> Markdown version of [/jobs/ext/2181888-information-system-security-manager](https://www.wearedevelopers.com/jobs/ext/2181888-information-system-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager - **Company:** Amentum Services, Inc. - **Location:** Shaw Air Force Base, SC, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Configuration Management, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Package Development Process, Security Content Automation Protocol, Software Vulnerability Management, SC Clearance, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9112072/information-system-security-manager ## About the Role * A BS degree in Information Technology, Cybersecurity, Data Science, Information Systems, Computer Science, or equivalently relative discipline, from an ABET accredited or CAE designated institution. * Must have an active Top-Secret clearance with Sensitive Compartmented Information (TS/SCI) eligibility. US Citizenship is required. * Active DoD 8140 / DoDI 8570.01-M IAM Level II or III Certification matched to ISSM responsibilities prior to hiring. * Minimum 3-5 years of dedicated experience in RMF package development, continuous monitoring, and acting as an ISSM or lead ISSO. * Demonstrated proficiency in navigating and managing ATO packages within both eMASS and Xacta. Experience with STIGs, SCAP, vulnerability scanning, and ACAS/NESSUS. * Knowledge of cybersecurity laws, regulations, policies, governance, and technical safeguards governing the use, processing, storage, and transmission of classified information. * Exceptional communication skills, with the ability to confidently brief senior government leadership (AOs, SCAs, PMs) on cyber risk posture. * Must possess and maintain a valid state-issued driver's license. Preferred Qualifications: * Master's degree in a Cybersecurity or related field. * Experience with DODM 5205.07 Risk Management Framework, and familiarity with RPA SOC/C4 ISR mission system. Work Environment, Physical Demands, and Mental Demands: Typical office environment with no unusual hazards, occasional lifting of 20 pounds, kneeling, standing, and walking, routinely sitting and constant use of speech/hearing abilities for communication, constant mental alertness, and must be able to work under deadlines. ## Description The ISSM provides dedicated strategic cybersecurity leadership and oversight for designated classified information system enclaves supporting the 25th Attack Group (25 ATKW). Unlike a hybrid or tactical operations role, this position focuses exclusively on system-level cybersecurity governance, Risk Management Framework (RMF) compliance, and continuous monitoring to achieve and maintain Authorizations to Operate (ATO). The ISSM serves as the primary cybersecurity technical advisor to the Government Authorizing Official (AO), Program Manager (PM), and Information System Owner (ISO)., * Serve as the formally appointed Information Systems Security Manager (ISSM) for up to four contractor-managed Information Systems (including RPA Low, ACN, Audio MLS, and RPA High), overseeing the full lifecycle of cybersecurity compliance and system accreditation in accordance with DoDI 8510.01, AFI 17-101 (RMF), and AFMAN 17-1301 (COMPUSEC). * Develop, maintain, and oversee authorization documentation, System Security Plans (SSPs), risk assessments, and continuous monitoring activities using both eMASS and Xacta workflow platforms. * Act as the primary interface with Government Authorizing Officials (AOs) and Security Control Assessors (SCAs) to present risk assessments, initiate ATO packages, manage Plan of Action and Milestones (POA&Ms), and secure timely renewals. * Maintain rigorous oversight of vulnerability management, incident reporting, access control governance, and configuration management functions across assigned enclaves. * Provide oversight and guidance to subordinate cybersecurity personnel (ISSOs) to ensure security control implementation and mitigation efforts align with established baselines and mission requirements. * Provide contingency continuity support for tactical enclave cybersecurity (ISSO) activities during periods of workforce shortfalls or as critical mission needs dictate. * Report conditions that materially affect system authorization status or cybersecurity posture directly to the Government, translating technical risk into actionable mission risk. * Initiate exceptions, deviations, or waivers to cybersecurity requirements when operational impacts dictate, ensuring complete documentation and coordination with the AO. * Ensure all assigned personnel and systems remain compliant with applicable DoW/DoD 8140 cybersecurity workforce requirements. ## Related Videos - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)