Information Systems Security Manager (ISSM)

Columbia, MD$137k–$205kPosted Aug 7, 2026

Overview

Information Systems Security Manager (ISSM)

LOCATION: Columbia, MD

JOB STATUS: Full-time

CLEARANCE: Ability to obtain TS/SCI

CERTIFICATION: CAP, CISSM, or CISSP

TRAVEL: Less than 5%

SALARY RANGE: $137K - $205K

 

Astrion has an exciting opportunity for an experienced Information Systems Security Manager (ISSM) to assist in establishing, implementing, and maintaining the security program for classified information systems. The ISSM serves as the primary advisor to management on classified information system security and is the principal interface with DCSA on cybersecurity matters. The role is defined in 32 CFR Part 117 (NISPOM Rule) and further expanded in the DCSA Assessment and Authorization Guide (DAAG). Further, the ISSM will establish security instructions, manuals and policies based on guidance from the DoW, Navy, and MDA; this position is located in Columbia Maryland.

 

REQUIRED QUALIFICATIONS / SKILLS

  • Bachelor’s degree with 10-12 years of experience.
  • Minimum of 5 years of experience in leading a team or managerial role.
  • Experience in supporting U.S. Government clients.
  • Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment.
  • A CAP, CISM, or CISSP certification is required.
  • U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility.

PREFERRED QUALIFICATIONS / SKILLS 

  • Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans.

RESPONSIBILITES:

  • Information System Security Program Management - Develop, implement, and oversee the organization's classified Information System Security Program (ISSP).
  • Ensure compliance with the NISPOM, DAAG, RMF, and CSA guidance.
  • Establish policies, procedures, and technical standards for classified information systems.
  • Coordinate preparation of: System Security Plans (SSPs); Security Assessment Reports (SARs); Plan of Action & Milestones (POA&Ms); Continuous Monitoring Strategy.
  • Support Authorization to Operate (ATO) and reauthorization activities.
  • Maintain authorization packages in eMASS (where applicable).
  • Security Control Implementation: Verify management, operational, and technical controls remain effective; Monitor security control compliance throughout the system lifecycle.
  • Continuous Monitoring: Establish and manage a Continuous Monitoring (ConMon) program.
  • Review: Vulnerability scans; audit logs; security alerts; patch compliance; configuration management
  • Ensure deficiencies are documented and corrected.
  • Conduct self-inspections per 32 CFR §117.18,
  • Incident Reporting: ensure incidents are investigated are reported to DCSA and appropriate Government agencies; coordinate incident response activities; maintain incident documentation, and track remediation activities.
  • Configuration Management: approve and monitor configuration changes; ensure security impact analyses are completed; verify secure baseline configurations; maintain system inventories.
  • User Management: approve user access procedures; ensure least privilege is enforced; review privileged accounts; ensure user accounts are disabled when no longer required.
  • Partner with the IT team to coordinate POA&M remediation, review and approve configuration changes, evaluate requested new software prior to deployment, and drive close collaboration between the Information Systems Security (ISS) and IT teams.
  • Training and Awareness: ensure users receive initial and annual cybersecurity training; promote insider threat awareness within the IS security program.
  • Coordination with Insider Threat Program.
  • Coordination with the FSO.
  • Interface with Defense Counterintelligence and Security Agency (DCSA) and other government agencies.

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free