ForgeApply
Try it free

ForgeApply · Job listing

Senior Cybersecurity WAN Manager

Nooks

Arlington, VA, USonsite

See all 62 open roles at Nooks

Tailor your resume for this Nooks job in about a minute.

ForgeApply rewrites your resume for this exact posting, then autofills the application on Nooks's site with it. You review everything before it's sent. Free trial, no card required.

About this role

ABOUT NOOKS

Nooks is pioneering Classified-Infrastructure-as-a-Service (CIaaS) — designing, building, and operating Sensitive Compartmented Information Facilities (SCIFs) and other secured, classified environments for the defense and national security community. We work with the agencies, contractors, and mission-driven organizations that keep the nation safe, delivering the physical infrastructure that makes classified work possible. We’re growing fast, operating across multiple markets, and building a company that takes both the mission and the business seriously.

About the Role

The Senior Cybersecurity WAN Manager owns the scaling and delivery of Nooks' wide-area networks (WANs) and serves as the Information System Security Manager (ISSM) for them — starting with NEST, our first multi-tenant WAN. Reporting to the Director of Cybersecurity, you own the Risk Management Framework (RMF) lifecycle and the project management behind every WAN deployment, ensuring authorization packages and ATOs are completed in accordance with NIST SP 800-53, the DCSA Assessment and Authorization Process Manual (DAAPM), and DCSA requirements. This is an individual-contributor role today, but it is built to grow: as WANs scale across the network, you will stand up and lead a team of WAN ISSOs and ISSM’s.

Because these are multi-tenant classified WANs, this is an on-site role at the sites where WANs are deployed. The program is being built as it scales — new WANs come online on aggressive timelines, and you are accountable for driving each one from categorization to ATO without becoming the bottleneck. You own that ambiguity, running the authorization and the project plan in parallel and keeping delivery on schedule while every package meets requirements.

Key Responsibilities

RMF & Authorization (ISSM)

• Serve as ISSM for Nooks' WANs, owning the full RMF lifecycle from categorization through continuous monitoring for each WAN.

• Develop and maintain authorization packages — SSPs, POA&Ms, and supporting artifacts — to secure and sustain ATOs.

• Ensure every package and control implementation aligns with NIST SP 800-53, the DAAPM, and DCSA requirements.

WAN Delivery & Project Management

• Project-manage WAN deployments end to end, driving each from kickoff to authorized, operational delivery.

• Build and maintain deployment schedules, milestones, and dependencies so ATOs land on time and in scope.

• Standardize repeatable authorization and deployment playbooks that scale to each new WAN and site.

Multi-Tenant Operations & Monitoring

• Operate and sustain multi-tenant WANs, maintaining authorization boundaries across tenants.

• Run continuous monitoring to keep authorizations valid and detect drift as the WAN grows.

• Coordinate on-site implementation with the IT and operations teams building and running each site.

Team & Stakeholder Leadership

• Serve as the primary security authority and point of contact for DCSA on WAN authorizations.

• Stand up and lead a team of WAN ISSOs as the network scales.

• Advise site and program stakeholders on WAN security posture, risk, and authorization status.

What Success Looks Like in This Role

Within the first year, NEST is authorized and operating as a multi-tenant WAN, with its ATO package complete and defensible under NIST SP 800-53, the DAAPM, and DCSA requirements. WAN deployments run to a repeatable project plan, and new WANs move from categorization to ATO on schedule without becoming the bottleneck for site delivery. Authorization boundaries hold across tenants, and continuous monitoring keeps every WAN's authorization valid as the network grows. DCSA and site stakeholders regard this role as the authoritative owner of WAN security and authorization status. As the footprint expands, the role is scaling from a single owner into a WAN ISSO team executing to a consistent standard.

Cross-Functional Expectations

This role partners closely with Enterprise IT, which builds the WAN architecture, and with IT/Cyber Operations, which deploys and sustains it at each site, to carry every WAN from design to authorized delivery. It coordinates with IT/Cyber Product on gate reviews and site build timelines so authorization stays off the critical path. Externally, it is the primary interface to DCSA for WAN authorizations, and it executes on the RMF and security strategy set by the Director of Cybersecurity.

The Skillset

Required

• Active Top Secret/SCI clearance and U.S. citizenship; SAP eligibility a plus.

• Demonstrated experience as an ISSM (or a senior ISSO ready to step up) for classified networks under DCSA/NISP.

• Deep, hands-on RMF expertise — owning authorization packages (SSPs, POA&Ms) through ATO under NIST SP 800-53 and the DAAPM.

• Direct experience with DCSA authorization processes and interfacing with DCSA as the cognizant security agency.

• Strong project-management skills — planning, scheduling, and driving complex technical deployments to deadline.

• Experience with WAN or network authorization, ideally multi-tenant or enterprise-scale classified networks (e.g., SIPR).

• Active DoD 8570/8140 IAM Level II or III certification (e.g., CISSP, CISM, CASP+).

Preferred

• PMP or equivalent project-management certification.

• Experience authorizing or operating SIPR/JWICS or other DoD transport networks.

• Experience standing up and leading an ISSO team.

• Familiarity with eMASS and DCSA/NISP eMASS authorization workflows.

Eligibility & Clearance

Candidates must be authorized to work in the United States and must be U.S. citizens. This role requires an active Top Secret clearance (SCI eligibility preferred) as a condition of employment. Salary Range for all departments

Salary Range $170,000 — $200,000 USD

Salary insight

This posting doesn't disclose pay. Across 2,052 Washington DC jobs with disclosed salaries on ForgeApply, the median is $133k.

See full Security Engineer salary data for Washington DC

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Nooks role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Washington DC · Browse all jobs

Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)