Sr Information Systems Security Manager

OSI Systems, Inc.
Richardson, TX, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$145,000.0 - $155,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Information Security Management Network Connections Network Segmentation Open Systems Interconnection (OSI) Computer Network Operations SC Clearance Information Technology National Industrial Security Program Operating Manual (NISPOM)

Job description

The Information Systems Security Manager (ISSM) is responsible for the management, oversight, compliance, and security posture of classified information systems supporting Department of Defense (DoD) programs and contracts. The ISSM serves as the organization’s principal authority for classified cybersecurity and works closely with government customers, DCSA representatives, program managers, and external vendors to ensure compliance with DoD cybersecurity and classified information handling requirements. The ISSM will lead the design, implementation, accreditation, and ongoing management of classified information systems supporting Department of Defense (DoD) programs, as well as establishing a new SIPRNet-capable classified computing environment from initial planning through Authorization to Operate (ATO) and sustainment. This role requires a hands-on leader capable of building classified infrastructure, developing security documentation, managing Risk Management Framework (RMF) activities, implementing technical controls, and maintaining compliance with all applicable government regulations., * Serve as the designated ISSM for classified information systems supporting DoD contracts and programs

  • Develop, implement, and maintain system security policies, procedures, and documentation
  • Ensure compliance with NISPOM, DAAG, RMF, and applicable government security requirements
  • Maintain system authorization packages and support Authorization to Operate (ATO) efforts
  • Coordinate with government Authorizing Officials (AO), Security Control Assessors (SCA), Information System Owners (ISO), and cybersecurity stakeholders

SIPRNet Enclave Development & Implementation

  • Lead the planning, design, and deployment of a new SIPRNet-connected infrastructure
  • Coordinate with government sponsoring agencies, DISA, and program stakeholders to establish classified network connectivity
  • Develop enclave architecture supporting classified processing, storage, and transmission requirements
  • Define and implement security boundaries, network segmentation, and defense-in-depth controls
  • Coordinate procurement, installation, and configuration of classified IT infrastructure
  • Ensure all SIPRNet infrastructure complies with DISA and customer requirements

COMSEC Program Management

  • Serve as the COMSEC Account Manager and primary point of contact for all COMSEC-related matters involving classified communications systems
  • Manage the COMSEC program in accordance with National Security Agency (NSA), DoD, and customer-specific requirements
  • Develop COMSEC policies, procedures, and local operating instructions to support classified network operations
  • Ensure proper safeguarding, accountability, storage, transfer, destruction, and inventory of COMSEC material
  • Maintain compliance with applicable Communications Security policies, regulations, and inspection requirements

Incident Response

  • Investigate cybersecurity incidents affecting classified systems
  • Coordinate reporting and response activities in accordance with DoD and DCSA requirements
  • Support forensic preservation, root-cause analysis, and corrective action implementation
  • Maintain incident documentation and reporting records

Audits and Inspections

  • Prepare systems and supporting documentation for DCSA inspections, customer assessments, and cybersecurity audits
  • Support internal and external compliance reviews
  • Respond to findings and ensure timely corrective actions
  • Maintain audit-ready security records and accreditation artifacts

Security Awareness and Training

  • Provide cybersecurity guidance to program personnel and system users
  • Deliver security awareness training related to COMSEC and handling classified information systems
  • Mentor Information System Security Officers (ISSOs) and administrators on compliance requirements and best practices
  • Uphold the company’s core values of Integrity, Innovation, Accountability, and Teamwork
  • Demonstrate behavior consistent with the company’s Code of Ethics and Conduct
  • It is the responsibility of every employee to report to their manager or a member of senior management any quality problems or defects in order for corrective action to be implemented and to avoid recurrence of the problem
  • Duties may be modified or assigned at any time to meet the needs of the business, OSI Systems, Inc. and its subsidiaries (collectively “OSI”) does not accept unsolicited resumes from recruiters or employment agencies. If any person or entity, including a recruiter or agency, submits any information, including any resume or information regarding any potential candidate, without a signed agreement in place with OSI, OSI explicitly reserves the right to use such information, and pursue and/or hire such candidates, without any financial obligation to the person, recruiter or agency. Any unsolicited information or resumes, including those submitted directly to hiring managers, are considered and deemed to be the property of OSI. Equal Opportunity Employer - Disability and Veteran Know Your Rights Poster Link: https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf OSI Systems, Inc. has three operating divisions: (a) Security, providing security and inspection systems, turnkey security screening solutions and related services; (b) Healthcare, providing patient monitoring, diagnostic cardiology and anesthesia systems; and (c) Optoelectronics and Manufacturing, providing specialized electronic components and electronic manufacturing services for original equipment manufacturers with applications in the defense, aerospace, medical and industrial markets, among others.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related discipline preferred. Equivalent military or industry experience may be substituted
  • 8+ years supporting classified information systems in DoD or Intelligence Community environments.
  • 5+ years serving as ISSM or senior ISSO
  • Demonstrated experience standing up classified networks or SIPRNet environments.
  • Experience leading RMF authorization efforts from system inception through ATO.
  • Experience working directly with:
  • DISA
  • DCSA
  • Government cybersecurity offices
  • Defense contractors
  • Experience supporting secure facility buildouts and classified infrastructure deployments

Security Clearance

  • Active Secret Clearance required
  • TS eligibility preferred

Certifications Required (one or more):

  • CISSP
  • CASP+
  • CISM
  • Security+
  • CEH
  • GSLC
  • CCSP
  • CAP (Certified Authorization Professional)

Must meet DoD 8570 / 8140 workforce requirements applicable to the position Preferred Qualifications

  • Previous experience building SIPRNet enclaves from inception or supporting them.
  • Experience with DISA connection approval processes.
  • Experience supporting classified cloud or hybrid environments.
  • Experience with Cross Domain Solutions (CDS).
  • Prior military cyber, communications, intelligence, or network operations experience

Pay may range from $145,000 to $155,000 annually The pay range above represents annual base salary only. Final compensation will be determined based on factors such as your job level, geographic location, date of hire, experience, job-related knowledge and skills, and education in conjunction with market and business considerations.

Benefits & conditions

Pulled from the full job description

  • Employee stock purchase plan
  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Health savings account
  • Paid jury duty, Base salary is one component of your total rewards package. You may be eligible for long-term incentives, potential discretionary bonuses, and the ability to purchase company stock at a discounted rate through the Employee Stock Purchase Program (ESPP). OSI also offers comprehensive benefits including various options for health plans, access to 401(k) retirement plan, health savings account, disability insurance, life insurance, AD&D insurance, leave of absence programs and an array of voluntary benefits. In addition, paid time off is offered to be used for vacation, holidays, bereavement, and jury duty. Full-Time salaried employees are entitled to flexible time-off.

About the company

Continental Electronics Corporation is a leading provider of RF technologies and innovative solutions with 80 years of proven performance. CEC has experienced significant recent growth and has established itself as the go-to supplier for a diversified product line supporting a wide spectrum of markets from commercial products, military customers, to space research laboratories.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all