Information System Security Manager (ISSM)

MORSE Corp
Cambridge, MA, United States
13 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$90,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Cyber Security Information Systems Linux Identity and Access Management Information Security Management Network Administration Systems Development Life Cycle Security Information and Event Management Plan of Action and Milestones Vulnerability Analysis

Job description

The Information System Security Manager (ISSM) is responsible for ensuring that security considerations are taken into account in both classified and unclassified IT environments. The ISSM serves as an advisor for all matters related to the security of the information systems. The Cybersecurity Analyst uses various information security frameworks and agency-specific implementation guidance to obtain and maintain compliance for information systems Responsibilities

  • Ensure that systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan.
  • Participate in the systems development life cycle to ensure that the systems are designed with proper security features and safeguards.

  • Maintain security architecture (SIEM, Vulnerability Scanning, DS/IPS).
  • Collaborate with ISSMs, System Administrators, and Network Administrators to ensure information systems remain compliant.
  • Draft policies and procedures related to the security of the information system and ensure compliance with government requirements.
  • Test required controls, record assessments, and maintain the POA&M.
  • Perform continuous monitoring of security controls as required by NIST 800-37 and the Cybersecurity Maturity Model Certification (CMMC).
  • Analyze vulnerability scans for Linux, Windows, and AWS machines.
  • Research CVEs to understand remediation actions and present findings to System Administrators.

Requirements

  • 1 years of relevant cybersecurity experience.
  • A strong understand of NIST 800-37, NIST 800-171, or similar regulatory frameworks.
  • Prior experience implementing and assessing compliance with ACAS (Tenable) and HBSS (Trellix ePO) requirements.
  • Security+ CE, or other certification which meets the IAM Level I standard from DoD 8570.01-M is preferred.
  • Current Secret security clearance with the ability to obtain a Top Secret clearance and additional accesses as necessary. Current Top Secret preferred.

Benefits & conditions

MORSE Corp’s salary range for this role carefully considers a wide range of compensation factors, including but not limited to, prior experience, education, skills and expertise, location, internal equity, and other factors that are job related and consistent with business need. Therefore, final offer amounts may vary from the amount stated. Depending on role eligibility, total compensation may also include bonus, stock, 401(k) match, paid time off, medical, dental, vision and life insurance.

Employees also receive 10 paid holidays per year. MORSE maintains an “open” leave policy that does not restrict exempt, regular full-time employees to a specific number of paid sick or vacation days. However, this policy is not an “unlimited” paid leave policy.

About the company

MORSE Corp is an employee owned, small business based in Cambridge, MA, Arlington, VA, and Seattle, WA with a history of fielding cutting-edge technology. MORSE boasts a specially selected team of scientists, engineers, and software developers to deliver best-in-class technical solutions that solve difficult multidisciplinary problems faced by the US National Security Ecosystem.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:24 min

Installing premium packages using the Store CLI

Noraa Junker Noraa Junker · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all