1

Information System Security Manager Jobs in Virginia

Everforth ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned ...

In this role, you will be responsible for maintaining the security posture of information systems, ensuring compliance with security policies, and managing risk through the implementation of robust ...

In this role, you will be responsible for maintaining the security posture of information systems, ensuring compliance with security policies, and managing risk through the implementation of robust ...

Assisting the Information System Security Manager (ISSM) with managing Plan of Action and Milestones (POA&Ms), ensuring the technical vulnerabilities are tracking, remediated, or mitigated with ...

Assisting the Information System Security Manager (ISSM) with managing Plan of Action and Milestones (POA&Ms), ensuring the technical vulnerabilities are tracking, remediated, or mitigated with ...

Also, perform duties as the alternate Information Systems Security Manager (ISSM). * Cyber security paperwork (compliance) and Information Assurance (IA) controls. * Develop supporting documentation ...

Showing results 41-60

Information System Security Manager information

See Virginia salary details

$62K

$134.9K

$198.3K

How much do information system security manager jobs pay per year?

As of Sep 12, 2026, the average yearly pay for information system security manager in Virginia is $134,937.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,600.00 and $159,100.00 per year, depending on experience, location, and employer.

What does an information system security manager do?

An Information System Security Manager (ISSM) is responsible for overseeing the security of an organization’s information systems. They develop and enforce policies, procedures, and protocols to protect sensitive data from cyber threats and unauthorized access. ISSMs also ensure compliance with relevant laws and regulations, conduct risk assessments, and respond to security incidents. Their duties often involve managing security teams, coordinating with IT departments, and staying updated on the latest cybersecurity trends.

What are the key skills and qualifications needed to thrive as an information system security manager?

To thrive as an Information System Security Manager, you need expertise in cybersecurity principles, risk management, and regulatory compliance, typically backed by a degree in information technology or a related field and relevant certifications like CISSP or CISM. Familiarity with security frameworks (e.g., NIST, ISO 27001), intrusion detection systems, and security information and event management (SIEM) tools is essential. Strong leadership, analytical thinking, and communication skills distinguish top performers in this role. These competencies are vital to effectively safeguard organizational data, lead security teams, and ensure compliance with evolving security standards.

What are some common challenges information system security managers face when balancing security and business objectives?

Information System Security Managers often encounter the challenge of aligning robust security protocols with the organization's operational needs. Balancing security requirements with user convenience and business agility can be difficult, as stringent controls may impact productivity or customer experience. Effective managers work closely with other departments to ensure security measures support, rather than hinder, business goals, requiring strong communication and negotiation skills. Staying current with evolving threats while supporting organizational growth is also an ongoing challenge in this role.

What is the difference between Information System Security Manager vs Security Analyst?

AspectInformation System Security ManagerSecurity Analyst
CertificationsCISSP, CISM, Security+Security+, CEH, CISSP (preferred)
Work EnvironmentOversees security policies, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageOrganizations with complex security needs, IT departmentsSecurity teams, cybersecurity firms, IT departments

The main difference is that the Information System Security Manager focuses on managing security strategies and teams, while the Security Analyst primarily monitors and analyzes security threats. Both roles require similar certifications and work within the cybersecurity field, but their responsibilities and scope differ significantly.

What cities in Virginia are hiring for Information System Security Manager jobs?

Cities in Virginia with the most Information System Security Manager job openings:

Infographic showing various Information System Security Manager job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 69% Full Time, 28% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $134,937 per year, or $64.9 per hour.

Information Systems Security Manager

Fairfax, VA β€’ On-site

$170K - $190K/yr

Full-time

Posted 21 days ago


Job description

Everforth ECS is seeking an Information Systems Security Manager to work in our Fairfax, VA office.
Everforth ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF).
The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS.
The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM).
The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands-on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well-organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization.
Key Responsibilities:
  • Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
  • Develop, maintain, and manage RMF documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plan of Action & Milestones (POA&Ms)
    • Continuous Monitoring Strategies
  • Ensure compliance with:
    • NIST SP 800-53 Rev. 5 security controls
    • NIST SP 800-37 Rev. 2 (RMF Guide)
    • DoD Cybersecurity Manual (DoDM 5200.01)
    • SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)
  • Interface directly with Navy stakeholders including:
    • Authorizing Officials (AOs)
    • Security Control Assessors (SCAs)
    • Information System Owners (ISOs)
    • Program Managers (PMs)
  • Manage system accreditation activities within eMASS and ensure data accuracy and completeness
  • Conduct and support security control assessments, vulnerability management, and mitigation tracking
  • Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA
  • Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)
  • Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable
  • Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures

Salary Range: $170,000-190,000
General Description of Benefits
  • Active Secret security clearance with willingness and ability to obtain TS/SCI
  • Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 8+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment
  • Strong experience implementing RMF under DoDI 8510.01 (latest version)
  • Hands-on experience with eMASS
  • In-depth knowledge of:
    • NIST SP 800-53 Rev. 5 controls
    • NIST SP 800-37 Rev. 2
    • DoDI 8500.01 / 8510.01
  • SECNAV M-5239.1
  • Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)
  • Familiarity with:
    • DISA STIGs and SCAP compliance tools
    • ACAS (Assured Compliance Assessment Solution)
    • HBSS / Endpoint Security Solutions
  • Strong understanding of system architectures (on-prem, cloud, hybrid)