Information System Security Manager (req-294)
cathexis
Team CATHEXIS elevates the government contracting experience through rapid response, deep skill, and thoughtful problem-solving and communication. Our core capabilities are our top-tier program and project management, data analytics, and audit services, the backbone of which is our integrated approach to operational excellence. You worked hard to get to where you are. You strive to make every day better than the day before.
So do we. Team CATHEXIS operates with an all-in mindset. We are working together to create a company that supports our shared values and individual goals. Our values are centered around leading with integrity, owning the outcome, growing together, and moving with purpose in everything we do for our employees, customers, partners, and communities. We believe success is best when we listen and lead with empathy; model high standards of ethics to provide a rewarding candidate experience; work hard, have fun, and appreciate the strengths we all bring to the team; and empower our employees to create innovative and trusted results.
We are looking for a dynamic Information System Security Manager to join our team! The Information System Security Manager (ISSM) serves as the principal advisor to the Authorizing Official (AO) and program leadership on all matters, technical and otherwise, involving the security of assigned information systems. The ISSM is responsible for the development, implementation, and maintenance of the agency's information security program in accordance with the Risk Management Framework (RMF), NIST SP 800-series guidance, and applicable federal and agency-specific security policies.
This role oversees a team of Information System Security Officers (ISSOs) and serves as the primary point of contact for security authorization, continuous monitoring, and incident response activities. Responsibilities Serve as the principal advisor to the Authorizing Official (AO) and Information System Owner on the security of assigned information systems Lead and manage the Assessment and Authorization (A&A) process for information systems in accordance with the Risk Management Framework (RMF, NIST SP 800-37), ensuring timely issuance and maintenance of Authorizations to Operate (ATOs) Develop, review, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and other required RMF artifacts Oversee a team of Information System Security Officers (ISSOs), providing guidance on day-to-day security operations and compliance activities Conduct and oversee continuous monitoring activities, including vulnerability scanning, configuration management, and security control assessments, to maintain the security posture of authorized systems Ensure compliance with FISMA, NIST SP 800-53, NIST SP 800-171 (as applicable), CNSSI, and agency-specific cybersecurity policies and directives Coordinate incident response activities and report security incidents to the appropriate agency SOC/CSIRC and leadership in accordance with established procedures Manage risk assessments and communicate residual risk to the AO, providing recommendations for risk acceptance, mitigation, or remediation Ensure personnel supporting assigned systems meet DoD 8570.01-M / DoD 8140 information assurance workforce certification and training requirements Maintain security documentation in agency GRC/eMASS (or equivalent) systems and support periodic audits, Inspector General (IG) reviews, and independent assessments Support the development of security policies, procedures, and standard operating procedures (SOPs) to strengthen the agency's overall security program Requirements Active Secret clearance or higher Minimum 3 years of experience in information systems security, information assurance, or cybersecurity, with direct experience supporting a federal agency Demonstrated experience serving as an ISSM, ISSO, or equivalent security role within the Risk Mana