×
Register Here to Apply for Jobs or Post Jobs. X

Information Systems Security Manager

Job in Cedar Park, Williamson County, Texas, 78613, USA
Listing for: Firefly Aerospace
Full Time position
Listed on 2026-09-28
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

Career Opportunities with Firefly Aerospace

Come be a part of the 21 st Century Space Race!

Careers At Firefly Aerospace

Share with friends or Subscribe!

Current job opportunities are posted here as they become available.

Subscribe to our RSS feeds to receive instant updates as new positions become available.

Firefly Aerospace is a space and defense technology company on a mission to reliably and repeatedly launch, land, and operate space systems from Earth to the Moon and beyond. As the partner of choice for critical space missions, Firefly is the first commercial company to launch a satellite to orbit with 24-hour notice and the first company to achieve a successful Moon landing.

Headquartered in north Austin, Texas, Firefly is looking for passionate, hardworking innovators to join our team and help fuel our successful trajectory into space.

This position will be based out of our corporate headquarters in Cedar Park, TX

SUMMARY

As the Information Systems Security Manager at Firefly Aerospace, you will serve as the primary authority for ensuring mission-critical space systems and enterprise information systems achieve and maintain authorization to operate in compliance with national security requirements. You will own the Risk Management Framework (RMF) accreditation lifecycle per NIST SP 800-37 Rev. 2, implementing CNSSP-12 and CNSSI 53 requirements across space vehicle platforms, ground systems, and supporting infrastructure.

Serving as the primary liaison between system owners, engineering teams, and Government Authorizing Officials (AOs), you will translate security policy into system requirements, manage security authorization packages, and ensure continuous monitoring of security controls. You will report directly to the Director of Cybersecurity and work closely with systems engineering, Dev Ops, and mission operations teams.

RESPONSIBILITIESNational Security Systems Compliance: CNSSP-12 & CNSSI 53
  • Serve as subject matter expert for CNSSP-12 and CNSSI 53 requirements, translating policy mandates into specific system security requirements and control baselines for space vehicles, ground stations, and mission support systems
  • Lead security categorization activities per CNSSI 53, determining appropriate Impact Levels (IL) and establishing control overlays for all national security systems
  • Develop and maintain system security architecture documentation, including data flow diagrams, security boundary definitions, and control inheritance mappings
  • Coordinate with system owners and engineering teams to identify security control implementation requirements and validate that technical solutions meet policy mandates
  • Conduct security impact assessments, threat modeling, and risk assessments on proposed architectures, system changes, and configuration updates
  • Review and approve technical security requirements in system specifications, interface control documents (ICDs), and engineering design documentation
  • Manage end-to-end RMF processes per NIST SP 800-37 Rev. 2 for multiple concurrent systems to achieve and maintain Authorities to Operate (ATOs)
  • Develop, maintain, and update System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and coordinate Security Assessment Reports (SARs)
  • Coordinate independent security control assessments with Security Control Assessors (SCAs) or third-party assessment organizations
  • Prepare and deliver authorization packages to Authorizing Officials, including executive summaries, risk determinations, and authorization recommendations
  • Present compliance briefings to senior management, government customers, and AOs regarding security posture, risk status, and authorization timelines
Continuous Monitoring and Control Validation
  • Establish and operate continuous monitoring programs per NIST SP 800-137, defining security metrics, collection mechanisms, and reporting cadences
  • Validate system configurations comply with Security Technical Implementation Guides (STIGs), DISA baselines, and DoD security configuration requirements
  • Review vulnerability scan results, penetration test findings, and security assessment outputs to identify control weaknesses and drive remediation
  • Maintain current security control traceability matrices mapping policy requirements to implemented controls and assessment evidence
Corporate and Enterprise Compliance Programs
  • Lead corporate information security compliance initiatives ensuring adherence to NIST SP 800-171, NIST SP 800-53, CMMC, and Space Policy Directive 5 (SPD-5)
  • Support CMMC…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary