> Markdown version of [/jobs/ext/2267098-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2267098-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager (ISSM) - **Company:** Riverside Research Institute - **Location:** Beavercreek, OH, United States - **Salary:** $130,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Information Systems, Firmware, Identity and Access Management, Information Security Management, SAP Project System, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Scap Compliance Checker - **Published:** August 27, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88162009/1 ## About the Role * Active Top Secret/SCI Security Clearance and the ability to obtain and maintain a polygraph * Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, Business, or a related discipline. * Twelve (12) years of progressively responsible experience in cybersecurity, information assurance, governance, risk, compliance, or related disciplines, including at least three (3) years of leadership experience managing technical teams or enterprise cybersecurity programs. * Above Experience to consist of: + NIST 800-53 and Risk Management Framework (RMF) based accreditations + Working in a classified environment consisting of multiple Collateral, SCI and/or SAP systems + Managing multiple projects at one time that could have many tasks within each. + Working with Windows operating systems + Developing standard operating procedures and system security plans + Supervising and mentoring ISSO level team * Certification Requirements: Current DoD 8570.1-M IAM Level 1 * Self-motivated and possess good written, verbal, listening and presentation skills * Strong customer service, leadership and team building skills * Organizational skills to include: attention to detail, time management, ability to multitask and prioritize. ## Description Riverside Research is seeking an Information System Security Manager to administer several classified programs, to include Assessment & Authorization (A&A) requirements. This position functions as an ISSM, responsible for the development and oversight of a comprehensive information security program as identified in applicable customer requirements to include NISPOM, ICD 503/CNSSI 1253, DFARS, NIST 800-53, NIST 800-171, JSIG, etc., Create and maintain A&A packages, System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Controls Traceability Matrices (SCTMs) and Plans of Action & Milestones (POA&Ms) for assigned classified systems * Establish and administer appropriate security systems, policies, standards, and procedures in compliance with applicable government and corporate directives, guidelines, and contractual obligations * Conduct analysis and assessment of the security control assessment guidance, procedures, and templates, ensuring correct and uniform implementation of the new RMF based assessment processes * Configure and validate information system compliance using DISA STIGs, SCAP Compliance Checker (SCC) and STIG Viewer * Conduct regular audits/CM in accordance with government customer requirements * Provide technical and professional leadership to support personnel, provide oversight for assigned classified system compliance and conduct self-assessments at multiple Riverside Research offices * Provide CM for security-relevant information system software, hardware and firmware * Investigate information system security violations and prepare reports with corrective actions and preventative measures. * Make recommendations regarding tools, trend analysis and applicable network countermeasures * Interfaces directly with DCSA or other DoD entities to conduct Information System security inspections, tests, and reviews * Guarantee system security requirements are addressed during all phases of system life cycle * Ensures system security assessments and audits are completed and documented * Certify that all Information System authorization documentation is current and accessible to authorized individuals * Supervisor assigned ISSO's ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)