Information Systems Security Manager (ISSM)
Firestorm · San Diego, CA · 4 days ago
On-siteInformation Technology$140k–$180k/yrFull-time
About the role
We are looking for a highly skilled and motivated Information Systems Security Manager (ISSM) to join our team onsite at our San Diego office. Reporting to the Director of Operations, you will be at the forefront of developing, implementing, and upholding our company's digital security compliance strategy and information security, ensuring compliance with stringent government regulations and standards. Your expertise will be crucial in protecting our sensitive data, managing risks, and ensuring that our operations meet all required cybersecurity maturity models and information control protocols.
Responsibilities
- Develop, implement, and maintain the company's information security policies, standards, and procedures to ensure compliance with NIST SP 800-171, DFARS 252.204-7012, and other relevant regulations.
- Lead efforts to achieve and maintain compliance with CMMC and ISO 27001, including coordinating certification processes and managing ongoing audits.
- Oversee the protection of Controlled Unclassified Information (CUI) and other controlled information.
- Implement and oversee procedures for handling classified information, ensuring compliance with all applicable government regulations and directives.
- Conduct regular risk assessments and vulnerability analyses to identify and mitigate potential security threats, including those related to classified information systems.
- Cook with internal teams to integrate security controls into all aspects of operations, including product development and supply chain management.
- Serve as the primary liaison with government agencies and customers regarding information security compliance, and reporting.
- Develop and manage the incident response plan, leading investigations and remediation efforts, in the event of security breaches or incidents involving classified or sensitive information.
- Provide training and awareness programs to educate employees on information security policies, procedures, best practices, and the handling of classified information.
- Stay current with evolving regulatory requirements, emerging threats, and industry best practices to continuously improve the company's security posture.
- Collaborate with our DevSecOps team on the design, implementation and maintenance of cATO (continuous Authority to Operate) pipelines.
- Collaborate with IT and engineering teams to ensure secure system architectures and data protection mechanisms are in place, especially for systems processing classified information.
Qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity or a related field; relevant experience may be substituted in lieu of a degree.
- U.S. Citizenship required due to ITAR regulations, with the ability to obtain and maintain a DoD security clearance.
- 7+ years of experience in information security management, with at least 3 years in a leadership role.
- Extensive knowledge of NIST SP 800-171, NIST SP 800-53, DISA-STIGS, DFARS 252.204-7012, ISO 27001, CUI handling requirements, and classified information security protocols.
- Proven experience in developing and implementing information security programs and achieving compliance with regulatory standards.
- Strong understanding of risk management principles and experience conducting risk assessments and vulnerability management, including in classified environments.
- Experience with incident response planning and execution, particularly concerning classified information.
- Familiarity with data protection laws and regulations.
- Excellent communication skills, with the ability to articulate complex security requirements to technical and non-technical stakeholders.
Skills
- Professional certifications such as CISSP, Security+, CISM, CISA or other DoD Approved 8570 Baseline Certification in the Information Assurance Management (IAM) Level III category.
- Defense or aerospace industry experience a plus.
- Familiarity with cybersecurity maturity models like CMMC (Cybersecurity Maturity Model Certification).
- Experience with security audit processes and interfacing with regulatory auditors.
- Experience with informing design and implementation cATO pipelines.
- Experience with classified information systems (e.g., Joint Worldwide Intelligence Communications System - JWICS, Secret Internet Protocol Router Network - SIPRNet).
- Experience with Special Access Programs (SAP) and Sensitive Compartmented Information (SCI).
- Knowledge of cloud security principles and experience securing cloud environments handling classified or sensitive data.
Benefits
- Base salary: $140,000 - $180,000 base, commensurate with experience.
- Equity: Meaningful equity grant in a growth-stage defense technology company.
- Comprehensive medical, dental, and vision plans.
- 401(k) Retirement Savings Plan.
- Unlimited PTO.
- Generous Parental Leave.
- Lifestyle Spending Account.
- Free mental health resources 24/7.
- Legal and financial support.