Back to jobs
New

Pricipal ISSM

Arlington, VA

ABOUT NOOKS

Nooks is pioneering Classified-Infrastructure-as-a-Service (CIaaS) — designing, building, and operating Sensitive Compartmented Information Facilities (SCIFs) and other secured, classified environments for the defense and national security community. We work with the agencies, contractors, and mission-driven organizations that keep the nation safe, delivering the physical infrastructure that makes classified work possible. We’re growing fast, operating across multiple markets, and building a company that takes both the mission and the business seriously.

About the Role

The Senior Cybersecurity WAN Manager owns the scaling and delivery of Nooks' wide-area networks (WANs) and serves as the Information System Security Manager (ISSM) for them — starting with NEST, our first multi-tenant WAN. Reporting to the Director of Cybersecurity, you own the Risk Management Framework (RMF) lifecycle and the project management behind every WAN deployment, ensuring authorization packages and ATOs are completed in accordance with NIST SP 800-53, the DCSA Assessment and Authorization Process Manual (DAAPM), and DCSA requirements. This is an individual-contributor role today, but it is built to grow: as WANs scale across the network, you will stand up and lead a team of WAN ISSOs and ISSM’s.

Because these are multi-tenant classified WANs, this is an on-site role at the sites where WANs are deployed. The program is being built as it scales — new WANs come online on aggressive timelines, and you are accountable for driving each one from categorization to ATO without becoming the bottleneck. You own that ambiguity, running the authorization and the project plan in parallel and keeping delivery on schedule while every package meets requirements.

Key Responsibilities

RMF & Authorization (ISSM)

  • Serve as ISSM for Nooks' WANs, owning the full RMF lifecycle from categorization through continuous monitoring for each WAN.
  • Develop and maintain authorization packages — SSPs, POA&Ms, and supporting artifacts — to secure and sustain ATOs.
  • Ensure every package and control implementation aligns with NIST SP 800-53, the DAAPM, and DCSA requirements.

WAN Delivery & Project Management

  • Project-manage WAN deployments end to end, driving each from kickoff to authorized, operational delivery.
  • Build and maintain deployment schedules, milestones, and dependencies so ATOs land on time and in scope.
  • Standardize repeatable authorization and deployment playbooks that scale to each new WAN and site.

Multi-Tenant Operations & Monitoring

  • Operate and sustain multi-tenant WANs, maintaining authorization boundaries across tenants.
  • Run continuous monitoring to keep authorizations valid and detect drift as the WAN grows.
  • Coordinate on-site implementation with the IT and operations teams building and running each site.

Team & Stakeholder Leadership

  • Serve as the primary security authority and point of contact for DCSA on WAN authorizations.
  • Stand up and lead a team of WAN ISSOs as the network scales.
  • Advise site and program stakeholders on WAN security posture, risk, and authorization status.

What Success Looks Like in This Role

Within the first year, NEST is authorized and operating as a multi-tenant WAN, with its ATO package complete and defensible under NIST SP 800-53, the DAAPM, and DCSA requirements. WAN deployments run to a repeatable project plan, and new WANs move from categorization to ATO on schedule without becoming the bottleneck for site delivery. Authorization boundaries hold across tenants, and continuous monitoring keeps every WAN's authorization valid as the network grows. DCSA and site stakeholders regard this role as the authoritative owner of WAN security and authorization status. As the footprint expands, the role is scaling from a single owner into a WAN ISSO team executing to a consistent standard.

Cross-Functional Expectations

This role partners closely with Enterprise IT, which builds the WAN architecture, and with IT/Cyber Operations, which deploys and sustains it at each site, to carry every WAN from design to authorized delivery. It coordinates with IT/Cyber Product on gate reviews and site build timelines so authorization stays off the critical path. Externally, it is the primary interface to DCSA for WAN authorizations, and it executes on the RMF and security strategy set by the Director of Cybersecurity.

The Skillset

Required

  • Active Top Secret/SCI clearance and U.S. citizenship; SAP eligibility a plus.
  • Demonstrated experience as an ISSM (or a senior ISSO ready to step up) for classified networks under DCSA/NISP.
  • Deep, hands-on RMF expertise — owning authorization packages (SSPs, POA&Ms) through ATO under NIST SP 800-53 and the DAAPM.
  • Direct experience with DCSA authorization processes and interfacing with DCSA as the cognizant security agency.
  • Strong project-management skills — planning, scheduling, and driving complex technical deployments to deadline.
  • Experience with WAN or network authorization, ideally multi-tenant or enterprise-scale classified networks (e.g., SIPR).
  • Active DoD 8570/8140 IAM Level II or III certification (e.g., CISSP, CISM, CASP+).

Preferred

  • PMP or equivalent project-management certification.
  • Experience authorizing or operating SIPR/JWICS or other DoD transport networks.
  • Experience standing up and leading an ISSO team.
  • Familiarity with eMASS and DCSA/NISP eMASS authorization workflows.

Eligibility & Clearance

Candidates must be authorized to work in the United States and must be U.S. citizens. This role requires an active Top Secret clearance (SCI eligibility preferred) as a condition of employment.

Salary Range for all departments

Salary Range

$170,000 - $200,000 USD

Create a Job Alert

Interested in building your career at Nooks? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Nooks’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...