
Cloud Information System Security Manager – ISSM
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Ohio.
• Aid in the development and enhancement of a secure DevSecOps cloud environment in accordance with DoD RMF, NIST SP 800-53 Rev. 5, and CMMC 2.0 standards.
• Assist in maintaining cybersecurity governance and compliance for a DoD DevSecOps setting on an Azure-based cloud infrastructure.
• Support the complete lifecycle of Assessment and Authorization processes.
• Uphold continuous compliance with Authority to Operate.
• Ensure the accuracy, completeness, and integrity of security artifacts within eMASS.
• Create, implement, and enforce cybersecurity policies and procedures.
• Monitor control inheritance and changes to system boundaries.
• Conduct risk assessments and perform vulnerability testing.
• Guide engineering teams to align configurations with RMF controls, Zero Trust principles, and DoD Cloud SRG standards.
• Act as a liaison to government stakeholders, authorizing officials, mission partners, auditors, and cross-functional engineering teams.
• Organize security briefings and coordinate remediation efforts.
• Collaborate effectively with development and operations teams.
• Foster a robust organizational security culture.
• Monitor and respond to security incidents and threats.
• Oversee security audits and assessments.
• Develop and provide security awareness training.
• Maintain professional relationships with the ISO, AO, SCA, and other cybersecurity engineers in information systems.
• Perform additional duties as assigned.
• Must be a U.S. citizen.
• Bachelor's degree in cybersecurity, computer science, engineering, or a related field, or equivalent experience.
• Over 5 years of cybersecurity experience in support of DoD, federal, or regulated environments.
• eMASS experience is MANDATORY.
• Comprehensive, hands-on experience with Azure security tools, including the Microsoft Defender suite, Sentinel, Purview, and Azure Policy.
• Strong understanding of DevSecOps methodologies and CI/CD pipelines.
• Experience in integrating security automation into development workflows.
• In-depth knowledge of DoD RMF and NIST SP 800-53 Rev. 5 controls.
• Familiarity with security assessment and evidence requirements.
• Proficient in vulnerability management tools, remediation processes, and risk-based prioritization.
• Knowledge of threat intelligence platforms and adversary TTP analysis.
• Experience in creating threat-informed security detections.
• Must successfully pass a background investigation, including a criminal history and identity check.
• Competitive benefits package within the industry.
• Awards and recognition program.
• Personalized guidance from ARS Senior Managers.
• Work/life balance.
• Support and opportunities for career development.
• Remote work arrangement.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.