> Markdown version of [/jobs/ext/2709084-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/2709084-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** ISTARI INC - **Location:** Cambridge, MA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Information Technology - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/information-systems-security-manager-issm-istari-7659182 ## About the Role * Minimum of 10 years of experience in a relevant field. * Deep understanding of cybersecurity principles, practices, and frameworks, including JSIG, NIST 800-171, NIST 800-53, ITAR, and CMMC. * Experience with risk assessments, vulnerability identification, and security control implementation. * Experience with security incident investigation and response. * Excellent communication and collaboration skills, with the ability to effectively communicate with both technical and non-technical audiences. * Strong analytical and problem-solving skills., * Bachelor's degree in computer science, information systems, or a related field. * Relevant certifications (e.g., CISSP, CISM).Experience with SOC compliance and audits. * Active TS Security Clearance. ## Description We are seeking a highly experienced and knowledgeable Information System Security Manager (ISSM) to join our Cybersecurity team. This role will be hybrid 3 days per week in our Arlington, VA office. The ISSM will serve as a principal advisor on all matters, technical and otherwise, involving the cybersecurity of information systems under their purview. This role requires a deep understanding of cybersecurity principles, practices, and frameworks, as well as the ability to develop, implement, and evaluate information system security program policy consistent with Federal and Commercial regulatory requirements. The ISSM will work closely with various stakeholders across the organization to ensure the confidentiality, integrity, and availability of our information systems., * Serve as the principal advisor on all matters involving the cybersecurity of assigned information systems. * Develop, implement, and evaluate information system security program policy consistent with Federal and Commercial regulatory requirements, including JSIG, NIST 800-171, NIST 800-53, CMMC, and ITAR. * Conduct risk assessments and identify vulnerabilities in information systems. * Develop and implement security controls to mitigate identified risks. * Monitor and evaluate the effectiveness of security controls. * Develop and deliver cybersecurity awareness training to employees. * Investigate security incidents and breaches. * Maintain security documentation, including system security plans (SSPs), risk assessments, and incident reports. * Stay up-to-date with the latest cybersecurity threats and vulnerabilities. * Collaborate with the engineering and customer success teams to ensure secure implementation and configuration of systems. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)