> Markdown version of [/jobs/ext/2026075-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2026075-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager (ISSM) - **Company:** AnaVation, LLC - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Cyber Security, OpenShift, Zero Trust Network Access, Software Engineering, Software Factory, Software Vulnerability Management, SARS Software Products, Cloud Platform System, Kubernetes, Information Technology, Cyber Warfare, Devsecops, Plan of Action and Milestones - **Published:** August 11, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87995769/1 ## About the Role * Clearance: U.S. Citizen, TS/SCI cleared within last 2 years; CI Polygraph within last 5 years * Education: Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or related field * Certification: One or more of the following: CISSP, CASP+, Security+ or Equivalent DoD 8140 certification * Location: Full-time on-site in San Antonio, TX. * Experience and knowledge: + Nine or more years supporting Department of Defense cybersecurity missions. + Nine or more years serving as an ISSM, ISSE, or senior cybersecurity engineer. + Experience implementing the Risk Management Framework (RMF). + Experience achieving and maintaining Authority to Operate (ATO). + Experience supporting Continuous Monitoring programs. + Experience supporting DevSecOps environments. + Experience supporting Agile or SAFe software development. + Experience supporting enterprise cloud environments. + Knowledge of NIST RMF, NIST 800-53, CNSSI guidance, DoD cybersecurity policy, and STIG implementation. + Experience briefing senior Government leadership. + Excellent written and verbal communication skills., * Clearance: TS/SCI w/CI Poly * Education: Advanced degree in Cybersecurity, Computer Science, Engineering, Information Assurance, or related field. * Certification: One or more of the following: CISSP-ISSMP, AWS Security Specialty, Certified Cloud Security Professional (CCSP). * Experience an Knowledge: + Nine or more years supporting DoD cybersecurity missions. + Experience supporting software factories. + Experience supporting Kubernetes and OpenShift. + Experience supporting Iron Bank or hardened container environments. + Experience supporting Continuous ATO (cATO). - Experience implementing Zero Trust architectures. + Experience supporting enterprise DevSecOps pipelines. + Experience supporting IL4/IL5/IL6 cloud environments. + Experience supporting software factories. + Experience supporting Cyber Operations Teams. + Experience supporting Cyber Penetration Teams. + Experience supporting multiple military services and Combatant Commands. ## Description AnaVation is seeking a highly motivated Information Systems Security Manager (ISSM) who is responsible for cybersecurity engineering, cyber policy, and Risk Management Framework (RMF) activities supporting Department of Defense software factories and enterprise cloud environments. The ISSM will serve as the cybersecurity lead supporting one or more agile teams, integrating directly with Government leadership, Cyber Operations Teams (COT), Cyber Penetration Teams (CPT), Product Owners, Software Engineers, and DevSecOps personnel to maintain secure cloud-native capabilities while accelerating software delivery through Continuous Authority to Operate (cATO). This position supports enterprise cybersecurity operations spanning multiple mission value streams and classified environments, ensuring secure software delivery while balancing mission execution, cybersecurity risk, and compliance with Department of Defense policies. The position requires full-time support within classified environments in San Antonio, Texas, with routine collaboration across mission engineering, cybersecurity, operations, and acquisition organizations., Position Responsibilities: The ISSM will provide technical leadership supporting cybersecurity engineering, RMF execution, and continuous cybersecurity operations across software delivery environments., * Lead RMF implementation supporting initial ATOs and Continuous ATO (cATO). * Serve as the cybersecurity lead supporting multiple mission value streams. * Develop and maintain RMF authorization packages including SSPs, SARs, POA&Ms and supporting artifacts. * Coordinate cybersecurity assessments with Authorizing Officials, Security Control Assessors, penetration testing teams, and engineering organizations. * Integrate cybersecurity requirements into Agile and SAFe software development activities. * Support planning, execution, remediation, and continuous monitoring. * Ensure cybersecurity controls remain operational across development, testing, staging, and production environments. * Coordinate vulnerability management, STIG implementation, POA&M tracking, and security control validation. * Support Zero Trust implementation, cloud security, Kubernetes/OpenShift security, container hardening, and DevSecOps pipeline security. * Evaluate cybersecurity risks and provide mitigation recommendations supporting mission operations. * Support annual cyber assessments, inspections, and operational readiness activities. * Develop executive-level briefings, risk assessments, and cybersecurity recommendations. * Support operations across Unclassified, Secret, and SCI environments as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)