> Markdown version of [/jobs/ext/2854260-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/2854260-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Booz Allen Hamilton Inc. - **Location:** Honolulu, HI, United States - **Experience:** Expert - **Salary:** $86,900.0 - $198,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Package Development Process, Plan of Action and Milestones - **Published:** September 11, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9066196/information-systems-security-manager ## About the Role * 8+ years of experience in cybersecurity compliance, information assurance, or IT security operations * Experience serving as an ISSM, ISSO, or RMF authorization role on DoD/DoW systems * Experience managing RMF Steps 1-6: Categorize through Authorize, and Step 7: Continuous Monitoring * Experience with eMASS, including authorization package development, control implementation statements, POA&M management, and artifact and evidence management * Experience supervising or mentoring ISSOs or junior compliance staff * Experience preparing systems for and supporting compliance audits, inspections, or assessments * Ability to communicate security risk and compliance status clearly to senior leaders, AOs, and SCAs * TS/SCI clearance * Bachelor's degree * DoD 8570/8140 IAM Level III certification Nice If You Have: * Experience with defense or national security issues in a specific theater or combatant command environment * Experience working at a DoD/DoW Command-level Headquarters * Experience with CNSSI 1253, NIST SP 800-53B, and DoD-specific overlays * Experience developing internal SOPs, naming conventions, or governance frameworks for artifact and control management * Experience with system boundary changes, categorization changes, or reauthorization packages * Experience hiring, interviewing, or building out a compliance team * Knowledge of cloud-hosted DoD systems, such as AWS, Azure, or GCP * Master's degree ## Description Department of War (DoW) information systems require continuous, disciplined oversight to stay authorized to operate and defensible against evolving threats. As a Senior Information System Security Manager (ISSM), you will own that oversight - serving as the principal cybersecurity authority for one or more system authorization packages across their full lifecycle. You'll manage the RMF process end-to-end: categorizing systems, selecting and tailoring controls, overseeing assessment and authorization activities, and maintaining continuous monitoring posture after ATO. You'll supervise a team of ISSOs, assigning control families, reviewing their work, and consolidating it into authoritative packages in eMASS. You'll coordinate directly with Authorizing Officials (AO), Authorizing Official Designated Representatives ( AODR), Security Control Assessors (SCA), and program leadership to resolve findings, manage POA&Ms, and drive packages to authorization on schedule. This role combines technical depth in NIST SP 800-53/800-37/800-137 with the leadership to run a compliance program: you'll set standards for documentation and artifact management, train and mentor ISSOs, and represent the security posture of your systems to senior stakeholders. ## Related Videos - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)