1

Issm Jobs (NOW HIRING)

next page

Showing results 1-20

Issm information

See salary details

$46K

$118.3K

$184.5K

How much do issm jobs pay per year?

As of Jul 22, 2026, the average yearly pay for issm in the United States is $118,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,000.00 and $138,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Issm position, and why are they important?

To excel as an Information System Security Manager (ISSM), you need a strong background in information security, risk management, and compliance, typically supported by a degree in cybersecurity, computer science, or a related field. Familiarity with security frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and certifications like CISSP or CISM are commonly required. Leadership, attention to detail, and effective communication are important soft skills for managing security teams and collaborating across departments. These skills help ensure organizational data is protected, compliance standards are met, and business operations remain secure.

What is an ISSM job?

An Information Systems Security Manager (ISSM) is responsible for overseeing and implementing cybersecurity policies for an organization's information systems. They ensure compliance with security standards, manage risk assessments, and coordinate with security teams to protect sensitive data. ISSMs work closely with IT and leadership to develop and enforce security strategies that align with regulatory requirements.

What are the typical daily responsibilities of an Information System Security Manager (ISSM)?

An ISSM’s daily responsibilities often include overseeing the implementation and monitoring of security controls, performing regular risk assessments, and ensuring compliance with relevant security policies and regulations. You may also coordinate incident response efforts, review system access logs, and provide guidance to IT staff on best practices. Additionally, ISSMs frequently interact with auditors, senior management, and cross-functional teams to report on security findings and advise on system improvements. This role requires staying current with emerging threats and adapting security strategies to protect organizational assets effectively.

How much does an ISSM make?

An Information Systems Security Manager (ISSM) typically earns between $100,000 and $160,000 annually, depending on experience, certifications like CISSP, and the organization. Salaries in the Washington, D.C. area tend to be higher due to the demand for cybersecurity expertise in government and defense sectors.

What is the career path of the ISSM?

An Information Systems Security Manager (ISSM) typically advances through roles such as cybersecurity analyst, security engineer, and security architect before reaching the ISSM position. Career progression often involves gaining certifications like CISSP and experience in information security management, with opportunities to move into senior leadership or specialized security roles.

What can I do with an information systems management degree?

An information systems management degree prepares individuals for roles such as IT manager, systems analyst, network administrator, or cybersecurity manager. These positions involve overseeing technology infrastructure, managing IT projects, and ensuring data security, often requiring knowledge of project management, networking, and relevant certifications like CISSP or PMP.

Can you make $200,000 in cyber security?

Cybersecurity professionals, including roles like ISSM (Information Systems Security Manager), can earn $200,000 or more with extensive experience, advanced certifications (such as CISSP or CISM), and leadership responsibilities. Salaries vary based on industry, location, and organization size, with senior and specialized positions typically offering higher compensation.
More about Issm jobs
What cities are hiring for Issm jobs? Cities with the most Issm job openings:
What states have the most Issm jobs? States with the most job openings for Issm jobs include:
What job categories do people searching Issm jobs look for? The top searched job categories for Issm jobs are:
Infographic showing various Issm job openings in the United States as of July 2026, with employment types broken down into 95% Full Time, 2% Part Time, and 3% Contract. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $118,327 per year, or $56.9 per hour.

Information System Security Manager (ISSM)

Electronic Consulting Services, Inc (ECS Federal)

Fairfax, VA • On-site

$170K - $190K/yr

Other

This job post has expired today. Applications are no longer accepted.


