> Markdown version of [/jobs/ext/2571739-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/2571739-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - **Company:** MORSE Corp - **Location:** Cambridge, MA, United States - **Salary:** $90,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Cyber Security, Information Systems, Linux, Identity and Access Management, Information Security Management, Network Administration, Systems Development Life Cycle, Security Information and Event Management, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 24, 2026 - **Apply:** https://www.dice.com/job-detail/abdae2ae-3d36-4021-9ee8-ae5d0bd116c8 ## About the Role * 1 years of relevant cybersecurity experience. * A strong understand of NIST 800-37, NIST 800-171, or similar regulatory frameworks. * Prior experience implementing and assessing compliance with ACAS (Tenable) and HBSS (Trellix ePO) requirements. * Security+ CE, or other certification which meets the IAM Level I standard from DoD 8570.01-M is preferred. * Current Secret security clearance with the ability to obtain a Top Secret clearance and additional accesses as necessary. Current Top Secret preferred. ## Description The Information System Security Manager (ISSM) is responsible for ensuring that security considerations are taken into account in both classified and unclassified IT environments. The ISSM serves as an advisor for all matters related to the security of the information systems. The Cybersecurity Analyst uses various information security frameworks and agency-specific implementation guidance to obtain and maintain compliance for information systems Responsibilities * Ensure that systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan. * Participate in the systems development life cycle to ensure that the systems are designed with proper security features and safeguards. * Maintain security architecture (SIEM, Vulnerability Scanning, DS/IPS). * Collaborate with ISSMs, System Administrators, and Network Administrators to ensure information systems remain compliant. * Draft policies and procedures related to the security of the information system and ensure compliance with government requirements. * Test required controls, record assessments, and maintain the POA&M. * Perform continuous monitoring of security controls as required by NIST 800-37 and the Cybersecurity Maturity Model Certification (CMMC). * Analyze vulnerability scans for Linux, Windows, and AWS machines. * Research CVEs to understand remediation actions and present findings to System Administrators. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [How Lufthansa Industry Solutions is preparing for the Quantum Age! ](https://www.wearedevelopers.com/videos/1443-how-lufthansa-industry-solutions-is-preparing-for-the-quantum-age) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)