Apply to Lead Information Systems Security Manager| ISSM/ISSO | TS security clearance required
Tulzi Technologies, LLC (Tulzi) prides ourselves on an open, and honest culture in the workplace which builds a morale conducive to inspiring growth on our team, while balancing lifestyle by supporting personal and family goals with flexibility. Tulzi offers secure network systems and software engineering solutions in both public and private sectors. With certified expert consulting the team at Tulzi is able to address the customers mission, and follow through in the systems development life cycle.
Clearance Required: TS/ SCI eligible
Title: Information Systems Security Manager
Location: Andrews Air Force Base, MD
We are seeking a highly skilled and experienced Lead Information System Security Manager who operates at the intersection of ISSM and ISSO responsibilities. The ideal candidate will have a deep understanding of implementing security measures across enterprise systems, applying governance frameworks, and engineering secure solutions for traditional infrastructure, cloud environments, DevSecOps pipelines, and containerized platforms. This role requires strong RMF leadership, advanced security engineering expertise, and hands-on technical execution across Linux, Windows, cloud, and container ecosystems. The Lead Information System Security Manager will secure systems throughout their entire lifecycle from initial design and accreditation through continuous monitoring while working collaboratively with cross-functional teams to ensure cybersecurity is embedded into every aspect of the organization’s IT infrastructure.
Responsibilities:
• Lead RMF activities across the system lifecycle and maintain required security documentation.
• Ensure compliance with applicable security frameworks and support all ATO processes.
• Conduct security impact analysis for system, infrastructure, and application changes.
• Manage RMF packages in enterprise GRC platforms and drive timely POA&M closure.
• Track and report on security control performance, coordinate remediation with technical teams, and support audits through clear cybersecurity metrics. • Engineer secure architectures across operating systems, virtualized environments, container platforms, and cloud services.
• Implement and review security controls and hardening standards and participate in security design evaluations.
• Integrate defense-in-depth strategies across hybrid environments and perform enterprise vulnerability assessments.
• Validate, analyze, and coordinate remediation of vulnerabilities while maintaining visibility through dashboards and reporting.
• Embed security into CI/CD pipelines and support DevSecOps tools and processes.
• Provide container and Kubernetes security engineering, including image assurance, runtime protection, and policy enforcement.
• Conduct cloud security architecture reviews and implement controls for identity, encryption, networking, logging, and compliance.
• Secure enterprise Windows and Linux environments and enforce configuration, identity, and platform security standards.
• Manage patching and configuration compliance across enterprise platforms and automation tools.
• Build dashboards for continuous monitoring, compliance reporting, vulnerability trends, threat intelligence, and enterprise risk scoring.
• Provide mentorship and guidance to teams on cybersecurity best practices.
Qualifications:
• Bachelor’s degree or equivalent experience (8+ years), or advanced degree with 5+ years of experience.
• TS/SCI eligibility.
• DoD 8570/8140 IAM/IAT Level III compliant certification(s).
• Strong understanding of the Risk Management Framework (RMF) and security governance principles.
• Knowledge of Linux/Unix operating systems and their administrative concepts.
• Familiarity with containerization and orchestration platforms (e.g., Docker, Kubernetes).
• Ability to interpret and apply DISA STIG requirements across traditional, cloud, and containerized environments.
• Proficiency in at least one scripting or automation language (e.g., Bash, Python, Go, Rust).
• Strong analytical and problem-solving capabilities with the ability to work effectively in dynamic environments.
• Effective written and verbal communication skills for both technical and non-technical audiences.
• Experience supporting cybersecurity initiatives within large-scale DoD or Intelligence Community environments.
• General understanding of endpoint security tools and broader security ecosystems.
Nice-to-Have Qualifications
• Background in DevSecOps, security automation, or secure CI/CD pipeline integration.
• Experience with cloud security across platforms such as AWS, Azure Government, or GovCloud.
• Advanced Kubernetes security experience beyond basic administration.
• Experience developing Infrastructure as Code (IaC) and automating deployments.
• Experience with DevOps tools and workflows (e.g., Jenkins, Git, Ansible, Terraform).
• Additional professional certifications, such as: -AWS DevOps Professional - Certified Kubernetes Security Specialist (CKS) -GIAC Cloud Security Automation (GCSA) -Certified DevSecOps Professional (CDP)
• Broader programming or automation experience beyond core scripting languages.
Desired Skills:
• Leadership and mentorship capabilities
• Strong analytical and troubleshooting skills
• Ability to communicate effectively with executives, engineers, and Authorizing Officials
• Experience leading cross-functional cybersecurity initiatives
• Strong understanding of software supply chain security and Zero Trust Architecture
Benefits:
We offer a competitive benefits and compensation package and FUN place to work! Benefits include, but not limited to:
Health and Wellness Benefits-
Medical Insurance (three CareFirst healthcare plans to choose from, Dental and Vision Insurance, 75% covered for employee/ 50% per dependent
-
Health Savings Account (HSA) contributions $1500 individual/ $3000 family
Personal Insurance Benefits
-
Company-paid Life Insurance and AD&D coverage
-
Company-paid Short-term and Long-term Disability Insurance
Paid Leave
-
Employees receive 20 days of vacation/10 holidays built into hourly rate/ 5 days of Administrative time (currently used for snow, jury, bereavement)
Retirement
-
Pre-tax 401k program including 6% company match
-
100% fully vested from eligibility date
*Eligible after 90 days of employment
Tulzi Technologies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, pregnancy, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.