Information System Security Manager

PeratonWashington, DC
Onsite

About The Position

Peraton is seeking an Information Systems Security Manager to support their customer onsite in Washington D.C. This role is responsible for managing and overseeing the security posture of all information systems, implementing and enforcing security policies, procedures, and best practices to ensure system integrity and confidentiality. The position also involves leading the process of certifying and accrediting information systems in accordance with the Risk Management Framework(s) (RMF) and other applicable government cybersecurity standards, ensuring systems meet required security controls for authorization to operate (ATO). The Information Systems Security Manager will perform risk assessments, vulnerability scans, and security audits, develop and implement mitigation strategies, and ensure compliance with relevant cybersecurity frameworks such as FISMA, NIST SP 800-53, and RMF. They will oversee incident response activities, manage continuous monitoring of information systems, and maintain accurate documentation of security controls and reports. Collaboration with engineering teams, mission planners, IT specialists, and other stakeholders is crucial for integrating cybersecurity into all phases of system lifecycle. The role also includes serving as the point of contact for information security issues, developing training programs for ISSO and ISSE personnel, conducting cybersecurity awareness campaigns, and managing relationships with external vendors and partners to ensure compliance with information assurance requirements.

Requirements

  • Must possess an active Top Secret security clearance with SCI eligibility.
  • Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 16 years of experience in Information Systems security may be considered in lieu of degree.
  • Proven ISSM experience including knowledge of system functions, cybersecurity policies, and technical cybersecurity protection measures.
  • IAM Level III certification required.
  • Experience with A&A package submission.
  • Ability to build and maintain relationships with key stakeholders and high-level management.
  • Strong knowledge of security frameworks, including NIST SP 800-53, FISMA, and RMF.
  • Familiar with Scrum methodologies.
  • Hands-on risk assessment experience that incorporates system/mission requirements and operational constraints.
  • Experience shaping policies and programs for Federal or DoD information security initiatives.
  • Knowledge of NIST guidelines (SP 800-37, 800-53, 800-53A) and proven experience in Security Control Assessment.
  • Advanced written and verbal communication skills to effectively communicate security concepts and policies.
  • Experience is to include at least two (2) of the following areas: knowledge of current security tools, hardware/software security implementation; communication protocols; and encryption techniques/ tools.

Nice To Haves

  • ITILv4 Foundation Certification
  • Splunk experience to enhance your threat detection capabilities.

Responsibilities

  • Manage and oversee the security posture of all information systems.
  • Implement and enforce security policies, procedures, and best practices to ensure system integrity and confidentiality.
  • Lead the process of certifying and accrediting information systems in accordance with the Risk Management Framework(s) (RMF) and other applicable government cybersecurity standards.
  • Ensure systems meet required security controls for authorization to operate (ATO).
  • Perform risk assessments, vulnerability scans, and security audits to identify security risks and weaknesses in information systems.
  • Develop and implement mitigation strategies to address identified risks and ensure ongoing compliance with security standards.
  • Ensure compliance with relevant cybersecurity frameworks, such as FISMA, NIST SP 800-53, and RMF, and ensure all systems supporting operations follow federal and DoD information assurance requirements.
  • Oversee incident response activities related to information security breaches, including root cause analysis, containment, remediation, and reporting.
  • Work with the security team and stakeholders to manage cybersecurity incidents and minimize their impact on operations.
  • Implement and manage continuous monitoring of information systems and networks to detect and respond to potential security threats.
  • Ensure all systems are regularly tested for security vulnerabilities.
  • Maintain accurate and comprehensive documentation of security controls, certifications, accreditation reports, and incident responses.
  • Prepare regular security reports and updates for management and program leadership.
  • Work closely with engineering teams, mission planners, IT specialists, and other stakeholders to integrate cybersecurity into all phases of system design, development, and operations.
  • Serve as the point of contact for information security issues related to information systems.
  • Develop and implement training programs for ISSO and ISSE personnel on information assurance and security best practices.
  • Conduct cybersecurity awareness campaigns to ensure all team members understand their role in protecting sensitive data and systems.
  • Manage relationships with external vendors, contractors, and partners to ensure their systems and operations comply with information assurance requirements for the program.
  • Ensure compliance with protection requirements, control procedures, incident management reporting, remote access requirements, and system management for all systems within the enterprise.
  • Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each IS.
  • Provide liaison support between the system owner, ISSOs, ISSEs, and other IS security personnel.
  • Provides technical and programmatic information assurance services to internal and external customers in support of network and information security systems.
  • Designs, develops, and implements security requirements within an organization’s business processes.
  • Prepares documentation from information obtained from customer using accepted guidelines.
  • Prepares security test and evaluation plans.
  • Provides certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments.
  • Analyzes policies and procedures against Federal laws and regulations and provides recommendations for closing gaps.
  • Recommends system enhancements to improve security deficiencies.
  • Develops, tests, and integrates computer and network security tools.
  • Secures system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration.
  • Conducts security program audits and develops solutions to lessen identified risks.
  • Provides information assurance support for the development and implementation of security architectures to meet new and evolving security requirements.
  • Provides assistance in computer incident investigations.
  • Performs vulnerability assessments including development of risk mitigation strategies.

Benefits

  • Overtime
  • Shift differential
  • Discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service