> Markdown version of [/jobs/ext/2443207-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2443207-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - **Company:** KBR Inc - **Location:** Beavercreek, OH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Systems, Information Security Management, Systems Architecture, Software Vulnerability Management, Information Technology, Scap Compliance Checker, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/4BBF0A0980A94A67887D70B01ECA477E/job/ ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline. * 10+ years of experience in Cybersecurity, Information Technology, or a related area with 5+ years of experience performing ISSM and/or ISSO responsibilities in classified environments. * Active DoD Top Secret security clearance with SCI eligibility. * Current DoD 8570-compliant certification. * Experience implementing and managing the Risk Management Framework (RMF). * Experience developing and maintaining RMF authorization packages and supporting ATO efforts. Technical & Leadership Skills * Knowledge of Assessment & Authorization (A&A) processes and cybersecurity compliance requirements. * Experience assessing systems against NIST SP 800-53 controls and/or DISA STIG and SRG requirements. * Experience developing RMF artifacts, including Security Plans, Risk Assessments, and POA&Ms. * Proficiency with cybersecurity and compliance tools such as eMASS, ACAS, Xacta, and SCAP Compliance Checker. * Strong analytical, organizational, and problem-solving skills. * Excellent written and verbal communication skills with the ability to collaborate across technical and non-technical teams., * Experience supporting Department of Defense, Intelligence Community, or other federal government cybersecurity programs. * Experience serving as the primary ISSM for multiple systems or security enclaves. * Working knowledge of enterprise vulnerability management and continuous monitoring programs. Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance. ## Description KBR is seeking an Information System Security Manager (ISSM) to serve as the onsite cybersecurity lead supporting Assessment & Authorization (A&A) activities and cybersecurity policy and procedure development to obtain and maintain Authorizations to Operate (ATOs) for assigned systems, applications, networks, and devices. Based in Beavercreek, Ohio, this position reports directly to the Information Assurance (IA) Operations Manager and serves as the primary onsite representative of the IA Operations organization. The ISSM develops and implements cybersecurity strategies, advises stakeholders on risk management and compliance requirements, and ensures adherence to applicable Department of Defense (DoD), Intelligence Community (IC), and National Institute of Standards and Technology (NIST) security standards., * Serve as the onsite representative and subject matter expert (SME) for Information Assurance activities across multiple enclaves and network environments. * Provide solutions to complex cybersecurity and compliance challenges requiring specialized technical expertise, independent judgment, and creative problem-solving. * Conduct risk and vulnerability assessments of information systems to identify security risks, vulnerabilities, and protection requirements. * Lead and participate in Assessment & Authorization (A&A) status meetings with government and contractor personnel to facilitate Risk Management Framework (RMF) efforts and address issues impacting authorization activities. * Support the development, implementation, and continuous improvement of cybersecurity policies, procedures, and processes. * Maintain awareness of evolving cybersecurity, RMF, NIST, DoD, and IC requirements and apply relevant changes to organizational practices and system authorization efforts. * Develop, review, and maintain RMF documentation, including Security Plans (SPs), Risk Assessment Reports (RARs), Implementation Plans, and Plans of Action and Milestones (POA&Ms). * Assess system compliance against NIST, DoD, and IC cybersecurity requirements, including NIST SP 800-53, NIST SP 800-171, DISA Security Technical Implementation Guides (STIGs), and Security Requirements Guides (SRGs). * Generate, collect, and maintain evidence required to demonstrate compliance with RMF security controls and authorization requirements. * Collaborate with system administrators, engineers, developers, and other stakeholders to create and maintain system and site security policies, procedures and process documentation. * Coordinate with technical SMEs to develop authorization boundary diagrams, system architecture diagrams, and hardware and software inventories. * Analyze vulnerability scan results and support remediation efforts to reduce cybersecurity risk and maintain compliance. * Participate in recurring IA Operations team meetings to provide RMF package updates, communicate system status, identify risks or issues, and obtain guidance as needed. * Lead or participate in stakeholder meetings regarding authorization activities, compliance status, and cybersecurity initiatives. * Prepare and submit weekly status reports to leadership regarding system and program progress. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany)