> Markdown version of [/jobs/ext/2529029-senior-information-systems-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2529029-senior-information-systems-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Security Manager (ISSM) - **Company:** KBR Inc - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Systems, Information Technology, Scap Compliance Checker - **Published:** August 18, 2026 - **Apply:** https://kbr.wd5.myworkdayjobs.com/KBR_Careers/job/Colorado-Springs-Colorado/Senior-Information-Systems-Security-Manager--ISSM-_R2128379 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline. * 10+ years of progressive experience including 5+ years of experience performing Information Systems Security Manager (ISSM) duties in classified and unclassified environments. * Experience supporting Risk Management Framework (RMF) authorizations and Assessment & Authorization (A&A) activities. * Experience leading cybersecurity efforts across multiple sites, programs, or geographically dispersed organizations. * Active DoD Top Secret security clearance with SCI eligibility required. * Current DoD 8570-compliant certification required. Technical & Leadership Skills * Working knowledge of NIST 800-53, NIST 800-171, DISA STIGs, SRGs, and related DoD or Intelligence Community security requirements. * Experience developing and maintaining RMF documentation, including Security Plans, Risk Assessment Reports, and POA&Ms. * Experience using cybersecurity and compliance tools such as eMASS, ACAS, SCAP Compliance Checker, Xacta, or similar platforms. * Strong communication, organizational, problem-solving, and stakeholder management skills. Preferred Qualifications * CISSP, CAP, CASP+, or similar advanced cybersecurity certification. * Experience supporting Intelligence Community (IC) programs or accreditation activities. * Experience developing cybersecurity policies, procedures, and governance processes. * Experience supporting multiple classified facilities or geographically dispersed operations. * Experience leading cybersecurity process improvement initiatives. ## Description KBR is seeking a Senior Information Systems Security Manager (ISSM) in Colorado Springs, Colorado to join our Information Assurance organization. Reporting to the Information Assurance Operations Manager, this role serves as the regional cybersecurity lead for multiple sites across the Western United States, overseeing Assessment & Authorization (A&A) activities, Risk Management Framework (RMF) compliance, cybersecurity policy implementation, and system authorization efforts for classified and unclassified environments., The Senior ISSM serves as a trusted advisor to government customers, business leadership, and technical stakeholders while providing oversight and guidance to Information Assurance professionals supporting multiple programs and locations. This position plays a critical role in maintaining Authorizations to Operate (ATOs), driving cybersecurity compliance initiatives, implementing enterprise security policies, and strengthening KBR's overall security posture across the assigned region., * Serve as the Regional Information Systems Security Manager (ISSM) for multiple sites across the Western U.S. region, providing cybersecurity oversight for classified and unclassified environments. * Lead Assessment & Authorization (A&A) activities and maintain Authorizations to Operate (ATOs) for assigned systems, applications, networks, and devices. * Provide technical leadership and guidance to Information Assurance personnel and site ISSMs supporting regional programs. * Develop, review, and maintain RMF documentation, including Security Plans, Risk Assessment Reports, Implementation Plans, and Plans of Action & Milestones (POA&Ms). * Ensure compliance with applicable cybersecurity requirements, including NIST 800-53, NIST 800-171, DISA STIGs, SRGs, and other government security frameworks. * Serve as a trusted advisor to government customers, program leadership, and technical teams on cybersecurity, compliance, and risk management matters. * Partner with Information Technology, Industrial Security, Facility Support, and program stakeholders to resolve cybersecurity issues and support authorization efforts. * Monitor evolving cybersecurity policies, regulations, and standards, ensuring timely implementation across assigned sites. * Lead cybersecurity assessments, compliance reviews, and continuous monitoring activities to identify, track, and mitigate security risks. * Prepare and deliver status reports, metrics, and briefings regarding authorization activities, compliance posture, and cybersecurity initiatives. * Support process improvement initiatives focused on RMF execution, cybersecurity governance, and operational effectiveness. * Utilize enterprise cybersecurity tools, including eMASS, ACAS, SCAP Compliance Checker, Xacta, and related technologies to support security and compliance activities. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)