A

AnaVation

Federal IT engineering services and cybersecurity

Cybersecurity Systems Engineer / Information Systems Security Manager

Full-Time
No salary listed
Senior
Bachelor's
Chantilly, VA, USA
In PersonOn-site in Chantilly, Virginia; local candidates preferred.
No H1B Sponsorship
US Top Secret Clearance Required

About the job

Requirements
  • Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent combination of education and experience)
  • 7+ years of progressive cybersecurity or information assurance experience
  • Experience serving as an ISSM, ISSO, IA Manager, or similar role
  • Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, DFARS 252.204-7012, CMMC, and DoD cybersecurity requirements
  • Experience developing SSPs, POA&Ms, security policies, standards, and procedures
  • Experience supporting security audits and assessments
  • Excellent written, verbal, and presentation skills
  • Ability to effectively communicate cybersecurity concepts to both technical and non-technical audiences
  • Physical requirements: Ability to work at a computer for extended periods (though this is not a typical requirement; include as separate item)
  • Security clearance: Ability to obtain and maintain a U.S. Government security clearance. Active Secret clearance required; Top Secret and SCI eligibility is desirable
Responsibilities
  • Develop, implement, and continuously improve the corporate Information Security Program, serving as the primary ISSM and security lead for corporate, customer, classified, air-gapped, and standalone information systems
  • Lead cybersecurity compliance activities associated with applicable regulations, contracts, and frameworks, including NIST SP 800-171, NIST SP 800-53, CMMC, CMMI, DFARS, FAR, ISO 27001, DCSA, RMF, ATO, and customer-specific requirements
  • Design, implement, document, and oversee the secure operation and lifecycle management of corporate, cloud, classified, air-gapped, and standalone systems, ensuring appropriate security controls are implemented and maintained
  • Develop and maintain SSPs, POA&Ms, authorization packages, policies, standards, procedures, system and network diagrams, inventories, configuration records, and documentation supporting account management, media control, auditing, incident response, and continuous monitoring
  • Lead internal and external security assessments, ISO audits, CMMC readiness activities, DCSA reviews, self-inspections, vulnerability assessments, control validation, and remediation of identified findings
  • Conduct risk assessments, oversee vulnerability management and remediation tracking, monitor emerging threats and regulatory changes, and provide executive-level reporting on cybersecurity posture, compliance, vulnerabilities, and risk
  • Manage cybersecurity incidents, including reporting, investigation, documentation, corrective action, and coordination with appropriate internal, customer, and government stakeholders
  • Review system changes from a security perspective and partner with IT personnel to ensure secure configuration management, patching, endpoint protection, identity and access management, backups, system hardening, and lifecycle maintenance
  • Administer, configure, secure, maintain, and troubleshoot Windows-based servers and workstations, network and security devices, Microsoft 365 Government, Entra ID, Intune, Defender, Purview, privileged access, cloud services, and related technologies
  • Coordinate with the Facility Security Officer, Insider Threat Program Senior Official, system administrators, executive leadership, auditors, government customers, third-party assessors, vendors, and managed service providers to ensure security responsibilities are assigned and executed
  • Develop and deliver security awareness and annual cybersecurity training for employees
  • Support business development activities through proposal responses, security compliance documentation, technology evaluations, and recommendations for security and infrastructure improvements
Desired Qualifications
  • CISSP certification (or ability to obtain within an agreed timeframe)
  • Certifications such as CISM, Security+, CASP+, CCSP, CGRC (formerly CAP), CEH
  • Experience with Microsoft 365 Government, Microsoft Defender, Microsoft Entra ID (Azure Active Directory), Intune, and Microsoft Purview
  • Experience with SIEM, EDR, vulnerability scanning, and cloud security platforms
  • Experience supporting CMMC Level 2 or 3, ISO 27001, and/or ISO 20000 compliance programs
  • Experience with developing policies and procedures and passing DCSA audits
  • Experience supporting Defense Industrial Base (DIB) contractors
  • Experience supporting classified and unclassified information systems

About the company

AnaVation provides IT engineering services to the U.S. Federal Government, focusing on complex technical and analytical challenges. It works by delivering contract-based projects that cover intelligence collection and processing, analytical systems, big data solutions, and cybersecurity, using cross-disciplinary engineering teams (called AnaVators) to tailor solutions to government needs. The company differentiates itself through a government-focused, cost-effective approach, deep technical expertise, and a values-driven culture that emphasizes building long-term partnerships and strong customer trust. Its goal is to help federal agencies improve operational efficiency, security, and decision-making by solving difficult technical problems and delivering reliable, mission-critical software and systems.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Reston, Virginia

Founded

2013

Get referred to AnaVation

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • AnaVation earned 2026 Best Places to Work, supporting recruiting and retention.
  • FBI ITSSS-2 and MDA SHIELD expand addressable task orders through 2034.
  • Open 2026 hiring for security and litigation support signals ongoing demand.

What critics are saying

  • FBI and MDA vehicles intensify competition from Leidos, Booz Allen, and SAIC.
  • Award concentration on federal contracts exposes revenue to protest delays and recompetes.
  • Without non-government diversification, AnaVation depends on a few agencies and contracting officers.

What makes AnaVation unique

  • AnaVation won FBI ITSSS-2, an eight-year, $8B vehicle in 2024.
  • AnaVation joined MDA SHIELD in January 2026, a $151B IDIQ pool.
  • CMMC Level 2 positions AnaVation for controlled government cyber work.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Paid Holidays

Professional Development Budget

Life Insurance

Growth & Insights and Company News

Headcount

6 month growth

↑ 8%

1 year growth

↑ 8%

2 year growth

↑ 8%
AnaVation LLC
May 28th, 2025
AnaVation's Intern Hackathon 2025: Programming with AI

AnaVation's Intern Hackathon 2025: programming with AI.

AnaVation LLC
Mar 24th, 2025
AnaVation Named Best Places to Work 2025 by Washington Business Journal

AnaVation has been recognized as Best Places to Work 2025 Honoree by The Washington Business Journal, marking its 10th consecutive year receiving this honor!

AnaVation LLC
Jul 9th, 2024
NexGen: Josh's Growth from Intern to Senior Software Engineer

Josh joined AnaVation in 2019 as an intern, bringing a fresh perspective and a strong foundation in software engineering.

AnaVation LLC
Jun 18th, 2024
AnaVator Spotlight: Meet Alex - FSO & ITPSO

Alex joined AnaVation in May 2019 as an HR Generalist and Assistant Facility Security Officer (AFSO).

AnaVation LLC
Apr 22nd, 2024
Celebrating Success: AnaVation Named BPTW by the Washington Business Journal

AnaVation has once again been recognized as the Best Place to Work in 2024 by the Washington Business Journal, marking its 9th consecutive year receiving this honor!