> Markdown version of [/jobs/ext/3115171-information-systems-security-manager](https://www.wearedevelopers.com/jobs/ext/3115171-information-systems-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - **Company:** Leidos, Inc. - **Location:** El Cajon, CA, United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Configuration Management, Cyber Security, Information Systems, Linux, Information Security Management, Key Management, Network Security, Network Architecture, Network Planning and Design, PSOS, SAP (Applications), SAP Project Management, SAP Security, Virtualization Technology, Computer Network Technologies, SAPBasis, Atlassian Tools, Nessus, Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 27, 2026 - **Apply:** https://www.thejobnetwork.com/job/14a51466-bbc6-4432-9059-eee636650f70/information-systems-security-manager ## About the Role The ideal candidate must be able to work independently while effectively collaborating with cybersecurity analysts, system administrators, engineers, program management, security personnel, site leadership, Program Security Officers (PSOs), Security Control Assessors (SCAs), and Authorizing Official (AO) representatives., Bachelor's degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an operational cybersecurity-specific role (e.g., Information Systems Security Manager, Information Systems Security Officer, cybersecurity specialist), or 16+ years of experience in an IT-related position with at least 10 years in an operational cybersecurity-specific role., Experience working directly with PSOs, SCAs, AOs/DAOs, government cybersecurity representatives, and SAP program management. \n * \n Experience supporting SAP Information System Assessment and Authorization activities from initial system design through ATO and continuous monitoring. \n * \n Experience developing JSIG/RMF authorization documentation and providing supporting artifacts and evidence for security control assessments. \n * \n Experience with SAP cybersecurity assessments, compliance inspections, and remediation of assessment findings. \n * \n Proficient with Microsoft Windows and Linux operating systems, virtualization technologies, and secure computing environments. \n * \n Experience with network security architecture, classified network design, secure communications, encryption, and key management. \n * \n Experience developing cybersecurity policies, procedures, SOPs, CONOPS, and other technical documentation supporting SAP Information Systems. \n * \n Experience using JIRA and Confluence for cybersecurity workflow, continuous monitoring, vulnerability tracking, POA&M management, and documentation. ## Description In this role, you will oversee Information Systems supporting Special Access Programs (SAPs) and maintain system authorization and cybersecurity compliance throughout the system lifecycle in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoD SAP security requirements, and customer-specific guidance., As the ISSM, you will serve as a Subject Matter Expert (SME) within the Information Assurance (IA) technical domain, supporting SAP Information Systems and enclaves across the enterprise. You will oversee day-to-day information system security operations, manage IA and IT personnel supporting SAP environments, resolve complex cybersecurity challenges, and develop innovative solutions to meet evolving program, customer, and security requirements., Experience developing, maintaining, and managing RMF authorization packages and associated cybersecurity documentation, including SSPs, security control implementation statements, POA&Ms, risk assessments, continuous monitoring artifacts, and supporting Body of Evidence. \n * \n Experience preparing Information Systems for cybersecurity assessments and supporting Security Control Assessors (SCAs), Authorizing Officials (AOs), Program Security Officers (PSOs), and customer cybersecurity representatives throughout the authorization process. \n * \n Familiarity with network technologies (LAN and WAN), network architecture, encryption technologies, key management, and cybersecurity best practices within classified and SAP environments. \n * \n Working knowledge of Microsoft Windows workstation/server and Linux operating systems within secure network environments. \n * \n Experience implementing and validating DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security configuration baselines, and system hardening requirements. \n * \n Experience with compliance, security monitoring, and vulnerability assessment tools such as Tenable/Nessus, ACAS, Splunk, and STIG Viewer. \n * \n Experience with workflow, documentation, configuration management, and change management tools such as JIRA and Confluence, as well as applicable RMF authorization management tools. \n * \n Ability to evaluate vulnerabilities, system changes, security control deficiencies, and cybersecurity risks and develop appropriate mitigation and remediation strategies. \n * \n Must be able to work in a constantly changing regulatory and mission environment with short-, mid-, and long-term timelines for resolving cybersecurity risks and compliance deficiencies. \n * \n Must work effectively within multidisciplinary teams and adapt quickly to changing program, customer, and mission requirements. \n * \n Excellent verbal and written communication skills with the ability to communicate cybersecurity risks and technical information to technical and non-technical stakeholders. \n ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)