> Markdown version of [/jobs/ext/567057-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/567057-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - **Company:** DSD Laboratories, Inc. - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Security Content Automation Protocol, Software Vulnerability Management, SC Clearance, Information Technology, Nessus, Devsecops - **Published:** June 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8959309/information-system-security-manager-issm ## About the Role * 3-5 years of hands-on experience in cybersecurity, Risk Management Framework (RMF) execution, system assessment & authorization, control assessment, vulnerability management, STIG/SCAP implementation and validation, or DoD/Federal information assurance support. * Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP/STIG tools. * A&A implementing NIST 800-53 Rev5, NIST 800-171, or FedRAMP Moderate. * Familiarity with DoD 8510.01, AFI 17-101, FISMA, and DoD Cloud Computing SRG (IL4/IL5). * Holistic Plan of Action and Milestone (POA&M) management, continuous monitoring, audit log implementation and review, and security control assessments. * DoD 8140 Intermediate / DoD 8570 IAM Level II equivalent certification (e.g., GMON, SecurityX/CASP+, CCSP, CGRC/CAP, Cloud+, GCSA, GSEC, CISM, CISSP Associate). * Must be eligible to obtain and maintain a Secret clearance. * Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related technical discipline; equivalent experience may be substituted where contract allows. Preferred Qualifications * 5+ years in DoD, Air Force, federal, or similar environments; experience leading system assessment & authorization efforts, leading and mentoring ISSOs, supporting enterprise cybersecurity program execution. * AWS/Azure/Google security hardening and monitoring experience. * DoD 8140 Advanced / DoD 8570 IAM Level III equivalent certification (e.g., CISM, CISSP, ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC, CCISO). * Active Secret clearance is strongly preferred. * Master's degree, graduate certificate, or advanced training in cybersecurity, information assurance, or risk management. ## Description * Serve as Information System Security Manager (ISSM) supporting AFMC A4 portfolio systems. * Lead RMF Rev 5 authorization activities and develop and maintain Authorization Packages (SSP, SAR, POA&M, Risk Assessments). * Coordinate with Authorizing Officials (AO/SCA) and manage ATO/cATO lifecycles in eMASS. * Oversee continuous monitoring, control assessments, STIG/SCAP compliance, vulnerability remediation, and audit readiness. * Coordinate with DevSecOps, system administrators, ISSOs, and program stakeholders to ensure cybersecurity requirements are integrated into system sustainment, transition, and operational processes. * Lead discrete cybersecurity tasks and mentor junior ISSO/cybersecurity staff. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)