> Markdown version of [/jobs/ext/1614374-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/1614374-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Foxtrot Division - **Location:** Barcelona, Spain - **Contract:** Contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, SARS Software Products, Information Technology - **Published:** July 3, 2026 - **Apply:** https://es.trabajo.org/oferta-3206-9ac68877aab323f438dbadfedcf29fed ## About the Role Supervise, mentor, and provide technical guidance to ISSOs, cybersecurity analysts, and security personnel while fostering a culture of security awareness and accountability.- Develop and manage cybersecurity awareness, role-based training, and workforce development programs to enhance organizational cybersecurity maturity.- Support cybersecurity budget planning, resource management, acquisition activities, and evaluation of emerging security technologies to strengthen organizational security posture.- Advise senior leadership on cybersecurity strategy, emerging threats, organizational risk exposure, and regulatory compliance requirements to ensure secure and mission-aligned operations.Required Qualifications- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field (Master's degree preferred).- 10+ years of experience in Information Assurance, Cybersecurity, Information Security, or Risk Management, including at least 5 years ## Description members are aligned with our core purpose. Through this alignment, we aim to leave a lasting, positive impact on the world, driving us further and faster towards our vision of excellence, with our people leading the charge.The Information Systems Security Manager (ISSM) serves as the senior cybersecurity leader responsible for overseeing and maintaining the security, compliance, and risk management of enterprise information systems. This role leads cybersecurity strategy, Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, and authorization efforts while ensuring compliance with federal and DoD cybersecurity requirements. The ISSM works closely with executive leadership, system owners, and security teams to protect organizational assets, manage cybersecurity risks, and maintain secure, authorized operations across the enterprise.Key Responsibilities- Serve as the senior cybersecurity authority and subject matter expert (SME) responsible for the organization's Information Assurance (IA) and Cybersecurity Program.- Lead the planning, implementation, governance, and continuous improvement of cybersecurity policies, standards, procedures, and best practices across the enterprise.- Direct and oversee Risk Management Framework (RMF) activities throughout the system lifecycle, ensuring systems achieve and maintain Authority to Operate (ATO), Interim Authority to Operate (IATO), or Authorization to Connect (ATC) status.- Provide strategic leadership for cybersecurity risk management, continuous monitoring, compliance, and security modernization initiatives.- Review, approve, and maintain cybersecurity authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Security Control Traceability Matrices (SCTMs), and contingency planning documentation.- Serve as the primary liaison between Authorizing Officials (AOs), Information System Owners (ISOs), Information System Security Officers (ISSOs), system administrators, executive leadership, and external cybersecurity stakeholders.- Lead enterprise vulnerability management, remediation efforts, and security assessment activities to identify, prioritize, and mitigate cybersecurity risks.- Oversee continuous monitoring programs, security control effectiveness assessments, penetration testing reviews, audit response activities, and compliance reporting.- Develop and present executive-level cybersecurity metrics, risk assessments, and compliance status reports to support informed decision-making.- Coordinate cybersecurity inspections, audits, and assessments, ensuring timely remediation of findings from Security Control Assessors (SCAs), Inspector General (IG), Government Accountability Office (GAO), and other oversight organizations.- Provide leadership and oversight during cybersecurity incidents, coordinating response efforts, risk mitigation strategies, and post-incident corrective actions.- ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)