> Markdown version of [/jobs/ext/2541652-issm](https://www.wearedevelopers.com/jobs/ext/2541652-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSM - **Company:** Accenture - **Location:** Hill Air Force Base, UT, United States - **Experience:** Experienced - **Salary:** $116,900.0 - $243,100.0 - **Contract:** Contract - **Skills:** Kubernetes Security, Amazon Web Services, Audit Trail, Microsoft Azure, Cyber Security, DevOps, Firmware, Data Flow Control, Identity and Access Management, Information Security Management, Information Technology Operations, Network Diagrams, Network Segmentation, Zero Trust Network Access, SAP (Applications), Kubernetes, Information Technology, CIS Benchmarks, Scap Compliance Checker, Docker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0a6c138f1bdc7794 ## About the Role * DoD 8140/8570 IAM Level III certification, such as CISSP or CISM * At least three (3) years of experience in an ISSM or equivalent security role * Experience leading small to medium-sized teams and driving accountability/ownership * Experience performing risk analysis, vulnerability assessments, and security audits * Strong technical writing skills (security plans, reports, technical writeups) to support documentation responsibilities Bonus Points if you have: * Eight (8) years of prior cybersecurity experience * Experience obtaining and maintaining Certificate to Field (CtF) packages * Experience providing and maintaining cybersecurity educational training and/or tabletop exercises * AWS or Azure technical certifications * Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or related field * Experience with Microsoft Defender or similar XDR/EDR tools * Experience with security incident response teams (NOC/SOC) * Familiarity with container security (Docker/Kubernetes/ECS/EKS/AKS) Security Clearance: * Must have an active TS/SCI level clearance ## Description We are seeking an experienced Information System Security Manager (ISSM) leader to support secure cloud systems and programs. The ISSM will assume responsibility for ensuring compliance, monitoring cybersecurity posture, supporting and driving RMF accreditation, and guiding the Information System Security Officers (ISSO) in the protection of classified systems. This position requires hands-on technical expertise, thorough familiarity with risk management processes, leadership of ISSO peers, and the ability to collaborate across development, operations, and security teams. Additionally, position will also require heavy coordination with other ISSMs and government POCs., * Lead high-performing team (5 to 10 individuals) and drive complete accountability/ownership * Develop, sustain, and maintain Rev 5 RMF documentation packages (SSP, SAP, SAR, POA&M, ConMon, etc.) * Lead development and sustainment of Authorization to Operate (ATO), Interim Authorization to Test (IATT), Incident Response Plan (IRP), and Body of Evidence (BoE) * Maintain the operational security posture consistent with the security authorization package and ATO requirements * Collaborate with Security Engineers, DevOps, and IT operations teams during the system design, integration, and development phases to evaluate risk and ensure compliance, including Zero Trust Architecture (ZTA) requirements * Implement cloud-native security solutions such as encryption, IAM, network segmentation * Develop and maintain network diagrams (PPSM, Dataflow, etc.) utilizing MBSE * Engage with Change Control Board (CCB) * Collaborate heavily with other ISSMs and AO/SCA teams * Lead and train the following ISSO workflows: + Perform continuous monitoring, vulnerability assessment, and risk analysis, validating remediation actions and documenting POA&M updates + Verify user clearance, need-to-know, and security responsibilities prior to system access + Ensure audit records are captured, reviewed regularly, and anomalies documented + Conduct regular system security reviews to ensure compliance with security authorization and STIG/CIS benchmarks and baselines + Coordinate hardware/software/firmware changes with ISSM and AO/DAO, notifying stakeholders of security-relevant changes + Participate in incident handling, reporting security incidents to ISSMs and AO/DAO teams, and tracking recovery actions to ensure controls are restored correctly + Ensure compliance with STIGs, utilizing SCAP Compliance Checker, Evaluate-STIG, and other DoD cyber assessment tools ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)