Information Systems Security Manager
Listed on 2026-08-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Overview
We are seeking a highly skilled and experienced Information System Security Manager (ISSM) to join our dedicated team at the San Diego location. The successful candidate will possess a proven track record as an ISSM, demonstrating exceptional autonomy, self-motivation, and a comprehensive understanding of cybersecurity principles. This pivotal role will be instrumental in ensuring IMC's adherence to National Industrial Security Program (NISP) and National Institute of Standards and Technology (NIST) special publication compliance for all information systems processing Controlled Unclassified Information (CUI) and classified data.
JobOverview
We are seeking a highly skilled and experienced Information System Security Manager (ISSM) to join our dedicated team at the San Diego location. The successful candidate will possess a proven track record as an ISSM, demonstrating exceptional autonomy, self-motivation, and a comprehensive understanding of cybersecurity principles. This pivotal role will be instrumental in ensuring IMC's adherence to National Industrial Security Program (NISP) and National Institute of Standards and Technology (NIST) special publication compliance for all information systems processing Controlled Unclassified Information (CUI) and classified data.
Key responsibilities will include, but are not limited to, the strategic implementation and oversight of robust cybersecurity measures such as endpoint protection, comprehensive vulnerability management programs, and diligent patch management protocols.
- Security Platform Management
- Administer and maintain cloud security posture management (CSPM) and vulnerability management platforms including Qualys, Crowd Strike, and Bitsight
- Design, build, and operate Crowd Strike solutions across cloud and cloud-native environments to enhance threat visibility, risk identification, and vulnerability remediation
- Information System Program Management
- Develop, implement, and maintain system security policies, plans and procedures in alignment with RMF, NIST 800 publications, DAAPM, and NISPOM requirements.
- Develop and maintain security architecture and security policies, principles and standards.
- Develop and validate baseline security configurations for operating systems, applications, and networking equipment.
- Authorization and Accreditation
- Manage the system lifecycle management process, including developing and maintaining security plans and documentation
- Risk Management and Compliance
- Perform and document risk assessments; manage POA&M’s with stakeholders to identify weaknesses, mitigation actions, and timelines; enforce configuration management and assess system changes for security impact.
- Knowledge of current and emerging threats/threat vectors.
- Knowledge of vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins).
- Knowledge of penetration testing principles, tools, and techniques.
- Participate in security investigations and compliance reviews, as requested by internal or external auditors.
- Continuous Monitoring and Auditing
- Implement continuous monitoring strategies; conduct regular audits and assessments to ensure controls remain effective and vulnerabilities are addressed promptly.
- Incident Response and Reporting
- Monitor for security incidents and vulnerabilities; manage incident response, system recovery, and reporting processes to restore security safeguards quickly and accurately.
- Provide second- and third-level support and analysis during and after a security incident.
- Assist security administrators and IT staff in the resolution of reported security incidents.
- Training and Awareness
- Develop and implement system security training and awareness program for all roles; brief users on security responsibilities and ensure training completion before access.
- Stakeholder Coordination
- Communicate regularly with stakeholders: FSO, SMO, managers, users, DCSA
- IT Administration
- Provide backup IT support when required.
- Oversee ISSO’s under their purview to ensure they follow established IS policies and procedures
- Assume ISSO responsibilities in the absence of the ISSO; maintain required IA certifications
- Ensure…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).