> Markdown version of [/jobs/ext/584964-information-system-security-manager-issm](https://www.wearedevelopers.com/jobs/ext/584964-information-system-security-manager-issm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager (ISSM) - **Company:** ZTI Solutions LLC - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $150,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cyber Security, Identity and Access Management, Information Security Management, Security Information and Event Management, Software Vulnerability Management, Enterprise Software Applications, Information Technology, Microsoft Sentinel - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e479118fc3f2d8df ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * U.S. Citizen. * Active Secret security clearance with the ability to obtain TS/SCI (TS/SCI preferred). * Active DoD 8140 IAM Level II or higher certification (e.g., CAP, CASP+, CISM, CISSP). * 8+ years of overall IT experience, including at least 5 years of progressive hands-on experience in cybersecurity, RMF, and information assurance, with demonstrated experience in an ISSM or equivalent leadership role. * Ability to work full-time, onsite in Ft. Meade, MD, 5 business days per week. * In-depth knowledge of the Risk Management Framework (RMF) and the DoD authorization (A&A) process. * Demonstrated experience developing and managing ATO packages, SSPs, POA&Ms, and continuous monitoring programs. * Experience overseeing security assessments, STIG compliance, and IAVM remediation across enterprise systems. * Familiarity with vulnerability management (ACAS/Tenable) and endpoint security (Trellix ESS) operations and how they inform risk decisions. * Familiarity with SIEM platforms such as Microsoft Sentinel. * Strong leadership, decision-making, problem-solving, and stakeholder communication skills, including the ability to brief senior-level executives and customers., * Bachelor's degree in Computer Science, Information Security, or another STEM discipline. * Active Top Secret clearance with the ability to obtain SCI. * Experience supporting systems in a DISA-administered DoW environment. * Experience with Azure environments and cloud authorization (e.g., FedRAMP/DoD CC SRG). * Experience leading A&A efforts for IL5/IL6 systems. * Prior experience managing teams of ISSOs and cybersecurity engineers., Security Clearance: Active Secret clearance required prior to start date, with the ability to obtain TS/SCI; TS/SCI preferred. The effort includes IL5 work (Secret) and IL6 work on the TS side. Applicants must be U.S. Citizens and able to pass a background investigation and maintain clearance. ## Description ZTI Solutions is seeking an Information System Security Manager (ISSM) to lead the cybersecurity and Risk Management Framework (RMF) program supporting a multinational IL5/IL6 collaboration effort in an operational Department of War (DoW) environment hosting multiple Coalition Mission Partner Environments (MPE). This is a demanding, high-energy role focused on security authorization, compliance oversight, and overall cyber risk posture across multiple enclaves., Clearance: Active Secret required, with the ability to obtain TS/SCI. TS/SCI preferred. The effort spans IL5 work (Secret) and IL6 work on the TS side, which ZTI supports. Citizenship: U.S. Citizen (required). Certification: Active DoD 8140 IAM Level II or higher. Reports To: Senior Technical Program Manager., The ISSM serves as the principal cybersecurity authority and subject matter expert responsible for establishing, maintaining, and overseeing the information system security program across classified, multinational, and mission-critical enclaves. The ISSM owns the RMF lifecycle, manages Authorization to Operate (ATO) packages, directs continuous monitoring, and provides supervision and direction to ISSOs and supporting cybersecurity staff. The ideal candidate brings strong leadership, deep RMF expertise, and the ability to translate risk into actionable decisions while working closely with infrastructure, operations, leadership, and mission partner teams to keep enterprise systems compliant and operationally secure., * Serve as the primary ISSM and cybersecurity authority for systems within a secure, multinational DoW environment. * Develop, implement, and maintain the organization's information system security program and policies. * Own and manage the RMF lifecycle, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring. * Lead the development, submission, and maintenance of ATO packages and supporting authorization artifacts. * Provide direction, oversight, and mentorship to ISSOs and supporting cybersecurity personnel. * Maintain and track POA&Ms, ensuring timely remediation of findings and risks. * Oversee security assessments, audits, and compliance activities, including STIG and IAVM compliance. * Coordinate incident response, reporting, and risk decisions with leadership and mission partners. * Review and approve system security documentation, including SSPs, risk assessments, and control implementation statements. * Advise leadership and customers on cyber risk posture, mitigations, and authorization status. * Ensure continuous monitoring data, vulnerability findings, and endpoint security posture are evaluated and acted upon. * Other duties, as assigned., Engagement: ZTI Solutions is filling this position as a subcontractor on a multinational IL5/IL6 collaboration effort. Final selection is subject to an interview with the prime contractor / customer. Work Requirements: Onsite work required at Ft. Meade, MD - 5 business days per week. No remote work options available. Standard business hours with occasional flexibility for operational needs. About ZTI Solutions, LLC ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)