1

Isso Issm Jobs in Baltimore, MD (NOW HIRING)

ISSO 1

Annapolis Junction, MD · On-site

$80K - $95K/yr

We are seeking an ISSO 1 to join our team. In this role, you will: -Provide support to senior ISSOs ... ISSM) for maintaining the appropriate operational IA posture for a system, program, or enclave ...

ME00620-ISSO 1

Annapolis, MD · On-site

$110K - $145K/yr

Serve as the Information Systems Security Officer (ISSO) for assigned information systems and support the Information System Security Manager (ISSM) in maintaining the overall security posture

next page

Showing results 1-20

Isso Issm information

See Baltimore, MD salary details

$45.7K

$117.6K

$183.3K

How much do isso issm jobs pay per year?

As of Aug 2, 2026, the average yearly pay for isso issm in Baltimore, MD is $117,574.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,400.00 and $137,100.00 per year, depending on experience, location, and employer.

What are the main challenges faced by an Information Systems Security Officer (ISSO) or Information Systems Security Manager (ISSM) when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What are the key skills and qualifications needed to thrive as an Information System Security Officer (ISSO) or Information Systems Security Manager (ISSM), and why are they important?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What does isso issm mean?

In the context of a job, 'ISSO' stands for Information System Security Officer, a role responsible for managing and implementing security policies for information systems. 'ISSM' refers to Information System Security Manager, who oversees security programs and ensures compliance with security standards. Both positions typically require knowledge of cybersecurity frameworks and security tools.

Which is higher, isso or issm?

In the context of job titles, 'ISSO' (Information System Security Officer) is typically a higher or more senior role than 'ISSM' (Information System Security Manager), though the specific hierarchy can vary by organization. Both roles involve cybersecurity responsibilities, with ISSO often focusing on security compliance and ISSM on managing security programs and teams. Certifications like CISSP are common for both positions, and experience levels can influence seniority.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

How much money does an isso make?

An Isso Issm typically earns a salary that varies based on experience, location, and industry, but the average salary ranges from $50,000 to $80,000 annually. They often require technical skills and certifications related to infrastructure management and systems administration.

Can you make $500,000 a year in cyber security?

In cybersecurity, reaching a $500,000 annual salary is possible for senior roles such as security executives or specialists with extensive experience, advanced certifications, and leadership responsibilities. Most cybersecurity professionals earn lower salaries, but high-level positions in large organizations or consulting firms can offer compensation at this level.

What are ISSOs and ISSMs?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.
What are popular job titles related to Isso Issm jobs in Baltimore, MD? For Isso Issm jobs in Baltimore, MD, the most frequently searched job titles are:
What cities near Baltimore, MD are hiring for Isso Issm jobs? Cities near Baltimore, MD with the most Isso Issm job openings:
Infographic showing various Isso Issm job openings in Baltimore, MD as of July 2026, with employment types broken down into 96% Full Time, 2% Part Time, and 2% Contract. Highlights an 94% Physical, 3% Hybrid, and 3% Remote job distribution, with an average salary of $117,574 per year, or $56.5 per hour.

Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)

CALIBRE Systems

Aberdeen, MD • On-site

Full-time

Posted 24 days ago


Job description


CALIBRE Systems, inc., an employee-owned, mission focused solutions and digital transformation company is seeking a highly experienced and professional Information Systems Security Officer (ISSO) / Information Systems Security Manager (ISSM) to support a Department of War (DoW) cybersecurity modernization initiative focused on Risk Management Framework (RMF) execution, continuous monitoring, compliance automation, and enterprise adoption of RegScale. This role will serve as the onsite primary cybersecurity compliance lead and trusted advisor to government stakeholders, cybersecurity personnel, system owners, and senior leadership.
The successful candidate will possess considerable expertise in RMF, DoW cybersecurity policy requirements, and project management. The individual will play a critical role in driving the implementation and adoption of RegScale while ensuring compliance with federal and DoW cybersecurity standards.
This position will be performed onsite at Aberdeen Proving Grounds (APG) and will be in support of systems on the DoW SIPRNet environment. This position will be on site.
Responsibilities
  • Serve as the onsite lead ISSO/ISSM supporting cybersecurity authorization and compliance efforts across multiple DoW systems.
  • Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes.
  • Act as onsite liaison between ASA(ALT) and Team CALIBRE to provide continued technical and product support for the RegScale application.
  • Installation of software and experience with databases and OS installation and configuration.
  • Provide expert guidance on all phases of the Risk Management Framework (RMF) lifecycle, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Act as the organization's primary subject matter expert for eMASS, ensuring accurate management of authorization packages, security controls, inheritance relationships, POA&Ms, and system artifacts.
  • Maintain the RegScale accreditation throughout the SDLC, to include develop, maintain, and review security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action & Milestones (POA&Ms), and Standard Operating Procedures (SOPs).
  • Coordinate with government leadership, ISSMs, ISSOs, system owners, security control assessors, and engineers to ensure compliance with DoW cybersecurity requirements.
  • Conduct RegScale and eMASS user training sessions and provide ongoing support to stakeholders throughout the authorization process.
  • Support vulnerability management activities, including ACAS review, DISA STIG compliance, remediation tracking, and POA&M management for the RegScale application.
  • Identify opportunities across ASA(ALT) and Army organizations to automate compliance activities, improve operational efficiencies, and streamline enterprise cybersecurity processes.
  • Provide executive-level reporting, risk assessments, and recommendations to government and program leadership.

Required Skills
  • Active Secret Clearance or higher.
  • Minimum of seven (7) years of hands-on experience supporting DoW or DoD systems utilizing eMASS.
  • Minimum of seven (7) years of experience executing RMF and Assessment & Authorization (A&A) activities within DoW or DoD environments.
  • Experience serving as either ISSO, ISSM, ISSE, Security Control Assessor (SCA), Validator, or equivalent cybersecurity role.
  • Expert-level proficiency with eMASS.
  • Extensive knowledge of:
  • Strong written and verbal communication skills with the ability to interact effectively with technical and non-technical stakeholders.
  • U.S. Citizenship required.
  • Experience implementing, administering, or supporting RegScale within a federal or DoW environment.
  • Experience with GRC platforms such as ServiceNow GRC, RSA Archer, Xacta, CSAM, or similar tools.
  • Experience integrating compliance tools with workflow, ticketing, and reporting systems.
  • Experience supporting AWS or other cloud-based environments.
  • Knowledge of ACAS, STIG Viewer, and vulnerability management best practices.
  • Master's degree in Cybersecurity, Information Assurance, Information Systems, or a related discipline.

Required Experience
Candidates must possess one of the following DoD 8570/8140 IAM Level III certifications:
  • CISSP
  • CISM
  • GSLC

Preferred certifications include:
  • CGRC
  • CISA
  • Security+

Why Join CALIBRE?
This is an opportunity to lead a high-visibility cybersecurity modernization effort supporting the Department of War. You will work directly with government stakeholders to advance compliance automation, improve RMF execution, and drive enterprise adoption of next-generation GRC capabilities through RegScale while serving as a key cybersecurity leader within the organization.