> Markdown version of [/jobs/ext/1990410-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/1990410-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager (ISSM) - **Company:** ASTRION, INC. - **Location:** Columbia, MD, United States - **Experience:** Expert - **Salary:** $137,000.0 - $205,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Audit Trail, Automation of Tests, Configuration Management, Cyber Security, Information Systems, Information Security Management, Internet Protocol, Network Security, Microsoft PowerPoint, SARS Software Products, National Industrial Security Program Operating Manual (NISPOM), User Administration, Plan of Action and Milestones, Vulnerability Analysis, User Accounts - **Published:** August 8, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87980317/1 ## About the Role * Bachelor's degree with 10-12 years of experience. * Minimum of 5 years of experience in leading a team or managerial role. * Experience in supporting U.S. Government clients. * Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment. * A CAP, CISM, or CISSP certification is required. * U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility., * Proficiency with Secure Internet Protocol Network establishment and maintenance. * Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA). * Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans. ## Description Astrion has an exciting opportunity for an experiencedInformation Systems Security Manager (ISSM) to assist in establishing, implementing, and maintaining the security program for classified information systems. The ISSM serves as the primary advisor to management on classified information system security and is the principal interface with DCSA on cybersecurity matters. The role is defined in 32 CFR Part 117 (NISPOM Rule) and further expanded in the DCSA Assessment and Authorization Guide (DAAG). Further, the ISSM will establish security instructions, manuals and policies based on guidance from the DoW, Navy, and MDA; this position is located in Columbia Maryland., * Information System Security Program Management - Develop, implement, and oversee the organization's classified Information System Security Program (ISSP). * Ensure compliance with the NISPOM, DAAG, RMF, and CSA guidance. * Establish policies, procedures, and technical standards for classified information systems. * Coordinate preparation of: System Security Plans (SSPs); Security Assessment Reports (SARs); Plan of Action & Milestones (POA&Ms); Continuous Monitoring Strategy. * Support Authorization to Operate (ATO) and reauthorization activities. * Maintain authorization packages in eMASS (where applicable). * Security Control Implementation: Verify management, operational, and technical controls remain effective; Monitor security control compliance throughout the system lifecycle. * Continuous Monitoring: Establish and manage a Continuous Monitoring (ConMon) program. * Review: Vulnerability scans; audit logs; security alerts; patch compliance; configuration management * Ensure deficiencies are documented and corrected. * Conduct self-inspections per 32 CFR *117.18, * Incident Reporting: ensure incidents are investigated are reported to DCSA and appropriate Government agencies; coordinate incident response activities; maintain incident documentation, and track remediation activities. * Configuration Management: approve and monitor configuration changes; ensure security impact analyses are completed; verify secure baseline configurations; maintain system inventories. * User Management: approve user access procedures; ensure least privilege is enforced; review privileged accounts; ensure user accounts are disabled when no longer required. * Partner with the IT team to coordinate POA&M remediation, review and approve configuration changes, evaluate requested new software prior to deployment, and drive close collaboration between the Information Systems Security (ISS) and IT teams. * Training and Awareness: ensure users receive initial and annual cybersecurity training; promote insider threat awareness within the IS security program. * Coordination with Insider Threat Program. * Coordination with the FSO. * Interface with Defense Counterintelligence and Security Agency (DCSA) and other government agencies. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Full-stack role-based authorization in 45 minutes](https://www.wearedevelopers.com/videos/312-full-stack-role-based-authorization-in-45-minutes) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)