Jobs › Maryland › Laurel › Information System Security Manager (ISSM)
Information System Security Manager (ISSM)
Johns Hopkins University Applied Physics Laboratory is hiring for the role of Information System Security Manager (ISSM), Laurel, MD (On-site). This is a Cybersecurity role in the governance, risk, and compliance field. Review the full details below and apply directly with Johns Hopkins University Applied Physics Laboratory.
Do you love solving problems while enabling impactful research to operate securely? APL is seeking motivated cybersecurity professionals to help develop system security plans, handle cyber risk decisions, and enable mission partners to innovate in a secure environment. As an Information System Security Manager, your primary responsibility will be to ensure classified systems follow government and APL regulations while meeting program demands and operating in an accredited state. You will lead all aspects of System Security Plan (SSP) development, maintenance, accreditation/re-accreditation, and oversight, including conducting periodic reviews to ensure compliance. You will function as lead contact for IS security inspections, tests, and reviews by oversight authorities, and support the Chief Information Security Officer and the Chief of Classified IT Compliance in carrying out the Laboratory's Classified Information Security Program. Minimum qualifications: BS in Computer Science, Cyber Security, or related field; 8+ years of relevant cybersecurity experience; current DoD 8140 Level III certification; 5+ years working with the RMF, DAAPM, NISPOM, JSIG or equivalent security frameworks; active Top Secret clearance; US citizenship. Preferred: prior experience as an Auditor, ISSO, ISSM, ISSE, Security Architect or Cyber Risk Manager.
Location and market context
This role is based in Laurel on-site. Local candidates benefit from being close to Johns Hopkins University Applied Physics Laboratory's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance roles
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Roles like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance role
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Johns Hopkins University Applied Physics Laboratory would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Senior Cybersecurity Engineer Specialist · Concurrent Technologies Corporation · Johnstown, PA
- Cyber Security Engineer III - Incident Response & Risk · Commerce Bank · Kansas City, MO
- Cybersecurity Risk Manager · Huntington National Bank · Detroit, MI
- Manager, IT Compliance · Arch Capital Group · Jersey City, NJ
- Information Security Risk Specialist · Booz Allen Hamilton · Arlington, VA
- Principal Technology Risk Management - Data Security · Early Warning · Phoenix, AZ
- Head of Government Cyber Integration · OpenAI · Remote
- Staff Security Engineer - Identity Risk & Governance · Nubank · Seattle, WA
More GRC jobs in Laurel
- Intelligence Analyst - Critical Infrastructure Protection · University of Baltimore · Baltimore, MD
- Information Systems Security Manager (ISSM) · University of Maryland · College Park, MD
- Critical & Emerging Technology Research Professional · University of Maryland (ARLIS) · College Park, MD
- Director of Governance, Risk & Compliance (GRC) · State of Maryland (DoIT) · Crownsville, MD
- Cybersecurity Risk Management Manager · State of Maryland (DoIT) · Crownsville, MD
- Compliance Training Technology Specialist · Johns Hopkins University · Baltimore, MD
Want to be next in a role like this?
Roles like Information System Security Manager (ISSM) in Laurel, MD open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.