Information Systems Security Manager - JobID-0311

Innovative Defense Technologies
San Diego, CA, United States
3 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$135,000.0 - $231,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Cyber Security Data Transmissions Linux DevOps File Transfer Identity and Access Management Information Security Management Network Security Windows PowerShell Systems Development Life Cycle Ansible
+14 more
SAS (Software) Security Information and Event Management Software Deployment Software Engineering SC Clearance Kubernetes Infrastructure Automation Frameworks Information Technology National Industrial Security Program Operating Manual (NISPOM) Puppet Devsecops Docker Plan of Action and Milestones Vulnerability Analysis

Job description

  • Responsible for implementing and managing the IDT San Diego Classified Information Systems (IS) security program and policies and procedures.
  • Extensive knowledge of Risk Management Framework (RMF) as it relates the published DCSA Assessment and Authorization Guide (DAAG), 32 CFR Part 117, “National Industrial Security Program Operating Manual (NISPOM)”, and NIST 800-53 series compliance.
  • Generate and maintain authority to operate (ATO) for new and current classified information systems authorized under RMF.
  • Use eMASS to document and track the security authorization process and maintain the security plan and artifacts.
  • Maintain a working knowledge of system functions, security policies, technical security safeguards, and operational security measures.
  • Chair the Change Control Board and oversee change in the environment, including clearly articulating requirements for change.
  • Oversee and conduct Control Correlation Identifier (CCI) self-assessments and periodic testing to evaluate the security posture of the IS.
  • Responsible for leading the information security portion of government assessments, Government on-sites and the periodic self-inspections.
  • Work closely with other program managers and stakeholders to facilitate change control and continuous monitoring of the lab environment.
  • Support the Software Development Lifecycle (SDLC) and DevOps/DevSecOps processes and ensure security best practices are followed.
  • Implement and manage an effective IS security education, training, and awareness program.
  • Assist the FSO and the Insider Threat Program Senior Official (ITPSO) in ensuring that insider threat awareness is addressed in the classified computing environments.
  • Manage and engage with the maintenance and execution of the Information Security Continuous Monitoring (ISCM) plan.
  • Ensure weekly audit compliance (user activity monitoring, data transfer audit logs) and audit data is analyzed, stored, and protected in accordance with the required auditing frequency.
  • Ensure compliance of current Information Assurance (IA) policies, concepts, and measures when designing, procuring, adopting, and developing new IS.
  • Manage and approve data transfer and assured file transfer responsibilities in accordance with IDT Policy and Procedures; both within IDT lab environments and in nearby US Government facilities.
  • Develop, document, manage and approve monthly vulnerability scan results, quarterly Security Technical Implementation Guide (STIG) compliance and applicable Plan of Action and Milestones (POA&M) for each Classified IS enclave.
  • Possess personnel leadership and technical competence commensurate with the complexity of the IS.
  • Manage requests that involve co-utilizations and joint-use agreements of data residing on the IS and/or within the closed area labs.
  • Lead a team of Information System Security Officers (ISSOs) and Security Administrators (SAs) through the RMF process, providing tasking to ensure program requirements, deliverables and schedules are met.
  • Perform comprehensive investigations of security incidents and ensure proper measures are taken post discovery of the incident/event.
  • Responsible for the preparation and demonstration of compliant classified IS’s in advance of a DCSA assessments.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related field, or equivalent professional experience.
  • Minimum of 8 years of IT experience, including 5 years or more as an ISSM or equivalent role in a cleared DCSA Accredited facility.
  • Ability to travel up to 10% of the time as needed.
  • Excellent knowledge of the NISPOM and the DCSA DAAG and their requirements and procedures.
  • Proficient in Windows and Linux operating systems and their security configurations.
  • Proficient in eMASS, Tenable, NIST 800-53 Controls, RMF, SIEM tools, ePO, and network security tools and techniques.
  • Familiar with the SDLC and DevOps/DevSecOps methodologies and their security implications. Active Secret clearance or higher.
  • Information Assurance Management (IAM) Level 3 certification in accordance with DODI 8140/8570 requirements, such as CISSP, CISM, or GSLC.
  • Strong analytical, troubleshooting, and communication skills with the ability to coordinate effectively across engineering, cybersecurity, and operational teams.

What Makes You Stand Out:

  • Self-motivated professional with the ability to independently manage multiple priorities, systems, and technical efforts simultaneously in fast-paced or mission-critical environments with minimal supervision.
  • Technical experience administering and securing containerized environments using Docker, Kubernetes, or similar container orchestration platforms.
  • Experience with infrastructure automation and configuration management tools such as Ansible, PowerShell, Chef, Salt, Puppet, or similar technologies.
  • Familiarity with software deployment and systems management tools such as PDQ Deploy or equivalent solutions.
  • Strong verbal and written communication skills with the ability to collaborate across engineering, cybersecurity, and operational teams.

Benefits & conditions

Pay Range*: $135,000 - $231,000

*Pursuant to California Senate Bill 1162 , IDT is required to disclose the “pay scale” or “pay range” associated with a job posting. Notably, however, this amount may not be reflective of actual compensation that may be earned as pay is dependent on a candidate’s experience, skills, and education. The posted range does not include bonuses, commissions, tips, or other benefits. Click here for additional information about Senate Bill 1162. IDT is often looking to place multiple candidates at various levels. Therefore, more than one pay range has been included, commensurate with experience.

Why Work at Innovative Defense Technologies (IDT):

Why Work at Innovative Defense Technologies (IDT):

IDT is a growing company with a vibrant, entrepreneurial culture. We are headquartered in Arlington, VA with additional offices in Fall River, MA; Mount Laurel, NJ; and San Diego, CA. At each location, our employees work together in a modern, snack-filled, and social office space, designing innovative solutions for our defense industry customers. We offer employees competitive pay and benefits including:

  • Generous benefits package
  • Competitive PTO
  • Paid holidays
  • 401(k) with immediate vesting and matching
  • 9/80 optional schedule (2nd and 4th Friday off every month)
  • Tuition Assistance Reimbursement Program
  • Professional Development Resources
  • Pre-Tax Commuter Benefits
  • Organization-Wide Monthly Tech Connect Events
  • Annual Employee Recognition Awards
  • Regular Social Events and Catered Lunches

About the company

Innovative Defense Technologies (IDT), a leading defense technology company, is seeking an Information System Security Manager (ISSM) to support its San Diego, CA office.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:22 min

Analyzing differences between mobile and traditional backend DevOps

Mete Baydar Mete Baydar · World Congress 2025

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all