
Information System Security Manager (ISSM) / Task Lead – Cyber Ops V
- United States Air Force Academy, CO
- $125,000-140,000 per year
- Permanent
- Full-time
- Serve as the senior cybersecurity lead responsible for the development, implementation, and oversight of the organization's cybersecurity program, including architecture, policy, objectives, procedures, and workforce development in accordance with AFI 17-101, AFI 17-130, and DoDI 8510.01.
- Provide strategic direction and leadership to the RMF team (ISSO, ISSE, SCAR, A&A Assessor), ensuring compliance with DoD 8140.03 workforce role separation and USAFA cybersecurity standards.
- Act as the primary point of contact with the Government, COR, and Authorizing Officials, managing communication, deliverables, schedules, risks, and contract compliance.
- Lead the creation and ongoing refinement of the System Security Plan (SSP), including tailoring and implementation of controls from NIST SP 800-53 Rev. 5 and baselines defined in FIPS 200.
- Oversee the selection, documentation, and management of security control implementation, ensuring that each control includes a functional description of inputs, behavior, and outputs as reflected in the SSP.
- Direct and support development of all RMF artifacts including POA&Ms, Security Assessment Reports (SARs), Risk Acceptance Packages, and continuous monitoring artifacts).
- Manage the complete Authorization to Operate (ATO) package lifecycle, including development of the POA&M tracker, Risk Acceptance Recommendation Report, residual risk statement, and briefing materials for AO presentation and decision-making.
- Coordinate incident response escalation and network access control oversight, including review and documentation of account provisioning processes and procedures in alignment with the IR Plan.
- Provide RMF-related planning and execution guidance at the organizational, mission, business process, and system levels to ensure risk-informed governance and control applicability.
- Monitor compliance with USAFA policies, DoD instructions, and federal cybersecurity mandates while identifying opportunities for control optimization and continuous improvement across systems and programs.
- This is an onsite position that requires work to be performed onsite in Colorado Springs, CO.
- Indoor office working conditions.
- Must be able to sit or stand for prolonged periods.
- Must be able to perform repetitive keyboard tasks and associated motions for prolonged periods.
- Must be able to carry up to 10 pounds.
- $125,000 -- $140,000 (annual) depending on qualifications
- CERTIFICATION: CISM or CISSO or FITSP-M or GCIA or GCSA or GCIH or GSLC or GICSP or CISSP-ISSMP or CISSP.
- REQUIED EDUCATION: Bachelor of Science degree in Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science, from an Accreditation Board for Engineering and Technology (ABET) accredited or Certified Association Executive (CAE) designated institution.
- EXPERIENCE: At least five years of experience in Information System Security Management required. Additional experience in the United States Air Force (USAF) environment is preferred. Must be familiar with NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, FIPS 199/200, FedRAMP, AFI 17-101, DoDI 8510.01, and eMASS workflows.
- SECURITY CLEARANCE: Must hold an active Secret security clearance
- Health insurance
- Dental/Vision insurance
- Paid Time Off
- Short- and Long-Term Disability
- Life insurance
- 401k and match
Loyal: Shows firm and constant support to a cause
Enthusiastic: Shows intense and eager enjoyment and interest
Detail Oriented: Capable of carrying out a given task with all details necessary to get the task done well
Dedicated: Devoted to a task or purpose with loyalty or integrityMotivation : Ability to Make an Impact: Inspired to perform well by the ability to contribute to the success of a project or the organizationEducation : BachelorsExperience : 5 years: At least five years of experience in Information System Security Management required. Additional experience in the United States Air Force (USAF) environment is preferred. Must be familiar with NIST SP 800-37 Rev. 2, SP 800-53 Rev. 5, FIPS 199/200, FedRAMP, AFI 17-101, DoDI 8510.01, and eMASS workflows.