About The Position

Applied Research Associates (ARA), Inc. has an immediate need for an early-career Information Systems Security Manager (ISSM) in Raleigh, NC. This role will provide day-to-day cybersecurity oversight for multiple classified information systems, with primary emphasis on a SIPRNet environment connected to the DoDIN and associated contractual cybersecurity requirements. The position is focused on maintaining secure, authorized, and inspection-ready operations across assigned DCSA/DoW environments. The Alternate ISSM will support RMF/ATO maintenance, eMASS administration, continuous monitoring, vulnerability and audit compliance, assessment readiness, and coordination with technical stakeholders while reporting to the Senior ISSM/Cybersecurity Team Manager.

Requirements

  • US Citizen with an active DoD Top Secret clearance; SCI eligibility preferred.
  • Bachelor's (or equivalent) with 5 - 7 yrs. of experience, or a Master's and 3 to 5 yrs. of experience; equivalent directly relevant experience may be considered in leu of degrees.
  • 5+ years of supporting cybersecurity, information assurance, information systems security, or related IT environments, including experience supporting classified Government systems.
  • 2+ years of experience performing ISSM, senior ISSO/IA, or comparable cybersecurity leadership responsibilities.
  • Experience supporting DoD RMF and DCSA authorization processes, with familiarity with DoDM/DoDI directive, NIST SP 800-53 Rev. 4 and Rev. 5, 32 CFR Part 117 (NISPOM), and continuous monitoring requirements.
  • Hands-on experience with eMASS or a comparable Government governance-risk-compliance platform.
  • Experience with vulnerability and configuration-compliance tools and processes such as ACAS/Tenable, STIGs, SCAP, SIEM/log review, patch management, and remediation tracking.
  • Ability to meet DoD 8750/DoD 8140 cybersecurity workforce qualification requirements applicable to the assigned ISSM/IAM work role.
  • Demonstrated ability to communicate technical risk, authorization status, deficiencies, and resource needs to technical staff, program leadership, and Government stakeholders.

Nice To Haves

  • Direct experience supporting SIPRNet or other DoDIN-connected classified environments.
  • Experience preparing for or supporting CORA, security control assessments, DCSA reviews, or comparable Government cybersecurity assessments.
  • Advanced cybersecurity certification or another DoD-approved credential appropriate to the assigned work role.
  • Experience with Splunk or another SIEM, ACAS/Tenable Security Center, Windows and Linux security baselines, virtualization, Active Directory/Group Policy, and network-security technologies.
  • Experience leading or coordinating cross-functional cybersecurity teams that include ISSOs, security engineers, system administrators, and program personnel.

Responsibilities

  • Serve as an Alternate ISSM for assigned classified systems and maintain day-to-day cybersecurity compliance, authorization readiness, and risk visibility.
  • Support Risk Management Framework (RMF) and Authorization to Operate (ATO) lifecycle activities, including system categorization, control implementation and assessment support, authorization package maintenance, and continuous monitoring.
  • Develop, review, and maintain cybersecurity documentation including System Security Plans (SSPs), Security Assessment Plans/Reports, POA&Ms, risk assessments and acceptances, continuous monitoring records, inventory, network diagrams, ports/protocols/services documentation, and supporting evidence.
  • Administer and quality-check eMASS records, control implementation statements, artifacts, assessment results, inherited controls, deficiencies, risk decisions, and authorization documentation.
  • Maintain assessment and inspection readiness; support DCSA, DoW, customer, and other Government cybersecurity reviews, annual self-assessments, and corrective-action activities.
  • Review system changes through configuration/change-control processes, assess security impact, and ensure approved changes are reflected in baselines, inventories, diagrams, and RMF artifacts.
  • Coordinate routine cybersecurity matters with technical teams and other mission partners; elevate significant risk or resource issues to the Senior ISSM.
  • Support development and maintenance of overarching DCSA cybersecurity policies, procedures, templates, and common documentation as assigned by the Senior ISSM.
  • Support incidents, urgent vulnerabilities, emergency patching, outages affecting security controls, and Government-directed cybersecurity actions when required.

Benefits

  • health
  • life & disability
  • retirement
  • flexible spending
  • rewards & recognition
  • work/life balance
  • professional development
  • relocation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service