1

Issm Jobs in Maryland (NOW HIRING)

ISSM

Hanover, MD · On-site

Assevero Security Consulting, LLC has several current openings for highly motivated and qualified security professionals. Successful candidates will support to cybersecurity-related projects for a ...

ISSM

Hanover, MD · On-site

Assevero Security Consulting, LLC has several current openings for highly motivated and qualified security professionals. Successful candidates will support to cybersecurity-related projects for a ...

Senior ISSM

Hanover, MD

$94K - $123K/yr

Assevero Security Consulting, LLC has several current openings for highly motivated and qualified security professionals. Successful candidates will support cybersecurity-related projects for a large ...

Senior ISSM

Hanover, MD · On-site

$94K - $123K/yr

Assevero Security Consulting, LLC has several current openings for highly motivated and qualified security professionals. Successful candidates will support cybersecurity-related projects for a large ...

Showing results 21-40

Issm information

See Maryland salary details

$44.6K

$114.8K

$179.1K

How much do issm jobs pay per year?

As of Sep 3, 2026, the average yearly pay for issm in Maryland is $114,841.00, according to ZipRecruiter salary data. Most workers in this role earn between $92,200.00 and $133,900.00 per year, depending on experience, location, and employer.

What is an ISSM?

An Information Systems Security Manager (ISSM) is responsible for overseeing and implementing cybersecurity policies for an organization's information systems. They ensure compliance with security standards, manage risk assessments, and coordinate with security teams to protect sensitive data. ISSMs work closely with IT and leadership to develop and enforce security strategies that align with regulatory requirements.

What are the typical daily responsibilities of an Information System Security Manager (ISSM)?

An ISSM’s daily responsibilities often include overseeing the implementation and monitoring of security controls, performing regular risk assessments, and ensuring compliance with relevant security policies and regulations. You may also coordinate incident response efforts, review system access logs, and provide guidance to IT staff on best practices. Additionally, ISSMs frequently interact with auditors, senior management, and cross-functional teams to report on security findings and advise on system improvements. This role requires staying current with emerging threats and adapting security strategies to protect organizational assets effectively.

What are the key skills and qualifications needed to thrive in the ISSM position, and why are they important?

To excel as an Information System Security Manager (ISSM), you need a strong background in information security, risk management, and compliance, typically supported by a degree in cybersecurity, computer science, or a related field. Familiarity with security frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and certifications like CISSP or CISM are commonly required. Leadership, attention to detail, and effective communication are important soft skills for managing security teams and collaborating across departments. These skills help ensure organizational data is protected, compliance standards are met, and business operations remain secure.

What is the role of the ISSM?

An ISSM (Information Systems Security Manager) is responsible for developing, implementing, and maintaining an organization's information security program. They oversee security policies, manage risk assessments, and ensure compliance with security standards such as NIST or ISO 27001. The role often requires certifications like CISSP and involves coordinating security efforts across technical and management teams.

What cities in Maryland are hiring for Issm jobs?

Cities in Maryland with the most Issm job openings:

Infographic showing various Issm job openings in Maryland as of August 2026, with employment types broken down into 96% Full Time, 2% Part Time, and 2% Contract. Highlights an 91% Physical, 4% Hybrid, and 5% Remote job distribution, with an average salary of $114,841 per year, or $55.2 per hour.

Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)

CALIBRE

Aberdeen Proving Ground, MD • On-site

Full-time

Re-posted 27 days ago


Job description

CALIBRE Systems, inc., an employee-owned, mission focused solutions and digital transformation company is seeking a highly experienced and professional Information Systems Security Officer (ISSO) / Information Systems Security Manager (ISSM) to support a Department of War (DoW) cybersecurity modernization initiative focused on Risk Management Framework (RMF) execution, continuous monitoring, compliance automation, and enterprise adoption of RegScale. This role will serve as the onsite primary cybersecurity compliance lead and trusted advisor to government stakeholders, cybersecurity personnel, system owners, and senior leadership.

The successful candidate will possess considerable expertise in RMF, DoW cybersecurity policy requirements, and project management. The individual will play a critical role in driving the implementation and adoption of RegScale while ensuring compliance with federal and DoW cybersecurity standards.

This position will be performed onsite at Aberdeen Proving Grounds (APG) and will be in support of systems on the DoW SIPRNet environment.  This position will be on site.  

Responsibilities

  • Serve as the onsite lead ISSO/ISSM supporting cybersecurity authorization and compliance efforts across multiple DoW systems.
  • Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes.
  • Act as onsite liaison between ASA(ALT) and Team CALIBRE to provide continued technical and product support for the RegScale application.
  • Installation of software and experience with databases and OS installation and configuration.
  • Provide expert guidance on all phases of the Risk Management Framework (RMF) lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Act as the organization's primary subject matter expert for eMASS, ensuring accurate management of authorization packages, security controls, inheritance relationships, POA&Ms, and system artifacts.
  • Maintain the RegScale accreditation throughout the SDLC, to include develop, maintain, and review security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action & Milestones (POA&Ms), and Standard Operating Procedures (SOPs).
  • Coordinate with government leadership, ISSMs, ISSOs, system owners, security control assessors, and engineers to ensure compliance with DoW cybersecurity requirements.
  • Conduct RegScale and eMASS user training sessions and provide ongoing support to stakeholders throughout the authorization process.
  • Support vulnerability management activities, including ACAS review, DISA STIG compliance, remediation tracking, and POA&M management for the RegScale application.
  • Identify opportunities across ASA(ALT) and Army organizations to automate compliance activities, improve operational efficiencies, and streamline enterprise cybersecurity processes.
  • Provide executive-level reporting, risk assessments, and recommendations to government and program leadership. 
  •  

Required Skills
  • Active Secret Clearance or higher.
  • Minimum of seven (7) years of hands-on experience supporting DoW or DoD systems utilizing eMASS.
  • Minimum of seven (7) years of experience executing RMF and Assessment & Authorization (A&A) activities within DoW or DoD environments.
  • Experience serving as either ISSO, ISSM, ISSE, Security Control Assessor (SCA), Validator, or equivalent cybersecurity role.
  • Expert-level proficiency with eMASS.
  • Extensive knowledge of:
  • Strong written and verbal communication skills with the ability to interact effectively with technical and non-technical stakeholders.
  • U.S. Citizenship required.
  • Experience implementing, administering, or supporting RegScale within a federal or DoW environment.
  • Experience with GRC platforms such as ServiceNow GRC, RSA Archer, Xacta, CSAM, or similar tools.
  • Experience integrating compliance tools with workflow, ticketing, and reporting systems.
  • Experience supporting AWS or other cloud-based environments.
  • Knowledge of ACAS, STIG Viewer, and vulnerability management best practices.
  • Master's degree in Cybersecurity, Information Assurance, Information Systems, or a related discipline.

Required Experience

Candidates must possess one of the following DoD 8570/8140 IAM Level III certifications:

  • CISSP
  • CISM
  • GSLC

Preferred certifications include:

  • CGRC
  • CISA
  • Security+

Why Join CALIBRE?

This is an opportunity to lead a high-visibility cybersecurity modernization effort supporting the Department of War. You will work directly with government stakeholders to advance compliance automation, improve RMF execution, and drive enterprise adoption of next-generation GRC capabilities through RegScale while serving as a key cybersecurity leader within the organization.