> Markdown version of [/jobs/ext/114078-information-system-security-manager-issm-fairfax-virginia](https://www.wearedevelopers.com/jobs/ext/114078-information-system-security-manager-issm-fairfax-virginia). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - Fairfax, Virginia - **Company:** In-Depth Engineering - **Location:** Fairfax, VA, United States - **Experience:** Expert - **Salary:** $100,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, System Configuration, Linux, Information Security Management, Red Hat Enterprise Linux, Security Content Automation Protocol, Service Pack, Information Security Management System, Information Technology, Vulnerability Analysis - **Published:** May 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9665081968b7562a ## About the Role Do you have experience in Stakeholder management?, Do you have a Bachelor's degree?, Effective communication and an ability to work independently are key attributes needed to be successful in this role. The ISSM will frequently interact with internal and external stakeholders, provide cybersecurity oversight, and drive compliance standards for the information systems. The ISSM partners with security engineers and system administrators to ensure security patches and secure configurations are in place and functioning properly on the information systems. Requirements: * Must be US Citizen for consideration and hold an active secret clearance * Bachelor's degree in computer science, cybersecurity, information systems, or related field * 5+ years of experience in an ISSM or ISSO role * Must have Security+ or CISSP * Hands-on experience with STIGs, STIG Viewer, and SCAP tools * Strong Linux experience (Red Hat Enterprise Linux or similar) * Demonstrated experience with eMASS * Experience with certification and authorization of IT systems * Experience with applying and documenting policy and system configurations that satisfy NIST Security Control requirements * Ability to develop and update relevant RMF artifacts; System Security Plan (SSP), Plan of Actions and Milestones (POA&M), Security Controls Traceability Matrix (SCTM), as well as the associated security policies and procedures. ## Description The ISSM is responsible for the oversight of the information system's security posture. Emphasis is placed on the application and sustainment of the security controls to ensure cyber security requirements are properly administered throughout the system. The ISSM serves as the principal advisor on all matters, technical and otherwise, related to the security of systems under their purview. Primary functions include processing for certifications and authorization of IT systems along with the development and maintenance associated with eMASS, and RMF. Additional responsibilities include continuous monitoring, vulnerability assessments, and incident investigations. The ISSM is also a primary stakeholder and partners with ISSOs to facilitate the continuous monitoring efforts used to promote security compliance throughout the organization. An ability to plan effectively and prioritize projects is a required function of the ISSM role. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [IKEA Story: Transforming an Iconic Retail Brand](https://www.wearedevelopers.com/videos/444-ikea-story-transforming-an-iconic-retail-brand) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)