Loading...

Innovation. Collaboration. Customer Focus.

ISSM

Position Title: Information System Security Manager (ISSM) III (1Position)

Location: Philadelphia, PA/Hybrid (89% on-site / 11% Remote)

Clearance: ****This position requires an Active Secret Clearance**** 

This position is contingent upon award 

Position Summary

CODEplus is seeking an experienced Information Systems Security Manager III. The successful candidate will play a central role in the development, implementation, and oversight of information security policies, procedures, and systems to ensure the integrity, confidentiality, and availability of mission-critical systems. You will provide strategic leadership for cybersecurity compliance across the program and support certification and accreditation activities in accordance with DoD and NIST frameworks.

Essential Duties & Responsibilities:

  • · Serve as the senior Information Assurance and cybersecurity advisor for assigned systems.
  • Implement and enforce DoD cybersecurity policies and standards in accordance with DFARS 252.239-7001 and Privileged Access Agreement requirements.
  • · Manage cybersecurity strategy, including personnel, infrastructure, security architecture, policy enforcement, risk assessments, emergency response planning, and training.
  • · Oversee the Risk Management Framework (RMF) lifecycle for DoD systems and ensure appropriate security controls are applied and documented.
  • · Coordinate across cross-functional teams and government stakeholders to ensure cybersecurity requirements are met.
  • · Ensure compliance with all applicable DoD cybersecurity directives and standards, including DIACAP/RMF and NIST SP 800-53.
  • · Maintain all documentation necessary for system accreditation and continuous monitoring.
  • · Support site inspections, audits, and cybersecurity reporting activities

Education, Certification & Experience Requirements

Education Required:

  • · Master's degree in computer science, information technology, or an equivalent science, technology, engineering & mathematics (STEM) degree from an accredited college or university.

Certification Required:

  • · Active DoD Secret Clearance or ability to obtain one
  • · IAM-II Certification – One required:
    • CAP
    • CASP+ CE
    • CISM
    • CISSP (or Associate)
    • GSLC
    • CCISO
    • HCISPP

Experience Required:

  • · Eight (8) years of experience coordinating with various levels of an organization to oversee and manage information security program implementation within the organization or other area of responsibility.
    • Must have managed cyber strategy, personnel, infrastructure, policy enforcement, emergency planning, security awareness, and/or other resources.
  • · Prior experience supporting Navy programs (Preferred)

Knowledge, Skills & Abilities:

Knowledge:

  • · Expert knowledge of DoD RMF, NIST SP 800-53, and Navy cybersecurity compliance processes.
  • · Proficiency in eMASS, ACAS, VRAM, and DISA STIG compliance tools.

Skills:

  • · Strong analytical and problem-solving skills with attention to detail.
  • · Excellent communication and interpersonal skills, with the ability to work effectively with a diverse team.

Abilities:

  • · Ability to coordinate across engineering, operations, and program management teams to resolve cybersecurity issues

Working Conditions/Working Environment/Physical Demands:

  • · This position is performed in a professional environment, remote/home office setting, or on-site government facility, as required by the contract.
  • · Standard work schedule is Monday through Friday, during normally scheduled business hours, with occasional evening or weekend work required to meet critical deadlines.
  • · Work involves extensive computer and secure network use, including periods of prolonged sitting, data entry, and screen time.
  • · The role requires working independently with minimal supervision, while also collaborating virtually or in person with CCS teams, subcontractors, and government stakeholders.
  • · Occasional travel may be required for customer meetings, training, or project-related activities.