Information Systems Security Manager (ISSM)

ASTRION, INC.
Columbia, MD, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$137,000.0 - $205,000.0
Working hours
Regular working hours

Tech stack

Microsoft Word Microsoft Excel Audit Trail Automation of Tests Configuration Management Cyber Security Information Systems Information Security Management Internet Protocol Network Security Microsoft PowerPoint SARS Software Products
+5 more
National Industrial Security Program Operating Manual (NISPOM) User Administration Plan of Action and Milestones Vulnerability Analysis User Accounts

Job description

Astrion has an exciting opportunity for an experiencedInformation Systems Security Manager (ISSM) to assist in establishing, implementing, and maintaining the security program for classified information systems. The ISSM serves as the primary advisor to management on classified information system security and is the principal interface with DCSA on cybersecurity matters. The role is defined in 32 CFR Part 117 (NISPOM Rule) and further expanded in the DCSA Assessment and Authorization Guide (DAAG). Further, the ISSM will establish security instructions, manuals and policies based on guidance from the DoW, Navy, and MDA; this position is located in Columbia Maryland., * Information System Security Program Management - Develop, implement, and oversee the organization’s classified Information System Security Program (ISSP).

  • Ensure compliance with the NISPOM, DAAG, RMF, and CSA guidance.
  • Establish policies, procedures, and technical standards for classified information systems.
  • Coordinate preparation of: System Security Plans (SSPs); Security Assessment Reports (SARs); Plan of Action & Milestones (POA&Ms); Continuous Monitoring Strategy.
  • Support Authorization to Operate (ATO) and reauthorization activities.
  • Maintain authorization packages in eMASS (where applicable).
  • Security Control Implementation: Verify management, operational, and technical controls remain effective; Monitor security control compliance throughout the system lifecycle.
  • Continuous Monitoring: Establish and manage a Continuous Monitoring (ConMon) program.
  • Review: Vulnerability scans; audit logs; security alerts; patch compliance; configuration management
  • Ensure deficiencies are documented and corrected.
  • Conduct self-inspections per 32 CFR *117.18,
  • Incident Reporting: ensure incidents are investigated are reported to DCSA and appropriate Government agencies; coordinate incident response activities; maintain incident documentation, and track remediation activities.
  • Configuration Management: approve and monitor configuration changes; ensure security impact analyses are completed; verify secure baseline configurations; maintain system inventories.
  • User Management: approve user access procedures; ensure least privilege is enforced; review privileged accounts; ensure user accounts are disabled when no longer required.
  • Partner with the IT team to coordinate POA&M remediation, review and approve configuration changes, evaluate requested new software prior to deployment, and drive close collaboration between the Information Systems Security (ISS) and IT teams.
  • Training and Awareness: ensure users receive initial and annual cybersecurity training; promote insider threat awareness within the IS security program.
  • Coordination with Insider Threat Program.
  • Coordination with the FSO.
  • Interface with Defense Counterintelligence and Security Agency (DCSA) and other government agencies.

Requirements

  • Bachelor’s degree with 10-12 years of experience.
  • Minimum of 5 years of experience in leading a team or managerial role.
  • Experience in supporting U.S. Government clients.
  • Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment.
  • A CAP, CISM, or CISSP certification is required.
  • U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility., * Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · WWC Europe 2026

3:44 min

Domain modeling for multi-user scalable account systems

Bartosz Pietrucha · JS Congress

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all