Information Assurance Deputy Director
York Space Systems · Greenwood Village, CO · 1 wk ago
OTHRFull-time
York Space Systems was founded to radically improve spacecraft affordability and reliability, transforming and enabling next-generation space mission operations worldwide. Today, York is one of the most innovative aerospace companies, specializing in end-to-end customer solutions and the rapid production of spacecraft platforms. The Information Assurance Deputy Director serves as the senior cybersecurity authority overseeing the compliance, authorization, and operational resilience of secure enterprise networks, classified enclaves, and mission IT infrastructure.
Responsibilities
- Governance, Risk & Compliance (GRC) Leadership
- Oversee the end-to-end Risk Management Framework (RMF) lifecycle for all Department of Defense (DoD) and Intelligence Community (IC) classified and unclassified systems.
- Lead the creation, submission, and maintenance of System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Plan of Action & Milestones (POA&Ms), and Authorization to Operate (ATO) packages across eMASS and XACTA systems.
- Serve as the primary cybersecurity interface to Authorizing Officials (AOs), Security Control Assessors (SCAs), DCSA, and customer security representatives.
- Ensure organizational alignment with CMMC 2.0, NIST SP 800-53, NIST SP 800-171, NISPOM (32 CFR Part 117), ICD 503, and JSIG requirements.
- Technical & Mission IT Infrastructure Oversight
- Provide operational direction to the Mission IT Lead to ensure network infrastructure and system administration efforts adhere strictly to cybersecurity architecture standards.
- Review and approve system architectural designs, cross-domain solutions (CDS), hardware/software baseline updates, and network topology modifications for classified environments.
- Enforce implementation of DISA Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP) benchmarks, and automated continuous monitoring tools.
- Drive Zero Trust Architecture (ZTA) initiatives, network segmentation, identity and access management (IAM), and centralized logging strategies across secure enclaves.
- Cybersecurity Operations & Incident Response
- Lead the enterprise Cyber Incident Response Team (CIRT); direct containment, eradication, forensic investigations, and reporting of security incidents in compliance with federal guidelines.
- Oversee vulnerability management programs, ensuring routine scanning (Tenable/Nessus, ACAS), patch management, and remediation timelines are strictly enforced.
- Collaborate with the Insider Threat Program Senior Official to integrate audit logging, SIEM alerts, and user activity monitoring (UAM) mechanisms.
- Team Management & Operational Budgeting
- Directly manage, mentor, and evaluate the performance of DoD/IC ISSMs and technical IT leadership.
- Establish standardized operational procedures (SOPs), cybersecurity policies, and technical baselines across all program enclaves.
- Manage hardware/software procurement requests, licensing, and cybersecurity budgeting requirements.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related technical discipline (Master’s degree preferred).
- Minimum of 8+ years of progressive experience in Information Assurance, Cybersecurity, and Mission IT operations, with at least 3–5+ years in a supervisory/management capacity.
- Proven experience managing ATO pipelines under both DoD RMF (eMASS) and IC RMF (ICD 503 / XACTA).
- Demonstrated experience leading network engineering and systems administration staff within secure environments.
- Active Top Secret / SCI clearance.
- Exceptional oral/written communication skills, cross-functional project management, and government auditor interaction skills.
Skills
- Mandatory Certifications (DoD 8140 / 8570 IAM Level III):
- Must hold at least one active IAM Level III certification upon hire: CISSP, CISM, GSLC, or CCISO.
- Compliance Frameworks: NIST SP 800-53, NIST SP 800-171, RMF, ICD 503, JSIG, DAAPM, NISPOM, CMMC 2.0.
- Systems & Platforms: Windows Server / Linux RHEL administration, VMware vSphere, Cisco/Juniper networking, Active Directory/PKI, eMASS, XACTA.
- Cybersecurity Tools: ACAS/Nessus, Splunk/SIEM platforms, HBSS/ESS, SCAP Compliant Compliance Checker.
This role will be fully on-site in our Greenwood Village, Colorado office.
Benefits
- 100% employer-paid medical, dental, and vision insurance (subject to spousal surcharge).
- Company holidays, floating holidays, and sick time.
- Unlimited PTO.
- Generous 401(k) match.
- Participation in discretionary annual bonus and equity programs.
- Eligibility to participate in the equity award program (discretionary, contingent upon individual and/or Company performance).