Sr. Information Systems Security Manger
Listed on 2026-10-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Location:
US-VA-Chantilly
We are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50+ locations world-wide. Much of our work contributes to innovative research in the fields of sensor science, signal processing, data fusion, artificial intelligence (AI), machine learning (ML), and augmented reality (AR).
QinetiQ US's dedicated experts in defense, aerospace, security, and related fields all work together to explore new ways of protecting the American Warfighter, Security Forces, and Allies. Being a part of QinetiQ US means being central to the safety and security of the world around us. Partnering with our customers, we help save lives; reduce risks to society; and maintain the global infrastructure on which we all depend.
WhyJoin QinetiQ US?
If you have the courage to take on a wide variety of complex challenges, then you will experience a unique working environment where innovative teams blend different perspectives, disciplines, and technologies to discover new ways of solving complex problems. In our diverse and inclusive environment, you can be authentic, feel valued, be respected, and realize your full potential. QinetiQ US will support you with workplace flexibility, a commitment to the health and well-being of you and your family and provide opportunities to work with a purpose.
We are committed to supporting your success in both your professional and personal lives.
QinetiQ US is seeking a senior Cybersecurity Information Systems Security Mnager to provide strategic cybersecurity support to a critical client in Chantilly, va. The cybersecurity professional will serve as the principal cybersecurity authority and liaison for internal, external, and guest information systems across multiple classification enclaves up to TS/SCI/SAR. Candidate will be responsible for the end-to-end Risk Management Framework (RMF) lifecycle, security architecture engineering, and continuous monitoring of complex on-premises, cloud, Platform IT (PIT), and Facility-Related Control Systems (FRCS).
Utilizing extensive cybersecurity policy writing expertise, this position partners with DoD mission partners and joint-service stakeholders to establish secure interconnectivity, govern Assured File Transfers (AFT), and execute guest system life cycles from initial site survey through final authorization.
- Lead comprehensive RMF Assessment and Authorization (A&A) efforts for DoD enterprise-level SaaS (IL5) and Facility-Related Control Systems (FRCS), preparing and validating complete System Security Plans (SSPs) to achieve and maintain System ATOs.
- Serve as the primary liaison between engineering staff and senior leadership, working directly with the Security Control Assessor (SCA), the SCO ITX Operations team, Information System Owner (ISO), and Authorizing Official (AO) to ensure DoD and NIST IA compliance.
- Execute robust continuous monitoring (Con Mon) programs, performing scheduled administrative and manual security checks to ensure the system's real-time risk posture remains within acceptable parameters.
- Proactively monitor privileged user accounts, conduct audit reviews, review configuration baselines, and data flows to prevent unauthorized modifications for SaaS environment.
- Develop, track, remediate, and report on Plans of Action and Milestones (POA&Ms), actively collaborating with technical teams to mitigate identified system vulnerabilities and close security gaps.
- Draft, establish, and enforce platform-specific cybersecurity policies and Standard Operating Procedures (SOPs) for a cloud-based SaaS solution, aligning cloud tenant configurations with JSIG, CNSSI 1253, and a multitude of DoD regulations.
- Maintain 100% physical and digital accountability of SAP removable media in coordination with the Agency Security team, enforcing strict lifecycle tracking from onboarding through witnessed destruction.
- Establish, document, and supervise strict AFT procedures (high-to-low/low-to-high) as a designated Data Transfer Agent (DTA), strictly enforcing Two-Person Integrity (TPI) and auditable transfer logging.
- Lead comprehensive cybersecurity assessments of FRCS (HVAC, Utility Control, Electronic Security Systems) in strict accordance with UFC 4-010-06 and NIST SP 800-82 (OT Security), executing the RMF process to secure and maintain ATOs.
- Direct…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).