> Markdown version of [/jobs/ext/2546137-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2546137-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - **Company:** KBR Inc - **Location:** El Segundo, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Systems, Information Security Management, Information Technology, Scap Compliance Checker, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://dejobs.org/x/x/599071DFC3904929A369DFE010D25646/job/ ## About the Role * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field; or equivalent combination of education and experience. * Active DoD Top Secret security clearance with SCI eligibility. * Current DoD 8570-compliant certification. * 5+ years of experience performing ISSM and/or ISSO responsibilities in classified environments. * Experience supporting Risk Management Framework (RMF) authorization and compliance activities. Technical & Leadership Skills * Knowledge of Assessment & Authorization (A&A) processes and RMF requirements. * Experience developing RMF artifacts, including Security Plans, Risk Assessments, and POA&Ms. * Familiarity with cybersecurity compliance tools such as eMASS, ACAS, Xacta, and SCAP Compliance Checker. * Working knowledge of NIST security standards and DISA STIGs. * Strong organizational, analytical, and problem-solving skills. * Excellent written and verbal communication skills with the ability to collaborate across technical and non-technical teams. Preferred Qualifications * Experience supporting Department of Defense or Intelligence Community programs. * Experience working within multi-enclave or classified network environments. ## Description KBR is seeking an Information System Security Manager (ISSM) to support Assessment & Authorization (A&A) activities and cybersecurity policy and procedure development under the Information Assurance organization. This position is responsible for helping obtain and maintain Authorizations to Operate (ATOs) for assigned systems, applications, networks, and devices. Based in El Segundo, California, the ISSM reports directly to the West Regional ISSM and supports the development, implementation, and enforcement of cybersecurity practices across assigned systems and locations., * Serve as the onsite representative of the Information Assurance Operations organization and provide subject matter expertise on cybersecurity and information assurance activities. * Conduct risk and vulnerability assessments to identify security risks, vulnerabilities, and protection requirements. * Lead and participate in Assessment & Authorization (A&A) and Risk Management Framework (RMF) meetings with government and contractor personnel. * Support the development and implementation of cybersecurity policies, procedures, and process improvements. * Develop, review, and maintain RMF documentation, including Security Plans, Risk Assessment Reports, and Plans of Action & Milestones (POA&Ms). * Assess system compliance with applicable NIST, DoD, and Intelligence Community security requirements, including NIST SP 800-53, NIST SP 800-171, and DISA STIGs and SRGs. * Coordinate with system administrators, engineers, developers, and other stakeholders to support authorization efforts and maintain required security documentation. * Analyze vulnerability scan results and assist with remediation activities to maintain compliance and reduce cybersecurity risk. * Provide regular status updates, brief stakeholders on authorization activities, and prepare reports for leadership. * Maintain awareness of evolving cybersecurity standards, RMF guidance, and security requirements and apply updates to assigned systems and processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)