Information Systems Security Manager (ISSM
Listed on 2026-07-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
This is an exciting opportunity to join a fast-growing startup in the aerospace/defense industry as their Information Systems Security Manager (ISSM). This position will be at the forefront of developing, implementing, and upholding our company's digital security compliance strategy and information security, alignment with rigorous governmental standards and regulatory frameworks. Your expertise will be essential in safeguarding proprietary assets, orchestrating risk mitigation strategies, and verifying operational adherence to mandated cybersecurity maturity models and information governance protocols.
Leveraging extensive knowledge in NIST, DFARS, ISO 27001, and classified information stewardship, you'll be instrumental in fortifying operational security and maintaining compliance with defense sector requirements.
- Create, execute, and update organizational information security frameworks, guidelines, and protocols to align with NIST SP 800-171, DFARS , and additional applicable regulations.
- Spearhead initiatives to secure and sustain CMMC and ISO 27001 certifications, including orchestrating assessment procedures and overseeing audits.
- Supervise the safeguarding of Controlled Unclassified Information (CUI) and related sensitive data assets.
- Establish and monitor protocols for classified information handling, ensuring adherence to all relevant governmental regulations and directives.
- Perform systematic risk evaluations and security gap analyses to detect and address potential vulnerabilities, particularly those affecting classified information systems.
- Partner with cross-functional teams to embed security measures throughout operational domains, including product lifecycle and vendor relationship management.
- Serve as the primary liaison with government agencies and customers regarding information security compliance and reporting.
- Develop and oversee the incident response framework, directing investigations and corrective actions following security compromises involving classified or sensitive information.
- Deliver training programs to enhance employee understanding of security policies, procedures, recommended practices, and classified information protocols.
- Monitor changes in regulatory landscapes, security threats, and sector-specific best practices to enhance the organization's defensive posture.
- Engage with Dev Sec Ops specialists on the design, deployment, and support of continuous Authority to Operate (cATO) workflows.
- Work alongside IT and engineering personnel to ensure robust system architectures and data protection mechanisms, with special focus on systems handling classified information.
- BS in Information Security, Computer Science, Cybersecurity or similar related field
- 7+ years of experience in information security management; 3 or more years in a leadership role
- Extensive knowledge of NIST SP 800-171, DFARS , DISA-STIGS, ISO 27001, CUI handling requirements, and classified information security protocols.
- Demonstrated track record in crafting and deploying comprehensive information security frameworks and attaining regulatory compliance benchmarks.
- Robust grasp of risk governance fundamentals and proven capability in executing threat assessments and vulnerability oversight, particularly within classified domains.
- Experience with incident response planning and execution, particularly concerning classified information.
- Working knowledge of data protection laws and regulations.
- Superior interpersonal and communication capabilities, adept at translating intricate security protocols for diverse audiences spanning technical specialists and executive leadership.
- Must be a U.S. Person due to the nature of work & required access to U.S. export-controlled information
- Must be able to obtain and maintain a U.S. Government security clearance.
- Must be willing to travel (up to 10%)
- Relevant professional certifications (i.e.CISSP, CISM, CISA, Security+, ISP) or other DoD 8570 certifications in Information Assurance Management (Level III) is strongly preferred
- Knowledge of cloud security principles and experience securing cloud environments handling classified or sensitive data.
- Familiar with cybersecurity maturity models and CMMC a plus
- Previous experience managing Facility Security Clearances (FCL) and handling classified information within a defense contractor environment is a plus
- Experience with security audit processes and interfacing with regulatory auditors a plus
- Experience with classified information systems a plus
- Experience with Special Access Programs (SAP) and Sensitive Compartmented Information a plus
$150k - $175k annual base salary
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).