Job description

Job Description
Everforth ECS is seeking an Information Systems Security Manager to work in our Fairfax, VA office .
Everforth ECS is seeking an experienced Information System Security Manager (ISSM) to support U.S. Navy systems and programs. The ISSM will serve as the primary cybersecurity authority for assigned systems, ensuring compliance with Department of Defense (DoD) and Department of the Navy (DON) cybersecurity policies under the Risk Management Framework (RMF).
The ideal candidate will have deep experience supporting Navy Authorizing Officials (AOs), working within Navy/DoD environments such as NAVWAR, NAVAIR, NAVSEA, or Fleet Cyber Command, and maintaining system authorization packages in eMASS.
The ISSM will lead the preparations and interactions with the government for system security assessments and ensure the IS maintains its Authority to Operate (ATO). The ISSM will manage the implementation of security policies, conduct risk assessments, manage security controls, and Plan of Actions and Milestones (POAM). The ISSM is expected to advise senior management on cybersecurity issues, communicate security risks, and collaborate with technical teams and other stakeholders. The successful candidate is able to multitask; assume ownership and accountability of risks, issues, and tasks; and successfully manage and resolve those risks, issues, and tasks to completion. The successful candidate is also able to work well in a team-oriented environment; self-manage his/her own tasks; and provide hands-on guidance, direction, and mentoring to the technical team. Finally, the successful candidate is extremely well-organized, well written, has a keen eye for detail, and can clearly articulate information (both orally and in writing) to customers, stakeholders, peers, and leadership within and external to the Program and organization.
Key Responsibilities:
  • Serve as the ISSM for Navy information systems in accordance with DoDI 8510.01 (RMF) and DoDI 8500.01 (Cybersecurity)
  • Oversee the full RMF lifecycle: categorization, control selection, implementation, assessment, authorization, and continuous monitoring
  • Develop, maintain, and manage RMF documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plan of Action & Milestones (POA&Ms)
    • Continuous Monitoring Strategies
  • Ensure compliance with:
    • NIST SP 800-53 Rev. 5 security controls
    • NIST SP 800-37 Rev. 2 (RMF Guide)
    • DoD Cybersecurity Manual (DoDM 5200.01)
    • SECNAV M-5239.1 (Department of the Navy Cybersecurity Manual)
  • Interface directly with Navy stakeholders including:
    • Authorizing Officials (AOs)
    • Security Control Assessors (SCAs)
    • Information System Owners (ISOs)
    • Program Managers (PMs)
  • Manage system accreditation activities within eMASS and ensure data accuracy and completeness
  • Conduct and support security control assessments, vulnerability management, and mitigation tracking
  • Ensure compliance with STIGs (Security Technical Implementation Guides) and SRGs (Security Requirements Guides) from DISA
  • Support audits, inspections, and cybersecurity readiness reviews (e.g., FISMA, DON CIO inspections)
  • Provide cybersecurity guidance to engineering teams throughout system development lifecycle (SDLC), aligning with DevSecOps practices where applicable
  • Oversee incident response coordination in alignment with DoDI 8530.01 (Cyber Incident Response) and Navy procedures

Salary Range: $170,000 - $190,000
General Description of Benefits
Required Skills
  • Active Secret clearance (TS/SCI preferred)
  • Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 12+ years of cybersecurity experience, with 3+ years as an ISSM or senior ISSO in a DoD/Navy environment
  • Strong experience implementing RMF under DoDI 8510.01 (latest version)
  • Hands-on experience with eMASS
  • In-depth knowledge of:
    • NIST SP 800-53 Rev. 5 controls
    • NIST SP 800-37 Rev. 2
    • DoDI 8500.01 / 8510.01
    • SECNAV M-5239.1
  • Experience supporting Navy programs (e.g., NAVWAR, NAVAIR, NAVSEA, or USMC systems)
  • Familiarity with:
    • DISA STIGs and SCAP compliance tools
    • ACAS (Assured Compliance Assessment Solution)
    • HBSS / Endpoint Security Solutions
  • Strong understanding of system architectures (on-prem, cloud, hybrid)

Desired Skills
  • Experience with Navy Authorizing Officials (AOs) and Navy-specific RMF processes
  • Familiarity with Platform IT (PIT) and Weapons Systems cybersecurity
  • Experience with DevSecOps pipelines and containerized environments
  • Knowledge of Zero Trust Architecture (DoD Zero Trust Strategy, 2022+)
  • Experience supporting systems in AWS GovCloud, Azure Government, or Navy cloud environments