Information System Security Manager (ISSM)Wright-Patterson AFBAt IPT Associates (IPTA), we enjoy solving real-world problems with technology. We work closely with our customers, teammates, experts, and partners to come up with practical solutions that make a difference. Whether it's a government or business organization, we focus on understanding the need and building something that works.Our TeamAt IPTA, everything starts with our people. We're big believers that when you invest in your team, great things happen. That's why we encourage learning, growth, and trying new things-even if you don't have all the answers yet.Our culture is rooted in fierce determination, fearless integrity, and passionate service-but we also like to keep things collaborative, supportive, and down-to-earth.We're looking for people who:Are curious and excited about technologyLike solving problems and figuring things outCan take initiative but also enjoy working with a teamWant to keep learning, growing, and challenging themselvesIf you're someone who's eager to jump in, learn something new, and make an impact-you'll fit right in here.*This position is contingent upon contract award and the actual job description may vary based on specific contract requirements and organizational needs.*Responsibilities:Manage cybersecurity compliance for assigned information systems in accordance with DoW, Air Force, RMF, FISMA, and NIST requirements, ensuring systems remain mission-capable, risk-informed, and authorized to operateDevelop, implement, and enforce cybersecurity policies, procedures, and security controls in accordance with DoW, Air Force, RMF, FISMA, and NIST requirementsLead all aspects of the RMF Lifecycle, including SSP development, maintenance, accreditation/re-accreditation, and oversight, including conducting periodic reviews to ensure complianceMaintain and take action on POA&M items, coordinate mitigation plans with system owners and technical teams, and track remediation through closureSupport eMASS package development and updates, including control implementation statements, artifact uploads, risk documentation, and ATO coordinationConduct cybersecurity risk assessments, audits, and control reviews to identify vulnerabilities, evaluate organizational risk, and recommend mitigation actionsOversee continuous monitoring activities, including recurring control reviews, vulnerability scans, audit log reviews, and compliance status reporting.Review ACAS, Splunk, STIG, IAVM, and audit log results to identify security risks, validate remediation actions, and support risk-based decisionsCoordinate security validation testing within DevSecOps, on-premises, and cloud environments to ensure new or changed capabilities meet authorization requirements. Perform as a primary contact for IS security inspections, tests, and Security Control Assessors (SCA) and Representatives (SCAR)Review firewall, system, and security change requests to assess cybersecurity risk, mission impact, and compliance with approved security baselinesMonitor intrusion detection, prevention, audit, and security event data to identify potential threats and coordinate timely response actionsCoordinate security incident response activities, support investigations, and report findings, impacts, and corrective actions to leadershipRequirements:BS in Computer Science, Cyber Security, or a related field; with 8+years of relevant cybersecurity experienceOne of the following current certifications: CASP+, CISSP, or GSLCActive TS clearance with SCI eligibilityExperience working with the Air Force RMF security frameworks, including DoD and Air Force security policies and instructionsExperience and ability to provide strategic and tactical information security advice and manage all Cybersecurity related activities for current or future IT platformsExperience working in conjunction with a multi-contractor team in support of Cybersecurity, continuous monitoring, and other emerging compliance requirementsExperience with Federal Information Security Management Act (FISMA)Experience with Air Force's Information Technology Investment Portfolio Suite (ITIPS)Experience ensuring software, hardware, and firmware comply with appropriate IAVM'sMust track and action POA&M entries as part of the RMF processExperience with reviewing and updating STIG resultsExperience ensuring Continuous Monitoring is adhered toWorking experience with Risk Management Framework and NIST 800-53 revision 4 and revision 5 controlsExperience working within eMASS and obtaining an ATOFamiliar with performing Security validation testing through a DevSecOps process and within both on-premises and a Cloud EnvironmentExperience with ACAS, utilizing Splunk, reviewing of audit logs, and other cybersecurity monitoring functionsAbility to identify risks of implementing technology solutions and analyze the impact on achieving desired business outcomesIPTA is an Equal Opportunity Employer. All employment decisions are based on individual merit, including qualifications, experience, performance, and business needs, consistent with applicable federal laws and federal contracting requirements. IPTA provides equal opportunity and utilizes merit-based principles to make employment-related decisions.#clearance