Information Systems Security Manager

Foxtrot Division
Barcelona, Spain
2 months ago
Apply on es.trabajo.org
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Shift work
Job source

Tech stack

Software System Penetration Testing Cyber Security Information Systems Information Security Management Software Vulnerability Management SARS Software Products Information Technology

Job description

members are aligned with our core purpose. Through this alignment, we aim to leave a lasting, positive impact on the world, driving us further and faster towards our vision of excellence, with our people leading the charge.The Information Systems Security Manager (ISSM) serves as the senior cybersecurity leader responsible for overseeing and maintaining the security, compliance, and risk management of enterprise information systems. This role leads cybersecurity strategy, Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, and authorization efforts while ensuring compliance with federal and DoD cybersecurity requirements. The ISSM works closely with executive leadership, system owners, and security teams to protect organizational assets, manage cybersecurity risks, and maintain secure, authorized operations across the enterprise.Key Responsibilities- Serve as the senior cybersecurity authority and subject matter expert (SME) responsible for the organization’s Information Assurance (IA) and Cybersecurity Program.- Lead the planning, implementation, governance, and continuous improvement of cybersecurity policies, standards, procedures, and best practices across the enterprise.- Direct and oversee Risk Management Framework (RMF) activities throughout the system lifecycle, ensuring systems achieve and maintain Authority to Operate (ATO), Interim Authority to Operate (IATO), or Authorization to Connect (ATC) status.- Provide strategic leadership for cybersecurity risk management, continuous monitoring, compliance, and security modernization initiatives.- Review, approve, and maintain cybersecurity authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Security Control Traceability Matrices (SCTMs), and contingency planning documentation.- Serve as the primary liaison between Authorizing Officials (AOs), Information System Owners (ISOs), Information System Security Officers (ISSOs), system administrators, executive leadership, and external cybersecurity stakeholders.- Lead enterprise vulnerability management, remediation efforts, and security assessment activities to identify, prioritize, and mitigate cybersecurity risks.- Oversee continuous monitoring programs, security control effectiveness assessments, penetration testing reviews, audit response activities, and compliance reporting.- Develop and present executive-level cybersecurity metrics, risk assessments, and compliance status reports to support informed decision-making.- Coordinate cybersecurity inspections, audits, and assessments, ensuring timely remediation of findings from Security Control Assessors (SCAs), Inspector General (IG), Government Accountability Office (GAO), and other oversight organizations.- Provide leadership and oversight during cybersecurity incidents, coordinating response efforts, risk mitigation strategies, and post-incident corrective actions.-

Requirements

Supervise, mentor, and provide technical guidance to ISSOs, cybersecurity analysts, and security personnel while fostering a culture of security awareness and accountability.- Develop and manage cybersecurity awareness, role-based training, and workforce development programs to enhance organizational cybersecurity maturity.- Support cybersecurity budget planning, resource management, acquisition activities, and evaluation of emerging security technologies to strengthen organizational security posture.- Advise senior leadership on cybersecurity strategy, emerging threats, organizational risk exposure, and regulatory compliance requirements to ensure secure and mission-aligned operations.Required Qualifications- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field (Master’s degree preferred).- 10+ years of experience in Information Assurance, Cybersecurity, Information Security, or Risk Management, including at least 5 years

About the company

Foxtrot Division is positioned at the forefront of cyber systems engineering, driven by a mission to create secure systems that empower our clients to excel in their endeavors. At the heart of our success are our people-our dedicated engineers and team members-whose expertise, creativity, and passion are the bedrock of our success. We understand that our strength lies in the collective spirit and the unique talents of our team, which is why we deeply value and invest in their growth and well-being. Our mission is rooted in transcending the ordinary, a force that unites us and propels us forward. We are not content with business as usual; we are the rockstars ofour industry, challenging the status quo, and setting the pace for innovation and excellence. Our DNA-thinking deeply, speaking boldly, leading by example, and striving to be great-defines us and our approach to everything we do. At Foxtrot Division, we are committed to leading the way, ensuring that our products, services, and team

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all