Information Systems Security Manager (ISSM)
Summary
Lead cybersecurity compliance and risk management for a defense-tech firm, ensuring adherence to NIST, DFARS, ISO 27001, and CMMC while protecting classified and sensitive data.
- Develop, implement, and maintain the company's information security policies, standards, and procedures to ensure compliance with NIST SP 800-171, DFARS 252.204-7012, and other relevant regulations.
- Lead efforts to achieve and maintain compliance with CMMC and ISO 27001, including coordinating certification processes and managing ongoing audits.
- Oversee the protection of Controlled Unclassified Information (CUI) and other controlled information.
- Implement and oversee procedures for handling classified information, ensuring compliance with all applicable government regulations and directives.
- Conduct regular risk assessments and vulnerability analyses to identify and mitigate potential security threats, including those related to classified information systems.
- Coordinate with internal teams to integrate security controls into all aspects of operations, including product development and supply chain management.
- Serve as the primary liaison with government agencies and customers regarding information security compliance, and reporting.
- Develop and manage the incident response plan, leading investigations and remediation efforts, in the event of security breaches or incidents involving classified or sensitive information.
- Provide training and awareness programs to educate employees on information security policies, procedures, best practices, and the handling of classified information.
- Stay current with evolving regulatory requirements, emerging threats, and industry best practices to continuously improve the company's security posture.
- Collaborate with our DevSecOps team on the design, implementation and maintenance of cATO (continuous Authority to Operate) pipelines.
- Collaborate with IT and engineering teams to ensure secure system architectures and data protection mechanisms are in place, especially for systems processing classified information.
- Must be willing to travel up to 10%
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity or a related field; relevant experience may be substituted in lieu of a degree
- U.S. Citizenship required due to ITAR regulations, with the ability to obtain and maintain a DoD security clearance
- 7+ years of experience in information security management, with at least 3 years in a leadership role.
- Extensive knowledge of NIST SP 800-171, NIST SP 800-53, DISA-STIGS, DFARS 252.204-7012, ISO 27001, CUI handling requirements, and classified information security protocols.
- Proven experience in developing and implementing information security programs and achieving compliance with regulatory standards.
- Strong understanding of risk management principles and experience conducting risk assessments and vulnerability management, including in classified environments.
- Experience with incident response planning and execution, particularly concerning classified information.
- Familiarity with data protection laws and regulations.
- Excellent communication skills, with the ability to articulate complex security requirements to technical and non-technical stakeholders.
- Professional certifications such as CISSP, Security+, CISM, CISA or other DoD Approved 8570 Baseline Certification in the Information Assurance Management (IAM) Level III category.
- Defense or aerospace industry experience a plus.
- Familiarity with cybersecurity maturity models like CMMC (Cybersecurity Maturity Model Certification).
- Experience with security audit processes and interfacing with regulatory auditors.
- Experience with informing design and implementation cATO pipelines.
- Experience with classified information systems (e.g., Joint Worldwide Intelligence Communications System - JWICS, Secret Internet Protocol Router Network - SIPRNet).
- Experience with Special Access Programs (SAP) and Sensitive Compartmented Information (SCI).
- Knowledge of cloud security principles and experience securing cloud environments handling classified or sensitive data.
- Position is based onsite at our San Diego, CA headquarters
- We welcome candidates who are local or open to relocating; relocation assistance is available and may be included in the offer package where appropriate.
- Willingness and ability to travel up to 10% for seminars
- Base salary: $140,000 - $180,000 base, commensurate with experience
- Equity: Meaningful equity grant in a growth-stage defense technology company
- We offer comprehensive medical, dental, and visions plans
- 401(k) Retirement Savings Plan to invest in your long-term retirement goals
- Equity grants for new hires
- Unlimited PTO
- Extremely generous company holiday calendar, including holiday hiatuses in July & December.
- Generous Parental Leave
- Lifestyle Spending Account
- FSA
- DCFSA
- HSA
- Hospital Indemnity insurance
- Critical Illness insurance
- Accident insurance
- Basic Life/AD&D, short-term and long-term disability insurance, 100% covered by Firestorm. Plus, the option to purchase additional life insurance for you and your family.
- Mental Health Resources: We provide free mental health resources 24/7 including therapy and more. Additional work-life services, such as free legal and financial support, are available to you as well.