> Markdown version of [/jobs/ext/2921946-information-system-security-manager](https://www.wearedevelopers.com/jobs/ext/2921946-information-system-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager - **Company:** Inc. (spa) - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Salary:** $150,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Complex Networks, Cyber Security, Information Systems, Linux, Firmware, Identity and Access Management, Information Security Management, Intrusion Detection Systems, Windows Domain, Network Routers, Firewalls (Computer Science), Information Technology, Network Server - **Published:** September 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9162226/information-system-security-manager ## About the Role * Bachelor's Degree in Information Security, Information Technology, or related discipline, or equivalent experience/combined education, with 10+ years of related professional experience * Must have and maintain a DoD 8570.01-M (Information Assurance Workforce) IAM level III certification (e.g. GSLC, CISM, CCISO, or CISSP) * Experience with RMF artifacts, obtaining and maintaining system ATOs, and implementing new and complex technologies at multiple classification levels within large enterprise environments * Experience performing continuous monitoring and cybersecurity hygiene of a windows domains and network enclaves * Experience with Linux operating systems in a Windows Domain * Problem solving and time management capabilities * Extensive experience working with federal/government agencies in sensitive and classified environments * Experience with Risk Management Framework (RMF), NIST 800-53, JSIG, and applicable legal and regulatory guidance * Excellent customer relations and customer support skills * Experience working in a team-oriented, collaborative environment * Currently hold an active TS/SCI clearance and the ability to maintain it throughout employment, * At least 3 years experience in the deployment, configuration, and troubleshooting of information technology equipment * Ability to understand information systems equipment functionality and configurations (switches, routers, IDS, firewalls, servers, storage, etc...) * Knowledge of virtualized datacenters and VDI ## Description SPA's Operations Research and C5ISR Analysis Group in CA is seeking an Information System Security Manager (ISSM). This position will develop information system solutions following Risk Management Framework (RMF) with implementations following the JSIG. The ISSM is responsible for contributions to the design, procurement, configuration, deployment, and leading accreditation and continuous monitoring of ORCA and customer networks. The ISSM is responsible for attaining and maintaining system assessments and authorizations through government authorizing agencies from requirements through operational deployment. ISSM implements requirements to establish classified communication links including internet, phone, video teleconferencing, and guest systems. The successful candidates coordinate requirements with DoD agencies to ensure mission accomplishment and the protection of sensitive information., ISSM Responsibilities: * Lead a team of Cybersecurity professionals in the day-to-day cybersecurity and operations of multiple classified systems. * Manage and mentor personnel. * Develop and maintain enterprise-wide RMF information security policies, standards, guidelines, procedures, and artifacts following RMF. * Oversee the development and deployment of the information security program for multiple classified systems to meet business and enterprise requirements, policies, standards, guidelines and procedures. * Prepares, reviews, and presents technical reports and briefings. * Create and Maintain the System Security Plans (SSP) and associated documentation. * Create a book of business for Cybersecurity Team. * Maintain compliance of accredited information systems based on federal and DoD security standards. * Manages and performs security compliance continuous monitoring. * Identifies root causes, prioritizes threats and recommends and/or implements corrective action. * Researches and addresses information security issues as required as an authority on the subject. * Ensure systems are operated, maintained, and disposed of in accordance with internal security policies and practices. * Participate in internal and external security audits and inspections; performs risk assessments. * Evaluate proposed changes or additions to the information system and assess their security relevance. * Ensure configuration management (CM) for security-relevant IS software, hardware, and firmware is maintained and documented. * Conduct investigations of computer security violations and incidents, reporting as necessary. * Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered. * Communicate, implement, and manage a formal Information Security / Information Systems Security Program together with ISSE, CPSO/CSSO, and ISO. * Integrate lessons learned and security control policies, procedures, and artifact generation best practices with peer ISSM/ISSE. * Contributor to the design, procurement, build, accreditation, and deployment of complex networks and systems in coordination with the ISSE and ISAs. * Manage cyber budgets to include hardware, software, and resources. * Receive and respond to incoming calls and/or e-mails regarding end-user or system problems. * Interface with third-party support and equipment vendors as needed. * Up to 20% travel required. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)