> Markdown version of [/jobs/ext/3534068-information-systems-security-manager-jobid-0311](https://www.wearedevelopers.com/jobs/ext/3534068-information-systems-security-manager-jobid-0311). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Manager - JobID-0311 - **Company:** Innovative Defense Technologies - **Location:** San Diego, CA, United States - **Experience:** Expert - **Salary:** $135,000.0 - $231,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Data Transmissions, Linux, DevOps, File Transfer, Identity and Access Management, Information Security Management, Network Security, Windows PowerShell, Systems Development Life Cycle, Ansible, SAS (Software), Security Information and Event Management, Software Deployment, Software Engineering, SC Clearance, Kubernetes, Infrastructure Automation Frameworks, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Puppet, Devsecops, Docker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 1, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9207292/information-systems-security-manager-jobid-0311 ## About the Role * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related field, or equivalent professional experience. * Minimum of 8 years of IT experience, including 5 years or more as an ISSM or equivalent role in a cleared DCSA Accredited facility. * Ability to travel up to 10% of the time as needed. * Excellent knowledge of the NISPOM and the DCSA DAAG and their requirements and procedures. * Proficient in Windows and Linux operating systems and their security configurations. * Proficient in eMASS, Tenable, NIST 800-53 Controls, RMF, SIEM tools, ePO, and network security tools and techniques. * Familiar with the SDLC and DevOps/DevSecOps methodologies and their security implications. Active Secret clearance or higher. * Information Assurance Management (IAM) Level 3 certification in accordance with DODI 8140/8570 requirements, such as CISSP, CISM, or GSLC. * Strong analytical, troubleshooting, and communication skills with the ability to coordinate effectively across engineering, cybersecurity, and operational teams. What Makes You Stand Out: * Self-motivated professional with the ability to independently manage multiple priorities, systems, and technical efforts simultaneously in fast-paced or mission-critical environments with minimal supervision. * Technical experience administering and securing containerized environments using Docker, Kubernetes, or similar container orchestration platforms. * Experience with infrastructure automation and configuration management tools such as Ansible, PowerShell, Chef, Salt, Puppet, or similar technologies. * Familiarity with software deployment and systems management tools such as PDQ Deploy or equivalent solutions. * Strong verbal and written communication skills with the ability to collaborate across engineering, cybersecurity, and operational teams. ## Description * Responsible for implementing and managing the IDT San Diego Classified Information Systems (IS) security program and policies and procedures. * Extensive knowledge of Risk Management Framework (RMF) as it relates the published DCSA Assessment and Authorization Guide (DAAG), 32 CFR Part 117, "National Industrial Security Program Operating Manual (NISPOM)", and NIST 800-53 series compliance. * Generate and maintain authority to operate (ATO) for new and current classified information systems authorized under RMF. * Use eMASS to document and track the security authorization process and maintain the security plan and artifacts. * Maintain a working knowledge of system functions, security policies, technical security safeguards, and operational security measures. * Chair the Change Control Board and oversee change in the environment, including clearly articulating requirements for change. * Oversee and conduct Control Correlation Identifier (CCI) self-assessments and periodic testing to evaluate the security posture of the IS. * Responsible for leading the information security portion of government assessments, Government on-sites and the periodic self-inspections. * Work closely with other program managers and stakeholders to facilitate change control and continuous monitoring of the lab environment. * Support the Software Development Lifecycle (SDLC) and DevOps/DevSecOps processes and ensure security best practices are followed. * Implement and manage an effective IS security education, training, and awareness program. * Assist the FSO and the Insider Threat Program Senior Official (ITPSO) in ensuring that insider threat awareness is addressed in the classified computing environments. * Manage and engage with the maintenance and execution of the Information Security Continuous Monitoring (ISCM) plan. * Ensure weekly audit compliance (user activity monitoring, data transfer audit logs) and audit data is analyzed, stored, and protected in accordance with the required auditing frequency. * Ensure compliance of current Information Assurance (IA) policies, concepts, and measures when designing, procuring, adopting, and developing new IS. * Manage and approve data transfer and assured file transfer responsibilities in accordance with IDT Policy and Procedures; both within IDT lab environments and in nearby US Government facilities. * Develop, document, manage and approve monthly vulnerability scan results, quarterly Security Technical Implementation Guide (STIG) compliance and applicable Plan of Action and Milestones (POA&M) for each Classified IS enclave. * Possess personnel leadership and technical competence commensurate with the complexity of the IS. * Manage requests that involve co-utilizations and joint-use agreements of data residing on the IS and/or within the closed area labs. * Lead a team of Information System Security Officers (ISSOs) and Security Administrators (SAs) through the RMF process, providing tasking to ensure program requirements, deliverables and schedules are met. * Perform comprehensive investigations of security incidents and ensure proper measures are taken post discovery of the incident/event. * Responsible for the preparation and demonstration of compliant classified IS's in advance of a DCSA assessments. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)