(704) Cybersecurity Information System Security Manager (ISSM)
Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future. Position Description: Arlo Solutions is seeking an experienced Information System Security Manager (ISSM) to support a U.S. Army customer in Orlando, Florida. This is a full-time on-site position responsible for managing the cybersecurity posture and Risk Management Framework (RMF) lifecycle for approximately 3–7 Army Information Systems supporting missions ranging from Controlled Unclassified Information (CUI) through classified environments. The ISSM serves as the primary cybersecurity advisor for assigned systems and is responsible for ensuring compliance with DoD RMF, Army Regulation (AR) 25-2, and U.S. Army NETCOM RMF policies, processes, and business rules. The position requires close coordination with Government leadership, Program Managers, Information System Owners, Security Control Assessors, engineers, and Authorizing Officials to maintain secure, compliant, and operationally ready systems throughout their lifecycle. Location: Onsite: US ARMY, Orlando FloridaClearance: Active Top Secret Security Clearance (SCI eligibility preferred) Responsibilities and/or Success Factors: Serve as the Information System Security Manager (ISSM) for 3–7 assigned Army Information Systems. Lead all phases of the DoD Risk Management Framework (RMF) lifecycle in accordance with NETCOM RMF guidance. Develop, maintain, and manage Authorization Packages, including SSPs, POA&Ms, Security Categorization, Continuous Monitoring documentation, and supporting Body of Evidence. Coordinate Authorization to Operate (ATO), Interim Authorization to Test (IATT), Authorization to Operate with Conditions (ATO-C), and reauthorization activities. Manage Continuous Monitoring (ConMon) activities, vulnerability management, STIG compliance, ACAS review, and cybersecurity reporting. Conduct cybersecurity risk assessments and recommend mitigation strategies supporting Authorizing Official (AO) risk decisions. Coordinate Security Control Assessments (SCA) and remediation of assessment findings. Review system architecture, authorization boundaries, network diagrams, data flows, and system changes to ensure continued compliance. Manage Plans of Action & Milestones (POA&M) and track corrective actions through closure. Provide cybersecurity guidance to system owners, engineers, administrators, and Government l...