> Markdown version of [/jobs/ext/1599964-issm](https://www.wearedevelopers.com/jobs/ext/1599964-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSM - **Company:** Systems, Inc - **Location:** Lincoln, NE, United States - **Experience:** Experienced - **Salary:** $180,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Security Management, NIPRNet, Package Development Process, Secure Coding, Systems Integration, Software Vulnerability Management, Information Technology, Devsecops, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://www.dice.com/job-detail/4168f7ca-f526-40e8-82bb-3cc9cc9689f0 ## About the Role * BS in cybersecurity, computer science, information assurance, or similar field plus 8+ years of cybersecurity experience on medium-to-large IT or software programs, including at least 4 years in an ISSM or equivalent leadership role * Direct experience implementing DoD RMF (and prior DIACAP) processes, including authoring and maintaining accreditation packages and FISMA-related records * Demonstrated experience leading or supporting DISA STIG compliance, vulnerability scanning, penetration testing, and testing in NIPR/SIPR and related environments * Familiarity with mission planning or similar weapon-system security contexts, including support for ATO and ATC activities and security targets * DoD-approved cybersecurity certification such as CISSP, CAP, or CISM * Active DoD Secret clearance (or higher) and the ability to maintain it throughout employment, * Master's degree in relevant field plus experience developing and maintaining enterprise cybersecurity master plans, Program Protection Plans, anti-tamper plans, and related security documentation * Familiarity with Air Force cybersecurity policy and coordination with AF network and accreditation authorities * Background in cyber resiliency for mission or weapon systems, including secure coding standards, security-focused scenarios, and user certification requirements * Experience integrating security controls into DevSecOps pipelines and CDE environments, including automated compliance and security testing * Prior experience addressing security considerations for FMS deliveries and multi-national information-sharing constraints ## Description SPA has a need for an Information System Security Manager (ISSM), who will serve as the overall cybersecurity lead for the systems and environments delivered under this contract. This individual will own RMF execution, accreditation package development, and coordination with government security stakeholders. The ISSM will be responsible for defining and enforcing cybersecurity and cyber-resiliency practices that are integrated into development, integration, and test activities across the Mission Planning Enterprise. #FC #Dice, The ISSM is responsible for the overall cybersecurity posture, compliance, and accreditation of systems delivered under this contract. They lead Risk Management Framework (RMF) activities, maintain security documentation and artifacts, and coordinate with government security officials on security testing, ATO/ATC actions, and policy compliance. The ISSM defines and enforces cybersecurity and cyber-resiliency practices across the development and integration lifecycle, including secure coding standards, vulnerability management, and security training. They work closely with engineering, test, and platform operations to embed security controls into architectures, pipelines, and test environments, ensuring that cybersecurity is a first-class aspect of the Mission Planning Enterprise. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)