> Markdown version of [/jobs/ext/1193159-issm-2-102-060](https://www.wearedevelopers.com/jobs/ext/1193159-issm-2-102-060). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSM 2 102-060 - **Company:** Ic-cap Llc - **Location:** Dayton, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, File Transfer, Firmware, Identity and Access Management, Information Security Management, Network Security, Network Administration, SAP (Applications) - **Published:** July 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9012738/issm-2-102-060 ## About the Role * Bachelor's degree * 7-9 years related experience; Prior performance in roles such as ISSO or ISSM SAP experience. Training and Certifications : * DoD 8570.01-M IAM Level II (in lieu of IAT Level II). Security Clearance: * Active TS/SCI and the willingness to sit for a polygraph, if needed ## Description * Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures * Develop and oversee operational information systems security implementation policy and guidelines of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint * Special Access Program Implementation Guide (JSIG) authorization process * Advise customer on Risk Management Framework (RMF) assessment and authorization issues * Perform risk assessments and make recommendations to DoD agency customers * Advise government program managers on security testing methodologies and processes * Evaluate authorization documentation and provide written recommendations for authorization to government PMs * Develop and maintain a formal Information Systems Security Program * Ensure that all IAOs, network administrators, and other cyber security personnel receive the necessary technical and security training to carry out their duties * Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation * Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media * Develop and execute security assessment plans that include verification that the features and assurances required for each protection level functioning * Maintain a and/or applicable repository for all system authorization documentation and modifications * Institute and implement a Configuration Control Board (CCB) charter * Develop policies and procedures for responding to security incidents, to include investigating and reporting security violations and incidents * Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system * Ensure that data ownership and responsibilities are established for each authorization boundary, to include accountability, access rights, and special handling requirements * Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local cyber security training. * Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed * Assess changes in the system, its environment, and operational needs that could affect the authorization * Ensure that authorization is accomplished a valid Authorization determination has been given for all authorization boundaries under your purview * Review AIS assessment plans * Coordinate with PSO or cognizant security official on approval of external information systems (e.g., guest systems, interconnected system with another organization) * Conduct periodic assessments of the security posture of the authorization boundaries * Ensure configuration management (CM) for security-relevant changes to software, hardware, and firmware and that they are properly documented * Ensure periodic testing is conducted to evaluate the security posture of IS by employing various intrusion/attack detection and monitoring tools (shared responsibility with ISSOs) * Ensure that system recovery and reconstitution processes developed and monitored to ensure that the authorization boundary can be recovered based on its availability level determination * Ensure all authorization documentation is current and accessible to properly authorized individuals * Ensure that system security requirements are addressed during all phases of the system life cycle * Develop Assured File Transfers (AFT) on accordance with the JSIG * Participate in self-inspections * Conduct the duties of the Information System Security Officer (ISSO) if one is not present and/or available. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Devouring APIs with Python](https://www.wearedevelopers.com/videos/355-devouring-apis-with-python) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)