Information Security Manager Jobs in McLean, VA
Information Security Manager jobs in McLean, Virginia concentrate in the Tysons Corner corridor, downtown McLean, and the Beltway defense-contractor cluster, with strong demand across federal contracting, financial services, and cybersecurity consulting. Employers hiring right now include Information Technology Senior Management Forum, Capital One, and Steampunk. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 162+ Information Security Manager jobs







Information System Security Officer (ISSO)
Location: Bethesda, MD (Hybrid; On-site as Required)
Clearance: Tier 2 Public Trust (Required)
Employment Type: Full-Time
Position Summary
Digital Global Connectors (DGC) is seeking an experienced Information System Security Officer (ISSO) to support a Federal information security program. The ISSO is responsible for ensuring assigned information systems comply with applicable Federal cybersecurity requirements by implementing, maintaining, and monitoring security controls throughout the system lifecycle.
This position serves as the primary cybersecurity advisor to System Owners and technical teams, supporting the Risk Management Framework (RMF), Authorization to Operate (ATO) activities, continuous monitoring, vulnerability management, security documentation, and compliance reporting. The ISSO collaborates closely with Security Engineers, Security Assessors, Security Architects, System Administrators, Project Managers, and Government stakeholders to ensure enterprise systems remain secure, compliant, and operational.
The successful candidate will possess extensive experience supporting Federal information security programs, managing system authorization packages, and implementing risk-based cybersecurity practices.
Essential Duties and Responsibilities
Information System Security Management
- Serve as the primary cybersecurity advisor for assigned information systems.
- Ensure systems remain compliant with applicable Federal cybersecurity requirements.
- Coordinate implementation and maintenance of required security controls.
- Monitor system security posture throughout the system lifecycle.
- Identify cybersecurity risks and recommend appropriate mitigation strategies.
- Support secure operation of enterprise information systems.
Risk Management Framework (RMF)
- Support all phases of the NIST Risk Management Framework (RMF).
- Coordinate Authorization to Operate (ATO), reauthorization, and continuous authorization activities.
- Ensure implementation of NIST SP 800-53 security controls.
- Maintain system authorization documentation throughout the authorization lifecycle.
- Coordinate remediation of identified security weaknesses.
- Support ongoing continuous monitoring activities.
Security Documentation
Develop, maintain, and update:
- System Security Plans (SSPs)
- Security Assessment Plans (SAPs)
- Security Assessment Reports (SARs)
- Plans of Action and Milestones (POA&Ms)
- Security Categorization Documentation
- Continuous Monitoring Strategies
- Configuration Management Documentation
- Contingency Plans
- Incident Response Documentation
- Privacy and Security Supporting Documentation
Ensure documentation remains current, complete, and compliant with organizational and Federal requirements.
Continuous Monitoring
- Monitor implementation and effectiveness of security controls.
- Review vulnerability assessment results and coordinate remediation activities.
- Track security findings through resolution.
- Validate implementation of corrective actions.
- Support periodic security reviews and system assessments.
- Maintain continuous awareness of system security posture.
Vulnerability and Risk Management
- Review enterprise vulnerability assessment results affecting assigned systems.
- Coordinate remediation efforts with technical teams.
- Evaluate risks associated with vulnerabilities and configuration weaknesses.
- Recommend risk mitigation strategies.
- Maintain Plans of Action and Milestones (POA&Ms).
- Support risk acceptance documentation when appropriate.
Security Compliance
- Ensure compliance with organizational cybersecurity policies, standards, and procedures.
- Support internal and external security audits.
- Coordinate responses to assessment findings.
- Assist with implementation of corrective actions.
- Monitor compliance with established security baselines.
- Support cybersecurity metrics and reporting requirements.
Incident Response Support
- Coordinate cybersecurity activities during security incidents affecting assigned systems.
- Support incident investigations and post-incident reviews.
- Ensure appropriate documentation of security events.
- Coordinate implementation of corrective actions following incidents.
- Participate in incident response exercises and tabletop activities.
- Assist with lessons learned and process improvement initiatives.
Collaboration
- Coordinate with System Owners, Security Engineers, Security Assessors, Security Architects, Cloud Engineers, Network Engineers, Project Managers, and Government stakeholders.
- Participate in security working groups and technical meetings.
- Provide cybersecurity guidance to project teams throughout the system lifecycle.
- Support technology modernization initiatives.
- Present system security status to technical and executive leadership.
Continuous Improvement
- Monitor updates to Federal cybersecurity guidance and organizational security policies.
- Recommend improvements to security processes and system security posture.
- Support automation of compliance and continuous monitoring activities.
- Promote cybersecurity best practices across assigned programs.
- Maintain professional certifications and technical expertise.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related discipline.
- Minimum five (5) years of experience serving as an ISSO or supporting Federal information security programs.
- Experience implementing the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls.
- Experience developing and maintaining system authorization documentation.
- Experience supporting continuous monitoring and vulnerability management activities.
- Strong analytical, documentation, communication, and organizational skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
- Master's degree in Cybersecurity, Information Assurance, Information Systems, Engineering, or a related discipline.
- Experience supporting a Federal civilian agency.
- Experience supporting cloud-hosted systems and hybrid environments.
- Experience utilizing Governance, Risk, and Compliance (GRC) platforms such as ServiceNow GRC or RSA Archer.
- Certified Authorization Professional (CAP)
- ISC2 Certified in Governance, Risk and Compliance (CGRC)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- CompTIA Security+ (preferred)
Knowledge, Skills, and Abilities
- Information System Security Officer (ISSO) Responsibilities
- Risk Management Framework (RMF)
- NIST SP 800-53
- NIST SP 800-37
- Authorization to Operate (ATO)
- Continuous Monitoring
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Security Assessment Plans (SAPs)
- Plans of Action and Milestones (POA&Ms)
- Security Control Implementation
- Vulnerability Management
- Risk Assessments
- Configuration Management
- Incident Response
- Cloud Security
- Identity and Access Management (IAM)
- Governance, Risk, and Compliance (GRC)
- Microsoft Office Suite
- ServiceNow
- RSA Archer
- Jira
Security Requirements
- Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
- Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
- Ability to support system authorization activities, continuous monitoring, security assessments, continuity of operations (COOP), emergency response activities, and surge support as required.
- Must maintain strict confidentiality while handling system security documentation, risk assessments, vulnerability information, compliance records, and Federal information systems.
- Ability to independently manage the cybersecurity posture of assigned information systems, coordinate with Government stakeholders and technical teams, maintain accurate authorization documentation, and ensure ongoing compliance with Federal cybersecurity requirements through effective risk management and continuous monitoring.
See All 162+ Information Security Manager Jobs in McLean
Find roles in McLean that match your experience and apply in just a few clicks.
Find JobsInformation Security Manager Job Market in McLean
Who's Hiring
- Information Technology Senior Management Forum39
- Capital One34

