Senior Manager Information Security

ASRC FederalAberdeen Proving Ground, MD
$140,000 - $180,000Onsite

About The Position

ASRC Federal Technology Solutions LLC is seeking an experienced Information System Security Officer with a minimum of an active Top Secret security clearance to support the DEVCOM-CBC and the Transformation Decision Analysis Center (TDAC) organization. This role serves as the Team's direct manager and is responsible for the development, implementation, and maintenance of cybersecurity policies, standards, and procedures, ensuring compliance with applicable Department of Defense (DoD), Army, and DEVCOM CBC regulations. The position provides cybersecurity support to the DEVCOM-CBC G-6 Cybersecurity Branch, focusing on Risk Management Framework (RMF) activities, cybersecurity assessments, and incident response. It requires a deep understanding of cybersecurity principles, strong analytical abilities, and excellent communication skills to convey complex information to diverse audiences, while managing a broad portfolio of compliance and accounts across various system types.

Requirements

  • Active DoD Top Secret clearance or higher.
  • Bachelor’s degree (BA/BS) in Computer Science, Information Technology, Engineering, or a related field and 8 additional years of experience OR Master’s degree in Computer Science, Information Technology, Engineering, or a related field or 6 additional years of experience OR a total of 12 years of work experience in the field in lieu of degree.
  • 5 or more years of hands-on RMF EMASS Authorization duties.
  • Working knowledge of DoD and Army cybersecurity regulations including Army Regulation 25-2, DoD 8140, and DoD RMF policy.
  • Experience with Active Directory account management and STIG/SRG audit processes.
  • Familiarity with the Army Account Validation System (AVS) or equivalent DoD workforce compliance tracking platforms.
  • DoDI 8140.03 qualification for DCWF Work Role Information Systems Security Manager (722 Advance). Accepted foundational qualifications include certifications mapped to Work Role 722 Advance in the current DoD 8140 Qualification Matrix, such as CISM, CISSP, CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, and GSLC.

Nice To Haves

  • Direct experience with eMASS, POA&M and RMF processes and responsibilities.
  • CISSP or CISM certification.
  • Experience supporting DEVCOM or Army G-6 cybersecurity programs.
  • Personnel management experience.
  • Experience serving as an Enhanced Trusted Agent for PKI hardware token issuance.
  • Experience performing Software Assurance or Hardware Assurance reviews for DoD networks.
  • Familiarity with NSA and Army data sanitization and destruction policy.
  • CISM certification.
  • CISSP certification.
  • CISSP-ISSMP certification.

Responsibilities

  • Maintain current Authority to Operate (ATO) status for DEVCOM systems and provide RMF guidance and support to other DEVCOM/TDAC locations.
  • Develop, update, and/or modify system-level artifacts (e.g., TTPs, plans, policies, procedures, hardware/software lists, data flow, system architecture diagrams, PIAs, Ports/Protocols/Services, MOA/MOU, etc.) and associate them with corresponding controls in eMASS.
  • Obtain, run, analyze, and import vulnerability scanners and compliance checkers (e.g., STIGs, Nessus/ACAS Scans).
  • Track and report IAVAs related to DEVCOM systems.
  • Create, modify, and/or maintain implementation plans and test results as defined by DOD, Army, NETCOM, and DEVCOM requirements.
  • Manage Plans of Action and Milestones (POA&M), including development, status updates, milestone tracking, and closure.
  • Manage assigned network packages within eMASS and maintain accurate authorization documentation.
  • Create, modify, and/or maintain all aspects of CONMON.
  • Utilize or develop custom solutions to facilitate RMF requirements, reduce timelines, and provide up-to-date compliance status reporting.
  • Update and track cybersecurity test results, implementation plans, and risk assessments.
  • Evaluate STIG checklists and document compliance status, deficiencies, and remediation actions.
  • Perform first-response coordination for Negligent Disclosure of Classified Information incidents.
  • Conduct vulnerability management activities, including identifying, tracking, and coordinating corrective actions.
  • Oversee and manage a small team with administrative and personnel duties.
  • Serve as liaison between government and contractor organizations.

Benefits

  • health care
  • dental
  • vision
  • life insurance
  • 401(k)
  • education assistance
  • paid time off
  • PTO
  • holidays
  • any other paid leave required by law
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service