1

Information Systems Security Manager Jobs (NOW HIRING)

*This is a contingent opportunity Information Systems Security Manager (ISSM) K2 Group is searching for an ISSM to support the Air Force Research Laboratory Sensors Directorate (AFRL/RY) at Wright ...

next page

Showing results 1-20

Information Systems Security Manager information

See salary details

$62.5K

$136.1K

$200K

How much do information systems security manager jobs pay per year?

As of May 29, 2026, the average yearly pay for information systems security manager in the United States is $136,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an Information Systems Security Manager, and why are they important?

To thrive as an Information Systems Security Manager, you need expertise in cybersecurity principles, risk management, and compliance, often supported by a degree in information technology or cybersecurity and certifications like CISSP or CISM. Familiarity with security tools such as SIEM platforms, vulnerability assessment tools, and incident response systems is typically required. Strong leadership, problem-solving abilities, and effective communication distinguish top performers in this role. These skills help ensure robust security postures, compliance with regulations, and effective management of cyber threats to protect organizational assets.

What are some common challenges faced by Information Systems Security Managers, and how are they typically addressed within organizations?

Information Systems Security Managers often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with regulatory standards. These challenges are typically addressed by staying current with industry trends, fostering strong communication between IT and business teams, and implementing ongoing training and awareness programs. Additionally, effective managers leverage a combination of proactive risk assessments, incident response planning, and collaboration with cross-functional teams to maintain robust security postures.

What are Information Systems Security Managers?

Information Systems Security Managers are professionals responsible for overseeing and implementing security measures to protect an organization's computer systems and networks. They develop policies, manage security teams, monitor for security breaches, and ensure compliance with laws and regulations. Their role is crucial in preventing unauthorized access, data breaches, and cyber threats, making them an essential part of any organization's IT infrastructure. They often collaborate with other departments to ensure overall security and may also respond to incidents when they occur.

What is the difference between Information Systems Security Manager vs Information Security Analyst?

AspectInformation Systems Security ManagerInformation Security Analyst
CertificationsCISSP, CISM, Security+Security+, CEH, CISSP (preferred)
Work EnvironmentOversees security teams, manages policies, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageOrganizations with dedicated security departments, large enterprisesVarious industries, including IT, finance, healthcare, focusing on threat detection

The main difference is that the Information Systems Security Manager focuses on managing security teams and policies at a strategic level, while the Information Security Analyst concentrates on monitoring and analyzing security threats. Both roles require similar certifications and are vital in maintaining organizational security, but their responsibilities and focus areas differ significantly.

What cities are hiring for Information Systems Security Manager jobs? Cities with the most Information Systems Security Manager job openings:
What are the most commonly searched types of Information Systems Security jobs? The most popular types of Information Systems Security jobs are:
What states have the most Information Systems Security Manager jobs? States with the most job openings for Information Systems Security Manager jobs include:
Infographic showing various Information Systems Security Manager job openings in the United States as of May 2026, with employment types broken down into 2% As Needed, 76% Full Time, 15% Part Time, and 7% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $136,104 per year, or $65.4 per hour.

Information Systems Security Manager (ISSM)

