Information Systems Security Manager

Merlin International Inc•McLean, VA
•Onsite

About The Position

We are looking for an Information System Security Manager (ISSM) to own the day-to-day security compliance and continuous monitoring activity that keeps our FedRAMP authorization current. You will coordinate access authorization, vulnerability scanning, POA&M management, change control, and the recurring compliance calendar, while tracking changes to the FedRAMP program itself. The role is as much about people as process: you will explain security and compliance requirements to customers, including ones who are frustrated or under pressure, and raise risks to leadership early, clearly, and in writing.

Requirements

  • 5+ years as an ISSM working directly with Cloud Service Providers (CSPs) in FedRAMP authorized environments
  • Direct, hands-on experience with FedRAMP Rev 5, 20x, and CR26 requirements, and the ability to translate controls into actionable items for engineering and SOC teams
  • Hands-on knowledge of vulnerability management, POA&M processes, and change control in a regulated environment
  • Strong organizational discipline across a large recurring compliance calendar, with deadlines held rather than dropped
  • Sound judgment on when to raise risks, escalating early instead of after issues become critical
  • Ability to work across technical, customer, and leadership audiences, including calm, plain-language communication with frustrated customers

Nice To Haves

  • Experience taking CSPs through the FedRAMP Authorization to Operate (ATO) process
  • Project management experience or certification (PMP, CSM, or equivalent)
  • CISSP certification

Responsibilities

  • Coordinate access authorization for the environment, keeping requests, approvals, and quarterly access reviews tracked and current
  • Maintain the Plan of Action and Milestones (POA&M) with current status, owners, and due dates, and coordinate remediation plans with the teams closing findings
  • Perform vulnerability scanning, analyze results, and produce reporting for stakeholders and leadership
  • Manage the Change Control Board (CCB) as concierge for change requests, and populate Security Impact Assessments (SIAs) for proposed changes
  • Coordinate significant change requests through the required review and approval process
  • Track the recurring compliance calendar, including the Incident Response and Contingency Plan (IRCP), contingency plan testing, quarterly access reviews, and Rules of Behavior (ROB) management
  • Coordinate Software Bill of Materials (SBOM) submissions with the teams that own them and keep reviews on schedule
  • Manage the Learning Management System (LMS) for security awareness training, tracking completion and following up on gaps
  • Monitor changes to the FedRAMP program, including Rev 5, 20x, CR26, and other RFCs, and assess their impact on the environment
  • Explain security and compliance requirements clearly to customers and stakeholders, including in difficult or high-pressure conversations
  • Report risks to leadership early, before they become critical, with enough detail to support a decision
  • Apply project management discipline throughout: sequencing work, tracking status, and keeping owners and deadlines visible

Benefits

  • medical insurance
  • dental insurance
  • vision insurance
  • FSA
  • EAP
  • 401(k) with employer match
  • unlimited PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service