- Steampunk17

- EY11

- AMERICAN SYSTEMS11

Top Industries Hiring
- Accounting & Auditing
- Banking & Financial Services
Information Security Manager Jobs in McLean: Frequently Asked Questions
How do I get a information security manager job in McLean?
Focus your search on McLean's three dominant hiring sectors: federal defense contractors along the Beltway, financial services firms in the Tysons Corner corridor, and cybersecurity consulting shops headquartered near Chain Bridge Road. Candidates with active clearances, CISSP certification, and experience managing compliance frameworks like NIST, FedRAMP, or CMMC stand out strongly in this market. Networking through local ISACA and ISSA chapter events also surfaces openings before they post publicly.
Which companies hire information security managers in McLean?
Employers hiring information security managers in McLean right now include Information Technology Senior Management Forum, Capital One, and Steampunk, based on current listings on Migrate Mate as of August 2026. McLean attracts a dense mix of defense primes, intelligence-community contractors, and financial-services firms, many of which maintain security operations centers requiring dedicated leadership.
Are there remote information security manager jobs in McLean?
Yes, though with limits: information security manager roles that involve overseeing cleared personnel, classified systems, or on-site SOC operations are predominantly on-site, while governance, risk, and compliance-focused positions carry more schedule flexibility. About 40% of information security manager openings tied to McLean are remote or hybrid as of August 2026, with hybrid arrangements most common among GRC and policy-focused roles at commercial employers in the Tysons corridor.
How can I get a information security manager job in McLean with little or no experience?
The most realistic entry path in McLean is through a junior analyst or security operations role at one of the area's many mid-size federal contractors, which frequently promote from within once candidates earn a clearance and foundational certifications like Security+ or CASP+. McLean employers also value candidates who transition laterally from IT administration or network engineering. Pursuing a Top Secret clearance early, even before a formal manager title, is the single strongest differentiator in this local market.
Which industries hire the most information security managers in McLean?
McLean information security manager roles concentrate in Accounting & Auditing and Banking & Financial Services, based on current listings on Migrate Mate as of August 2026. McLean's proximity to federal agencies, the intelligence community, and major financial headquarters means these sectors consistently need managers who can bridge technical security requirements with regulatory and compliance mandates.
Related Jobs in Virginia
See All 162+ Information Security Manager Jobs in McLean
Find roles in McLean that match your experience and apply in just a few clicks.
Find Jobs