> Markdown version of [/jobs/ext/572572-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/572572-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - **Company:** Akima - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Software Vulnerability Management, SARS Software Products, Information Technology - **Published:** June 5, 2026 - **Apply:** https://dejobs.org/x/x/1378969E331D477E87C026EBA2A15B79/job/ ## About the Role * 7-10 years of experience in cybersecurity, information assurance, or risk management, or equivalent years of experience. * Must be a US Citizen - Able to obtain a Public Trust. * Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field or relevant years of experience. * Experience supporting RMF compliance efforts within DoD, Federal, or Intelligence Community environments. * Knowledge of NIST SP 800-37 and NIST SP 800-53 security controls. * Strong analytical, communication, and briefing skills. * Experience with continuous monitoring programs in secure environments. Desired Certifications : * IAM Level III Preferred. * CISSP (Certified Information Systems Security Professional). * CISM (Certified Information Security Manager). * GSLC (GIAC Security Leadership Certification). * CCSP (Certified Cloud Security Professional). ## Description The Information System Security Manager (ISSM) is responsible for overseeing the cybersecurity posture of systems and ensuring compliance with the Risk Management Framework (RMF). This role frequently collaborates with the Government Information System Security Officer (ISSO) to develop, maintain, and submit RMF artifacts and documentation. The ISSM will apply cyber hardening practices and lead continuous monitoring activities to ensure the system obtains and maintains an Authority to Operate (ATO)., * Serve as the primary cybersecurity lead, ensuring system accreditation and ongoing ATO sustainment. * Develop, update, and maintain RMF documentation (including SSPs, POA&Ms, SARs, and other artifacts). * Perform security assessments, risk analysis, and vulnerability mitigation activities. * Implement cyber hardening requirements and continuously assess security controls for effectiveness. * Coordinate with internal and external stakeholders, including the Government ISSO, system owners, engineering teams, and auditors. * Oversee incident response activities and ensure compliance with organizational and DoD/IC cybersecurity policies. * Track and report cybersecurity posture and compliance status to leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)