Information Systems Security Manager (ISSM)

Astrion

Columbia (MD)

On-site

USD 137,000 - 205,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Astrion invites applications for an Information Systems Security Manager (ISSM) in Columbia, MD. The role focuses on establishing, implementing, and maintaining a security program for classified information systems.

The ISSM will advise management and coordinate with DCSA on cybersecurity matters. The candidate should hold a CAP, CISSP, or CISM certification, possess TS/SCI eligibility, and have a strong background in RMF, NISPOM, and security control implementation.

Qualifications

  • Bachelor’s degree and 5+ years in a leadership/managerial role.
  • Experience supporting U.S. Government clients.
  • Knowledge of IA policy, procedures, and workforce structures to secure networks.
  • CAP, CISM, or CISSP certification required.

Responsibilities

  • Develop, implement, and oversee the organization’s classified ISSP.
  • Ensure compliance with NISPOM, DAAG, RMF, and CSA guidance.
  • Create and maintain SSPs, SARs, POA&Ms, and continuous monitoring strategy.
  • Coordinate ATO activities and maintain authorization packages in eMASS.
  • Lead monitoring of security controls and vulnerability management.

Skills

Leadership
Govt clients
IA policy
Security management

Education

Bachelor’s degree

Tools

eMASS
RMF

Job description

Overview
Information Systems Security Manager (ISSM)

LOCATION: Columbia, MD

JOB STATUS: Full-time

CLEARANCE: Ability to obtain TS/SCI

CERTIFICATION: CAP, CISSM, or CISSP

TRAVEL: Less than 5%

SALARY RANGE: $137K - $205K

Astrion has an exciting opportunity for an experienced Information Systems Security Manager (ISSM) to assist in establishing, implementing, and maintaining the security program for classified information systems. The ISSM serves as the primary advisor to management on classified information system security and is the principal interface with DCSA on cybersecurity matters. The role is defined in 32 CFR Part 117 (NISPOM Rule) and further expanded in the DCSA Assessment and Authorization Guide (DAAG). Further, the ISSM will establish security instructions, manuals and policies based on guidance from the DoW, Navy, and MDA; this position is located in Columbia Maryland.

Required Qualifications / Skills
  • Bachelor’s degree with 10-12 years of experience.
  • Minimum of 5 years of experience in leading a team or managerial role.
  • Experience in supporting U.S. Government clients.
  • Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment.
  • A CAP, CISM, or CISSP certification is required.
  • U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility.
Preferred Qualifications / Skills
  • Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans.
Responsibilites
  • Information System Security Program Management - Develop, implement, and oversee the organization's classified Information System Security Program (ISSP).
  • Ensure compliance with the NISPOM, DAAG, RMF, and CSA guidance.
  • Establish policies, procedures, and technical standards for classified information systems.
  • Coordinate preparation of: System Security Plans (SSPs); Security Assessment Reports (SARs); Plan of Action & Milestones (POA&Ms); Continuous Monitoring Strategy.
  • Support Authorization to Operate (ATO) and reauthorization activities.
  • Maintain authorization packages in eMASS (where applicable).
  • Security Control Implementation: Verify management, operational, and technical controls remain effective; Monitor security control compliance throughout the system lifecycle.
  • Continuous Monitoring: Establish and manage a Continuous Monitoring (ConMon) program.
  • Review: Vulnerability scans; audit logs; security alerts; patch compliance; configuration management
  • Ensure deficiencies are documented and corrected.
  • Conduct self-inspections per 32 CFR
  • 117.18,
  • Incident Reporting: ensure incidents are investigated are reported to DCSA and appropriate Government agencies; coordinate incident response activities; maintain incident documentation, and track remediation activities.
  • Configuration Management: approve and monitor configuration changes; ensure security impact analyses are completed; verify secure baseline configurations; maintain system inventories.
  • User Management: approve user access procedures; ensure least privilege is enforced; review privileged accounts; ensure user accounts are disabled when no longer required.
  • Partner with the IT team to coordinate POA&M remediation, review and approve configuration changes, evaluate requested new software prior to deployment, and drive close collaboration between the Information Systems Security (ISS) and IT teams.
  • Training and Awareness: ensure users receive initial and annual cybersecurity training; promote insider threat awareness within the IS security program.
  • Coordination with Insider Threat Program.
  • Coordination with the FSO.
  • Interface with Defense Counterintelligence and Security Agency (DCSA) and other government agencies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Astrion • Columbia (MD)

On-site
USD 114,000 - 171,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 170,000 - 195,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Information System Security Manager
Information System Security Manager

ATR International • Palo Alto (CA)

On-site
USD 120,000 - 180,000
Senior ISSM: Classified Systems Security Leader
Senior ISSM: Classified Systems Security Leader

Astrion • Columbia (MD)

On-site
USD 137,000 - 205,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

OMNI Consulting Solutions, LLC • Chantilly (VA)

On-site
USD 140,000 - 190,000
Medical Coverage
Dental Benefits
Vision Benefits
+5
Information Systems Security Manager (ISSM) I
Information Systems Security Manager (ISSM) I

General Dynamics - IT • San Antonio (TX)

On-site
USD 110,000 - 150,000
Information System Security Manager (Skill Level 2-3)
Information System Security Manager (Skill Level 2-3)

Strategic Analytix • Fort Meade (MD)

On-site
USD 100,000 - 140,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Mission Essential • Fairfax (VA)

On-site
USD 120,000 - 160,000
Medical, dental, vision insurance
Life and disability insurance
Paid time off
+2
Information System Security Manager
Information System Security Manager

Peraton • Maryland

On-site
USD 130,000 - 170,000
Information Systems Security Manager
Information Systems Security Manager

Mission Essential • Virginia (MN)

On-site
USD 120,000 - 180,000