> Markdown version of [/jobs/ext/3136114-information-system-security-manager-issm-onsite](https://www.wearedevelopers.com/jobs/ext/3136114-information-system-security-manager-issm-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) (Onsite) - **Company:** RTX - **Location:** Richardson, TX, United States - **Experience:** Expert - **Salary:** $107,500.0 - $204,500.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Computer Networks, Databases, Identity and Access Management, Information Security Management, SAP Implementation, Security Information and Event Management, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Splunk, Vulnerability Analysis - **Published:** September 29, 2026 - **Apply:** https://globalhr.wd5.myworkdayjobs.com/REC_RTX_Ext_Gateway/job/US-TX-RICHARDSON-461--3200-E-Renner-Rd--RENNER-BLDG-461/Information-System-Security-Manager--ISSM---Onsite-_01876435 ## About the Role The ability to obtain and maintain a U.S. government issued security clearance is required. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance, Must have knowledge regarding National Industrial Security Operating Manual (NISPOM) and related documentation such as: * Baseline Technical Security Configuration Standards, * Defense Counter-Intelligence Security Agency (DCSA) * Assessment and Authorization Process Manual (DAAPM) * Customer/contract specific Cybersecurity regulations. * Joint Special Access Program Implementation Guide (JSIG), * Typically requires a University Degree and minimum of 10 years prior relevant experience or an Advanced Degree in a related field and minimum 7 years of experience * U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance. * Experience supporting cybersecurity compliance as stipulated by DCSA Assessment and * Authorization Guide (DAAG), Joint SAP Implementation Guide (JSIG), and/or National * Industrial Security Program Operating Manual (NISPOM) regulations * Past direct leadership or project/program management experience * IAM Level III certification (CISSP, CISM or other) * Cybersecurity, systems security or hardening * Compliance-based auditing using the Risk Management Framework (RMF) and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA * Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics) * Physical security/security, policework/criminal justice, investigations, or Border Patrol * Project or program management, office management, senior administration, or account management Qualifications We Prefer: * Master's degree in computer science, Information Systems, Information Technology, * Cyber Security, Criminal Justice, Business or other relevant degrees * Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc. * Experience in the oversight and execution of the Assessment & Authorization processes (Certification & Accreditation), as defined in JSIG/RMF * Experience in the execution and management of Information System's (IS) incident response and administrative inquiries/investigations in collaboration with the Investigations department ## Description Our team in Richardson, Texas is seeking an Information System Security Manager (ISSM). The Information Systems Security Manager is responsible for compliance oversight, assessment, and operations of systems under their purview. They may be assigned to a single large-scale program or oversee multiple programs., * ISSMs are required to maintain IAM Level III certification commensurate with their role as required by DoDD 8140 (8570). * Complete all DCSA and Collins Aerospace required training within 6 months of appointment (annual requirements thereafter). * Accountability for all systems under their assigned purview. * Maintaining a working knowledge of all CIS functions, security policies, technical security safeguards, and operational security measures. * Interactions with DCSA SCA/ISSP to track items including, but not limited to, upcoming authorizations (ATO), new technologies solutions (i.e., new SIEM, OS, etc.), policy interpretations (in conjunction with Site ISSM), and onsite A&A. * Developing, maintaining, and updating, in coordination with all system stakeholders (CS Manager, ISO, DT, etc.), applicable site POAM(s) to identify system weaknesses, mitigating actions, resources, and timelines for corrective actions. * Coordinating DCSA SVA preparation activities for assigned CAGE in conjunction with Site ISSM. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)