> Markdown version of [/jobs/ext/1747584-information-system-security-site-lead](https://www.wearedevelopers.com/jobs/ext/1747584-information-system-security-site-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Site Lead - **Company:** QNity, Inc. - **Location:** Carlsbad, CA, United States - **Experience:** Expert - **Salary:** $99,120.0 - $155,760.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Event Logging, Identity and Access Management, Information Security Management, Nessus - **Published:** July 8, 2026 - **Apply:** https://dejobs.org/x/x/77F8FED24AB84CA4A9AA43480162EF5B/job/ ## About the Role Are you looking to power the next leap in the exciting world of advanced electronics? Do you want to help solve problems that drive success in the rapidly evolving technology and connectivity landscape? Then bring your problem-solving, passion, and creativity to help us power the next leap in electronics., * MUST BE A U.S. CITIZEN due to government security clearance requirement. * Final Transferable Secret security clearance; last Periodic Reinvestigation must be within the last five (5) years or enrollment in Continuous Vetting program * Experience executing Security Hardening on based on approved DISA STIGs and SRGs * Experience with standard cyber security tools and applications (e.g., Nessus Pro) * Proven technical expertise and knowledge * Ability to build effective customer and partner relationships Desired Skills: * Prior experience as an ISSO, ISSM or related DoD Cyber Workforce Role * Possess a valid certification that meets or exceeds DoD 8570.01-M IAM II requirements. (e.g., CASP+ CE, CISM, CISSP (or Assc), GSLC, CCISO, HCISPP * Prior RMF (Risk Management Framework) experience. * Proven knowledge of DCSA Assessment and Authorization Process Manual (DAAPM), Joint Special Access Program Implementation Guide (JSIG), or Risk Management Framework (RMF) as a Subject Matter Expert (SME) * Excellent written and verbal communication skills and ability to effectively interface with numerous cognizant security agencies, customers and senior leadership * Knowledge of other security disciplines and how they impact and interact with information system security Security Clearance Statement: This position requires a government security clearance, you must be a US Citizen for consideration. ## Description At Qnity , we're more than a global leader in materials and solutions for advanced electronics and high-tech industries - we're a tight-knit team that is motivated by new possibilities, and always up for a challenge. All our dedicated teams contribute to making cutting-edge technology possible. We value forward-thinking challengers, boundary-pushers, and diverse perspectives across all our departments, because we know we play a critical role in the world enabling faster progress for all. Learn how you can start or jumpstart your career with us. This Information System Security Site Lead position is responsible for all cybersecurity efforts at the Carlsbad, CA facility supporting development, maintenance, and oversight of the assigned classified and/or unclassified systems. Typical responsibilities of the role may include but are not limited to: * Developing and maintaining the site's cybersecurity program for assigned systems. * Ensuring all applicable cybersecurity policy, plans and procedures are followed. * Ensuring required cybersecurity controls are implemented and validated, to include continuous monitoring actions for assigned systems. * Developing and maintaining cybersecurity related plans, procedures and guidance. * Maintaining DOD Emass account as the Responsible Officer; to include performing custodian duties. * Monitoring and recognizing non-compliance, suspicious and anomalous activity (i.e., threats), and effectively reporting such activity and associated risks to the appropriate parties. * Ensuring plans of actions and milestones or remediation plans are in place for vulnerabilities identified during monitoring activity, audits, inspections, etc. and implementing, or overseeing, required corrective actions. * Conducting role-based cybersecurity training for assigned users. * Creating, collecting and retaining data to meet reporting requirements. * Monitoring and correlating data (e.g., logs, events, activity, etc.) from a variety of sources (e.g. Nessus Pro, Windows Event logs.) to identify and mitigate threats, vulnerabilities and non-compliance. * Investigating, analyzing and responding to cyber events, incidents and non-compliance, to include trend analysis, assembling detailed written reports and briefing the appropriate parties. * Identifying, implementing, and enforcing overall security requirements for the proper handling and storage of Government data and electronic media. * Conducting self-inspections and preparing for customer inspections. * Communicating and interacting professionally during the enforcement of security policy and procedures. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Is your backend a hodgepodge of queues, event stores and cron jobs? Durable Execution to the Rescue.](https://www.wearedevelopers.com/videos/744-is-your-backend-a-hodgepodge-of-queues-event-stores-and-cron-jobs-durable-execution-to-the-rescue) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Kafka Streams Microservices](https://www.wearedevelopers.com/videos/168-kafka-streams-microservices) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)