaRemote work- ...will serve as an expert on Cybersecurity, Risk Management Framework (RMF) accreditation, and Application Security.ResponsibilitiesOversee and execute the end-to-... ...degree20 years of experience in cybersecurity, information assurance, or security systems engineering within...Full timeStart working today
$120k - $140k
...Information System Security Officer (ISSO) 2 weeks ago Be among the first 25 applicants Responsibilities Perform verified risk assessments that... ...viewer Monitor and assist with implementing security controls Manage and monitor Plan of Action and Milestones (PO&AMs)...Full timeTemporary workWork experience placement- ...Information System Security Officer (ISSO)Torch Technologies Inc., is seeking a talented Information System Security Officer (ISSO) to support... ...implemented as defined in security plans.Develop, update, and manage Authorization to Operate (ATO) packages. Navigate and...Contract workTemporary workLocal areaRelocation packageFlexible hours
- ...at least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional... ...in DoD Instruction 8570.1 Information Assurance Management (IAM) Level III proficiency. - Possesses at least 7 years...Work experience placement
- ...Job Description Job Description Information Systems Security Officer (ISSO) (Senior)Redstone Arsenal/Huntsville, ALIPT Associates (IPTA) is... ...professionalsHunger to continually learn and growJob Description:Manage classified and unclassified systems through the Assessment...
$115k - $140k
...Description Job Description Dark Wolf is looking for an Information System Security Officer to join a collaborative, dynamic team in a fast-... ...in software development, security engineering, risk management, and compliance. The successful candidate will have strong...For contractorsRemote work$101k - $154k
..., CJ’s, and AO’s - Prepare, submit, and manage export license applications (DSP-5, DSP-... ...submit requests for Commodity Jurisdictions, advisory opinions and general correspondence.... ...:This position requires access to information that is subject to compliance with the International...Permanent employmentFull timeContract workFor contractorsWork experience placementWork at officeRemote work- ...Title : IT Cyber Security Specialist (contingent 034) Journeyman to assess Cooperative... ...Subject matter expert on Cybersecurity/Information Assurance activities based upon a... ...procedures applicable to each CPE IEW&S program management office, HQ staff, and other external...Full timeWork experience placementInterim roleWork at office
$150k - $165k
...the Missile Defense Agency Title: Cyber Security Analyst Program: MDA, C3BM and C2BMC... ...Command, Control, Communications, and Battle Management (C3BM) cyber engineering efforts... ...software and/or hardware to individual information systems and/or enterprise environment....Full timeFor contractorsFor subcontractorWork at officeImmediate start- ...IPT Associates (IPTA) in Huntsville, AL is seeking a seasoned security professional to help protect computer networks and information assets. The role emphasizes planning, implementing, upgrading, and monitoring security measures across our digital infrastructure. Requirements...
- ...of an active Top Secret clearance with Sensitive Compartmented Information (SCI) eligibility to start due to federal contract... ...responsibilities:- Responsible for monitoring computer networks for security issues. - Investigating security breaches and other cybersecurity...Contract workLocal area
- ...contract requirements and organizational needs. Responsibilities Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information May ensure appropriate security controls are in place that will safeguard digital files and vital...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Advisory Information Security Manager. Be the first to apply!
- information technology security engineer Huntsville, AL
- information security Huntsville, AL
- director information security Huntsville, AL
- information security lead Huntsville, AL
- data center security officer Huntsville, AL
- senior information security analyst Huntsville, AL
- sr information security engineer Huntsville, AL
- information technology security engineer
- information security
- data security analyst





