Information Systems Security Manager
Themerlingroup · Merlin International Inc - HQ, McLean, VA, US · United States · On-site
Posted Sep 30, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Merlin Group
Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions.
At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact.
The Opportunity
We are looking for an Information System Security Manager (ISSM) to own the day-to-day security compliance and continuous monitoring activity that keeps our FedRAMP authorization current. You will coordinate access authorization, vulnerability scanning, POA&M management, change control, and the recurring compliance calendar, while tracking changes to the FedRAMP program itself. The role is as much about people as process: you will explain security and compliance requirements to customers, including ones who are frustrated or under pressure, and raise risks to leadership early, clearly, and in writing .
Primary Duties & Responsibilities
Coordinate access authorization for the environment, keeping requests, approvals, and quarterly access reviews tracked and current
Maintain the Plan of Action and Milestones (POA&M) with current status, owners, and due dates, and coordinate remediation plans with the teams closing findings
Perform vulnerability scanning, analyze results, and produce reporting for stakeholders and leadership
Manage the Change Control Board (CCB) as concierge for change requests, and populate Security Impact Assessments (SIAs) for proposed changes
Coordinate significant change requests through the required review and approval process
Track the recurring compliance calendar, including the Incident Response and Contingency Plan (IRCP), contingency plan testing, quarterly access reviews, and Rules of Behavior (ROB) management
Coordinate Software Bill of Materials (SBOM) submissions with the teams that own them and keep reviews on schedule
Manage the Learning Management System (LMS) for security awareness training, tracking completion and following up on gaps
Monitor changes to the FedRAMP program, including Rev 5, 20x, CR26, and other RFCs, and assess their impact on the environment
Explain security and compliance…