> Markdown version of [/jobs/ext/2574813-information-system-security-manager](https://www.wearedevelopers.com/jobs/ext/2574813-information-system-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager - **Company:** Chickasaw Nation Industries, Inc. - **Location:** Ellsworth Air Force Base, SD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Information Security Management - **Published:** August 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c63915d1838ba704 ## About the Role The ability to obtain, maintain and access classified information at the Top Secret level. Required Certification at the DoD 8410 WRC 722, Advanced level - CISSP, CISSP-ISSMP, CISM, GCIH, GICSP, or GSLC. Must comply with Air Force cybersecurity directives, including IAVA, TCNO, and NOTAM implementation and verification requirements, Bachelors Degree or equivalent experience and eight (8) years of relevant IT/cybersecurity/systems engineering experience. ## Description The Information System Security Manager (ISSM) provides enterprise-level cybersecurity management, oversight, and leadership for Department of the Air Force Financial Management (DAF FM) systems. The ISSM ensures compliant implementation of cybersecurity policy, oversees the Risk Management Framework (RMF) lifecycle, guides the development and maintenance of authorization artifacts, and supports the Authorizing Official (AO) with risk-based decision materials. This role leads cybersecurity governance and collaborates closely with system owners, ISSOs, engineers, and program management staff to maintain security posture across all mission-critical FM systems., * Essential Duties and responsibilities include the following. Other duties may be assigned. * Lead and oversee the RMF lifecycle across all DAF FM systems, ensuring security control implementation, assessment preparation, and continuous monitoring compliance * Provide enterprise cybersecurity program guidance to the AO, AODR, ISSOs, and system owners to ensure compliant application of DoD, federal, and Air Force cybersecurity policies. * Manage and review all FM security authorization artifacts-including SSPs, RARs, POA&Ms, and supporting documentation-in eMASS and ITIPS. * Oversee enterprise vulnerability and risk management, including analysis of findings, mitigation strategy development, and remediation coordination across multiple FM systems. * Prepare and deliver risk-informed decision packages for the AO (ATO, ATO with Conditions, Denial), including mission impact analysis and risk justification. * Coordinate cybersecurity governance activities, lead technical briefings, and provide updates to FM leadership on enterprise cyber posture and authorization status. * Ensure secure implementation of system modifications and verify cybersecurity impact following engineering changes. * Mentor and guide ISSOs, cybersecurity analysts, and engineering staff in RMF processes, security control requirements, and compliance procedures. ## Related Videos - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Automated Driving - Why is it so hard to introduce](https://www.wearedevelopers.com/videos/628-automated-driving-why-is-it-so-hard-to-introduce) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)