Jobs and Careers
HE
Information System Security Manager (ISSM)
Hexagon US FederalHuntsville, United Statesfull_timeVerifiedPosted 9 Mar 2026
About the role
Company Overview Hexagon US Federal is a proxy-governed subsidiary of Hexagon AB providing an ever expanding portfolio of Hexagon Technologies to U.S. Federal Government organizations, including defense and intelligence agencies to meet a variety of mission requirements. With our unique capabilities and experience we transform state-of-the-art commercial technology into mission-specific solutions for our customers, partnering with them to solve their most challenging problems.Quick Hits Employees: 200Operating Locations: Chantilly, VA (HQ); Huntsville, AL; Lanham, MD, and other client sites across the US
We are seeking an Information System Security Manager (ISSM) in Huntsville, AL.
A Day in the Life of an Information System Security Manager:As an Information System Security Manager at Hexagon US Federal, you will be expected to provide strategic cybersecurity leadership, leading and prioritizing staff, and driving enterprise RMF execution and ATO sustainment across DoD environments.
We are seeking an Information System Security Manager (ISSM) in Huntsville, AL.
A Day in the Life of an Information System Security Manager:As an Information System Security Manager at Hexagon US Federal, you will be expected to provide strategic cybersecurity leadership, leading and prioritizing staff, and driving enterprise RMF execution and ATO sustainment across DoD environments.
Responsibilites
- Serve as the principal cybersecurity advisor to senior leadership, translating technical risk into mission and operational impact to support informed risk decisions.
- Direct cybersecurity resource planning, backlog prioritization, and workforce alignment to ensure coverage for execution, continuous monitoring, and high-risk remediation.
- Establish and oversee enterprise cybersecurity compliance while delegating execution to the ISSO and engineering staff while managing competing operational priorities.
- Own the cybersecurity governance framework, approving policies, standards, and system boundary definitions aligned to DoD 8500-series and NIST SP 800-53 Rev. 5.
- Provide strategic security architecture guidance to engineering and DevSecOps teams while enabling the team to focus on highest-risk activities.
- Lead cybersecurity readiness for SCAs and A&A events, directing artifact preparation, managing team tasking, and representing the program during AO and assessor engagements.
- Establish weekly prioritization cadence and backlog management to balance daily incident response with RMF sustainment activities.
- Provide technical oversight and quality review of RMF artifacts, eMASS packages, and POA&M remediation plans.
- Track and report enterprise cybersecurity KPIs including POA&M aging, vulnerability trends, and ATO sustainment health.
This job is for you if you:
- Thrive in leading cybersecurity operations and compliance for mission-critical, highavailability environments supporting DoD or public-safety missions.
- Possess deep working knowledge of the Risk Management Framework (RMF) and DoD cybersecurity policy (NIST SP 800-53, CNSSI 1253, DoDI 8510.01), with the ability to translate requirements into executable team priorities.
- Are an effective communicator who can bridge senior technical staff, program leadership, and government stakeholders while clearly articulating risk and operational impact.
- Demonstrate sound judgment, disciplined decision-making, and the ability to balance competing priorities in a dynamic threat and compliance landscape.
- Excel at establishing operating cadence, and driving accountability without excessive hands-on intervention.
- Can operate effectively in fast-paced, agile environments by prioritizing high-risk work and maintaining steady progress toward ATO sustainment and continuous monitoring objectives.
What we are expecting from you (i.e., the qualifications you must have):
- Bachelor’s degree in cybersecurity, information assurance, computer science, or a related field, with 8-10+ years of experience in cybersecurity, information system security, or related technical field.
- Security+ certification is required; advanced certifications such as CISSP, CASP+, or CISM are preferred.
- Minimum 3-5 years experience of technical leadership experience
- Demonstrated experience working within the Risk Management Framework (RMF), including control implementation oversight, assessment readiness, authorization support and continuous monitoring.
- Hands-on familiarity with core cybersecurity toolsets including eMASS, STIGs/STIG Viewer, ACAS (Nessus/Tenable), and vulnerability scanning/assessment tools.
- Experience leading or supporting NIST SP 800-53 Rev 5 control implementation and tailoring activities to align with system requirements preferred.
- Strong understanding of the Authorization to Operate (ATO) process, including the development and maintenance of Plan of Action and Milestones (POA&Ms) and other required RMF artifacts.
- Familiarity with FedRAMP controls and cloud security frameworks (AWS, Azure, or hy
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s