> Markdown version of [/jobs/ext/2352275-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2352275-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager ISSM - **Company:** KMS Solutions, LLC - **Location:** Alexandria, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Windows, Systems Engineering, Microsoft Outlook, Cyber Security, Information Systems, Linux, Identity and Access Management, Microsoft Office, Nmap, Microsoft PowerPoint, Security Content Automation Protocol, Systems Integration, Software Vulnerability Management, SC Clearance, Navsea, Information Technology, Workday, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b8120b11b25bb89f ## About the Role * Bachelor's degree in cybersecurity, information systems, engineering, mathematics, or related discipline. * Minimum 5 years of cybersecurity or RMF-based experience supporting DoD systems. * DoD 8570.01M IAT/IAM Level II or III certification (e.g., Security+). * Operating Systems certification (Windows or Linux). * Experience with RMF, A&A processes, and cybersecurity validation of DoD IT systems. * Experience using eMASS. * Equivalent combinations of education and experience will be considered. Preferred Education and Experience * Master's degree in cybersecurity, information systems, or engineering. * 6-8+ years of cybersecurity experience supporting DoD or Navy cybersecurity programs (NSW/SOF or undersea systems preferred). * Navy Qualified Validator (NQV). * Experience with NIST RMF, Navy cybersecurity policy, and DIACAP-to-RMF transitions. * Systems engineering or system integration experience. Competencies * Proficiency in Microsoft Office, specifically, Word, Excel, PowerPoint, and Outlook software. * Excellent verbal and written communication skills; ability to clearly articulate technical requirements. * Ability to independently perform cybersecurity assessments and analyses. * Thoroughness, attention to detail, and disciplined documentation habits. * Ability to work collaboratively across engineering, acquisition, and cybersecurity teams. * Must be highly reliable and demonstrate personal initiative to operate in a fast-paced environment with changing priorities., * This position requires the ability to obtain and/or maintain a Secret DoD Security Clearance and required access to all worksite locations. Security clearances may only be granted to U.S. citizens. * Legally authorized to work in the United States at the time of hire and throughout employment., While performing the duties of this job, the employee is regularly required to talk and hear. The employee is frequently required to stand, walk, use hands to finger, handle or feel, and reach with hands and arms. Must be able to lift up to 20 lbs. Position Type/Expected Hours of Work: The typical workday is eight hours in length. Some flexibility in hours is allowed, with concurrence from the supervisor. Attendance at mandatory meetings is required. Must be available during the core work hours as determined by the contract/location and must account for the required number of hours in a pay period to maintain Full-time status. ## Description KMS solutions, LLC is seeking a highly motivated individual for an Information Systems Security Manager (ISSM) position providing senior-level cybersecurity leadership, oversight, and Risk Management Framework (RMF) support to the Naval Special Warfare (NSW) and expeditionary systems managed by PMS 340. PMS 340's mission encompasses manned and unmanned undersea systems, surface systems, air operations, visual augmentation systems, small arms, diving systems, and Special Operations Forces (SOF) maritime capabilities. The ISSM will serve as the cybersecurity authority for PMS 340, responsible for system accreditation, cybersecurity engineering, vulnerability management, and ensuring compliance with DoD, DoN, NAVSEA, NIST, and CNSSI cybersecurity requirements., Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. * Lead development, maintenance, and submission of RMF accreditation packages for PMS 340 systems, ensuring compliance with DoD, DoN, NAVSEA CS-DoN SOPs, and business rules. * Oversee cybersecurity documentation including SSPs, POA&Ms, validation procedures, and risk assessments, ensuring systems meet information assurance and security requirements. * Conduct and oversee security control assessments in accordance with NIST SP 800-53, 800-53A, CNSSI 1253, and RMF requirements. * Perform and direct vulnerability assessment and compliance reviews using ACAS, SCAP, and Nmap for PMS 340 systems. * Manage cybersecurity workflows and accreditation artifacts using eMASS. * Support cybersecurity Test & Evaluation phases including cooperative vulnerability identification, adversarial testing, penetration assessments, and adversarial assessments. * Identify and mitigate cybersecurity risks across PMS 340 systems; ensure risk treatment, compliance, and monitoring throughout the system lifecycle. * Coordinate cybersecurity activities across NAVSEA, NSW, SOCOM, NUWC, and other stakeholders, supporting IPTs, Working Groups, and program reviews. * Prepare cybersecurity reports, briefs, and documentation, clearly articulating cybersecurity requirements to PMO leadership and technical teams. * Provide cybersecurity guidance, engineering support, and subject matter expertise for PMS 340 systems, including undersea, maritime, surface, air, and expeditionary technologies. * Support PMS 340 leadership in ad hoc cybersecurity meetings and engagements, including those requiring travel. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)