E-Space

Arlington, TX โ€ข On-site

Full-time

Posted 15 days ago


Job description

Job Summary:
E-Space is a company focused on making connectivity from space universally accessible and secure. The Information Systems Security Manager (ISSM) will be responsible for the cybersecurity posture and compliance of classified information systems, ensuring adherence to various security policies and managing the authorization and continuous monitoring of these systems.
Responsibilities:
โ€ข Lead the Assessment and Authorization (A&A) process for all classified IS under the Risk Management Framework (RMF) in accordance with NIST SP 800-37 and DAAPM.
โ€ข Prepare, maintain, and submit System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Authorization to Operate (ATO) packages.
โ€ข Serve as the primary liaison with DCSA and Government customer representatives during system assessments, inspections, and audits.
โ€ข Maintain and manage the System Security Authorization Agreement (SSAA) or equivalent documentation for all IS operating at the TS level or above.
โ€ข Ensure all classified information systems comply with 32 CFR Part 117 (NISPOM), applicable DoD and IC cybersecurity policies, Contract Data Requirements List (CDRLs), and Statement of Work (SOW) security requirements.
โ€ข Develop, implement, and maintain facility-level Information Systems Security policies, procedures, and Standard Operating Procedures (SOPs).
โ€ข Enforce configuration management (CM) controls and ensure all hardware/software changes to classified IS are reviewed and approved prior to implementation.
โ€ข Conduct periodic self-inspections of classified IS programs and remediate findings in coordination with the FSO and program leadership.
โ€ข Implement and manage a Continuous Monitoring (ConMon) program for all authorized classified information systems.
โ€ข Monitor audit logs, SIEM alerts, and vulnerability scan results; investigate anomalies and potential insider threats.
โ€ข Serve as the Facility Incident Response Manager for classified information system security incidents; coordinate reporting to DCSA and GCAs within required timeframes.
โ€ข Conduct or oversee technical vulnerability assessments and penetration testing as required by the CSA or contract requirements.
โ€ข Oversee ISSM-delegated Information System Security Officer (ISSO) personnel; provide mentorship, task delegation, and performance oversight.
โ€ข Develop and deliver annual IS security awareness training and role-based training for users of classified information systems.
โ€ข Maintain personnel access records and access control lists (ACLs) for all classified IS; ensure need-to-know verification prior to system access grants.
โ€ข Coordinate with the FSO to ensure the integration of personnel security and information security requirements.
โ€ข Coordinate with facilities and physical security teams to ensure IS are housed in appropriately accredited spaces (SCIFs, Closed Areas, SAPs) in accordance with ICD 705 and DCSA physical security standards.
โ€ข Manage and enforce media protection, sanitization, and destruction procedures for classified storage media in accordance with NSA/CSS EPL requirements.
โ€ข Oversee PKI, multi-factor authentication (MFA), and privileged access management (PAM) implementations across classified networks.
Qualifications:
Required:
โ€ข Active Top Secret (TS) security clearance; SCI eligibility required or must be obtainable within 6 months of hire.
โ€ข Minimum of 10 years of progressive experience in information systems security within a DoD or Intelligence Community classified environment with 5 or more yearโ€™s direct experience as an ISSM, ISSP, Security Control Assessor (SCA), or equivalent position.
โ€ข Demonstrated ISSM or ISSO experience supporting DCSA-adjudicated classified IS programs under NISPOM/DAAPM.
โ€ข A minimum of 3 years of direct working knowledge of the NIST RMF process (NIST SP 800-37, 800-53, 800-171) and DoD Assessment Methodology (DAAPM).
โ€ข Experience preparing and managing ATOs, SSPs, SAPs, and POA&Ms for TS and SCI-level information systems.
โ€ข Proficiency with eMASS (Enterprise Mission Assurance Support Service) or equivalent GRC tool.
โ€ข Working knowledge of SIEM platforms, vulnerability scanners (e.g., ACAS/Nessus), and HBSS/endpoint security tools.
โ€ข IAM Level II or III certification required per DoD 8570.01-M / DoD 8140 (e.g., CISSP, CISM, GSLC, or equivalent).
โ€ข Masterโ€™s degree or Bachelor's degree with equivalent work experience and certifications in Cybersecurity, Information Technology, Computer Science, or a related technical discipline, OR equivalent verifiable experience.
Preferred:
โ€ข Current TS/SCI access with polygraph (CI or Full Scope).
โ€ข Experience supporting Special Access Programs (SAPs) or Sensitive Compartmented Information Facilities (SCIFs).
โ€ข Familiarity with Cross Domain Solutions (CDS), data transfer processes, and CDSE/NSA approval workflows.
โ€ข Experience with LINUX and Windows hardened STIG baseline implementation and validation.
โ€ข Knowledge of ICD 503, ICS 500-27, and CNSSI 1253 security control overlays.
โ€ข Prior DCSA inspection experience (NISP, SAP, or SCI programs).
โ€ข Additional certifications such as CASP+, CCSP, Security+, or CEH are a plus.
โ€ข Direct experience managing the system lifecycle of connected classified systems including Secret Defense Research and Engineering Network (SDREN), Secret Internet Protocol Router Network (SIPRNET), Non-classified Internet Protocol Router Network (NIPRNET, and Joint Worldwide Intelligence Communications System (JWICS) systems.
Company:
E-Space is bridging Earth & space with the most sustainable LEO space system, delivering real-time, anywhere comms, IoT & Smart-IoTโ€ฏservices Founded in 2021, the company is headquartered in Toulouse, FRA, with a team of 201-500 employees. The company is currently Growth Stage.