> Markdown version of [/jobs/ext/3109654-information-system-security-manager](https://www.wearedevelopers.com/jobs/ext/3109654-information-system-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager - **Company:** Venesco LLC - **Location:** Aberdeen Proving Ground, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Security Support Provider Interface, Software Vulnerability Management, SC Clearance, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 27, 2026 - **Apply:** https://www.juju.com/job/16_bf8c168d ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field preferred *5+ years of cybersecurity or information assurance experience * Prior team leadership or security oversight experience preferred. * Active Secret clearance *Relevant DoD 8140 certifications such as CISSP strongly preferred * Strong knowledge of NIST SP 800-53, RMF processes, and ATO lifecycle activities * Experience leading security governance, compliance, and risk management efforts * Experience supervising ISSOs or coordinating security activities across multiple technical teams * Strong communication skills for executive updates, audit support, and risk briefings * Familiarity with vulnerability scanning tools, STIG validation, POA&M governance, and security documentation workflows, * Ability to operate in fast-paced, compliance-driven environments * Strong judgment in evaluating cyber risk and balancing mission needs * Proven ability to build trust with technical teams and senior leadership * Detail-oriented approach to documentation, authorization, and continuous monitoring requirements ## Description We are seeking an experienced Information System Security Manager (ISSM) to lead cybersecurity oversight for assigned systems, programs, or enclaves. The ISSM is responsible for directing Risk Management Framework (RMF) execution, supporting authorization activities, managing vulnerability and risk posture, enforcing security policy implementation, and overseeing the performance of ISSOs and related security support personnel. This role serves as the primary security lead interfacing with leadership, system owners, assessors, engineers, and Authorizing Officials to confirm systems remain secure, compliant, and operationally ready., * Lead and oversee RMF execution across assigned systems, programs, or enclaves *Direct Authority to Operate (ATO) activities and ensure required documentation is complete, current, and audit-ready * Manage, coach, and mentor ISSOs and other security support staff * Oversee vulnerability management, risk assessments, POA&M tracking, and remediation prioritization *Develop, implement, and enforce security policies, procedures, and training requirements * Coordinate with Authorizing Officials, system owners, CISO staff, engineers, and program leadership to assess and communicate system risk posture * Ensure compliance with security frameworks and federal requirements, (e.g., NIST RMF, NIST SP 800-53, related DoD cybersecurity guidance) ## Related Videos - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)