JOBSEARCHER

Information Systems Security Manager

EcsFairfax Station, VAApril 12th, 2026
Job DescriptionECS is seeking an Information Systems Security Manager to work in our Fairfax, VA office.ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF).The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS.The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM). The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands-on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well-organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization.Key Responsibilities Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoringDevelop, maintain, and manage RMF documentation including:System Security Plans (SSPs)Security Assessment Reports (SARs)Plan of Action & Milestones (POA&Ms)Continuous Monitoring StrategiesEnsure compliance with:NIST SP 800-53 Rev. 5 security controlsNIST SP 800-37 Rev. 2 (RMF Guide)DoD Cybersecurity Manual (DoDM 5200.01)SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)Interface directly with Navy stakeholders including:Authorizing Officials (AOs)Security Control Assessors (SCAs)Information System Owners (ISOs)Program Managers (PMs)Manage system accreditation activities within eMASS and ensure data accuracy and completenessConduct and support security control assessments, vulnerability management, and mitigation trackingEnsure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISASupport audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicableOversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures Required Skills Active Secret clearance (TS/SCI preferred)Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environmentStrong experience implementing RMF under DoDI 8510.01 (latest version)Hands-on experience with eMASSIn-depth knowledge of:NIST SP 800-53 Rev. 5 controlsNIST SP 800-37 Rev. 2DoDI 8500.01 / 8510.01SECNAV M-5239.1Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)Familiarity with:DISA STIGs and SCAP compliance toolsACAS (Assured Compliance Assessment Solution)HBSS / Endpoint Security SolutionsStrong understanding of system architectures (on-prem, cloud, hybrid)Desired SkillsExperience with Navy Authorizing Officials (AOs) and Navy-specific RMF processesFamiliarity with Platform IT (PIT) and Weapons Systems cybersecurityExperience with DevSecOps pipelines and containerized environmentsKnowledge of Zero Trust Architecture (DoD Zero Trust Strategy, 2022+)Experience supporting systems in AWS GovCloud, Azure Government, or Navy cloud environments#ECS1ECS is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.ECS is a leading mid-sized provider of technology services to the United States Federal Government. We are focused on people, values and purpose. Every day, our 3200+ employees focus on providing their technical talent to support the Federal Agencies and Departments of the US Government to serve, protect and defend the American People.