> Markdown version of [/jobs/ext/2203860-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2203860-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager (ISSM) - **Company:** Kratos Defense & Rocket Support Services, Inc - **Location:** Glen Burnie, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Software System Penetration Testing, Configuration Management, Cyber Security, Information Systems, Linux, Hardware Virtualization, HP Thin Clients, Identity and Access Management, Information Security Management, Network Security, SAP (Applications), Software Vulnerability Management, Data Logging, Information Security Management System, Information Technology, CIS Benchmarks, Plan of Action and Milestones - **Published:** August 23, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18047780?backUrl=%2Fcareer%2F18047780%2FInformation-Systems-Security-Manager-Issm-Maryland-Glen-Burnie ## About the Role * U.S. Citizenship required. * Thorough understanding of US Government (specifically DoD) IS security policies. * Strong communication skills, strong critical thinking and problem-solving skills; self-motivated with ability to effectively prioritize multiple projects; ability to work with people in a team environment and deal effectively with changing project priorities. * Ability to manage time, make sound decisions, take independent action, analyze problems and provide focused solutions. * High degree of attention to detail. * Must have active in-scope TOP SECRET clearance and be able to obtain and maintain access to Sensitive Compartmented Information (SCI) and/or any necessary Special Access Programs (SAP). * DoD 8140/DoD 8570 approved (IAM Level 2-3) certification required within 6 months of hire., * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent experience may be considered. * 5+ years of experience in Information Technology (IT) in a classified environment, or 3+ years of experience as an ISSM/ISSO in government/industrial security or an intelligence career field. * Strong understanding of identity and access management, endpoint security, network security, logging/monitoring, and incident response * Experience administering Windows and Linux operating systems, experience with large-scale server systems, thin client architecture, system virtualization and other related peripherals. * Strong understanding of cybersecurity frameworks such as NIST CSF, NIST SP 800-53, RMF, ISO 27001, CIS Controls, or equivalent. ## Description We are seeking an experienced and highly motivated Information Systems Security Manager (ISSM) to lead the security management and compliance activities for information systems supporting our organization. The ISSM will be responsible for ensuring systems are securely designed, implemented, operated, and maintained in accordance with organizational security policies, regulatory requirements, and applicable cybersecurity frameworks., * Implement the risk management framework for classified systems, typically following the Defense Counterintelligence Security Agency (DCSA), DAAG or JSIG process and supporting communications with cognizant security authorities. * Serve as the primary point of contact for classified systems. * Produce and maintain Body of Evidence (BoE) documentation to include risk assessments, System Security Plan (SSPis) and Plan of Action and Milestones (POA&Mis). * Maintain the day-to-day security posture and continuous monitoring for all systems, including patching and updates. * Assist Information Security team in unclassified security operations, including continuous monitoring, incident response, and vulnerability management. * Assist Information Technology team in unclassified services functions. * Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the information systems. * Ensures adherence to these information system security policies and procedures. * Coordinate vulnerability management, security assessments, penetration testing, and remediation activities. * Performs oversight and provides guidance for media sanitization and destruction. * Confirms domain/local policies are configured to meet regulatory requirements. * Assesses changes to the system/operational needs that could affect its accreditation. * Voting/veto member of the CCB for all systems. * Assists with coordination between Kratos and Defense and Government authorities regarding system security posture requirements. * Participate in information system security inspections, tests, and reviews. * Maintains a working knowledge of system functions, security policies, technical security safeguards and operational security measures. * Schedules periodic testing to evaluate the security posture of IS. * Develops an effective information system security education, training, and awareness program. * Interfaces with internal and external customers and auditors, program managers, IT, security staff, etc. * Support security incident response, investigations, and corrective actions. Other Job Functions * Serve as a member of the Configuration Control Board as necessary * Other duties as assigned SUPERVISORY RESPONSIBILITY: Coordination of Information System Security Officers (ISSO) and System Administrators (SysAdmins) Other duties as assigned Keyword: Information Systems Security Manager (ISSM) ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)