> Markdown version of [/jobs/ext/2189309-national-industrial-security-program-lead-manager](https://www.wearedevelopers.com/jobs/ext/2189309-national-industrial-security-program-lead-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # National Industrial Security Program Lead/Manager - **Company:** ASTRION, INC. - **Location:** Columbia, MD, United States - **Experience:** Expert - **Salary:** $94,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Information Systems, Information Security Management, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3362642708&tx=JT10395UTD&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree with 8-10 years of experience. * Must understand and implement 32 CFR Part 117 (NISPOM) and applicable DCSA requirements. * Completion of FSO Program Management for Possessing Facilities * Experience in supporting U.S. Government clients. * Experience with Security Business Integrated Management Systems (i.e., Sign-In-Compliance, Sign-In Enterprise, SIMS, etc.) * U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility., * Proficiency with DISS, NBIS, NISS, and related personnel/industrial security systems. * Proficiency with DD Form 254 requirements and classified contracts/subcontracts. * Knowledge of classified information handling, safeguarding, storage, transmission, destruction, and incident reporting requirements. * Vulnerability assessment and remediation. * Strong written and verbal communication skills, including the ability to train employees and advise program leadership. * Excellent organization, attention to detail, discretion, and records-management skills. * Prior experience as an FSO, AFSO, CPSO, security specialist, or industrial security professional in the defense/aerospace/government-contracting environment. * Professional certifications such as ISP (Industrial Security Professional) or relevant CDSE training/certifications are a plus. ## Description * NISP Compliance & Program Management: - Oversee the day-to-day administration of the facility's industrial security program; interpret and implement 32 CFR Part 117, contract security requirements, DCSA guidance, and applicable government security policies and guidelines. * Classified Information Protection: Establish and oversee controls for receipt, generation, access, handling, reproduction, transmission, storage, and disposition of classified information; this includes safeguarding areas, approved storage, combinations/credentials, and physical security controls * Personnel Security: Ensure personnel have appropriate eligibility, access authorization, need-to-know, briefings, and debriefings to support the facility operations. * Continuous Monitoring and Improvement Assess security risks, identify trends, recommend improvements to senior management, and ensure adequate security resources are available to meet the complexity and classified workload of the facility. * Security Education & Training: Ensure personnel understand their responsibilities for safeguarding classified information and receive required initial, recurring/refresher, and termination/debriefing security training. * Insider Threat: Coordinate with the Insider Threat Program Senior Official (ITPSO) and ensure security-program information relevant to insider threat is identified, reported, and integrated into the insider-threat program. * Self-Inspections & Corrective Actions: Conduct or coordinate required self-inspections, identify vulnerabilities and deficiencies, develop corrective actions, brief management, and maintain supporting records. * DCSA Interface: Serve as a principal facility contact for the servicing DCSA Industrial Security Representative, support DCSA security reviews/assessments, respond to findings, and maintain required records/documentation. DCSA notes that routine ISR engagement normally flows through the FSO. * Security Procedures: Develop and maintain local Standard Practice Procedures (SPPs), SOPs, plans, and processes appropriate to the facility's classified operations. * Information Systems Collaboration and Coordination Coordinate with the Information System Security and Information Technology teams. * Provide Security input for Security Plans, POA&Ms, and Configuration Management Plans. * Security Incidents: Conduct inquires to actual or suspected loss, compromise, unauthorized disclosure, security violations, and other incidents; preserve relevant information, conduct required inquiries, report through appropriate channels, and implement corrective actions. * Technical Advising - Advise program managers, system owners, and administrators on security implications of risk decisions. * Security Reporting: Ensure proper reporting of adverse information, suspicious contacts, security incidents, foreign contacts/travel and other insider-threat indicators. ## Related Videos - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)