Padmi
E-Space logo
E-Space

LEO satellite constellation · Internet of Things (IoT)

Information Systems Security Manager (ISSM)

United States · OnsitePosted 2 months ago
SecurityStaff+Full Time
Apply at E-Space

Opens the source posting on jobs.lever.co

Source description

About the role

View original

System Authorization & Accreditation (A&A / RMF)

• Lead the Assessment and Authorization (A&A) process for all classified IS under the Risk Management Framework (RMF) in accordance with NIST SP 800-37 and DAAPM.

• Prepare, maintain, and submit System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Authorization to Operate (ATO) packages.

• Serve as the primary liaison with DCSA and Government customer representatives during system assessments, inspections, and audits.

• Maintain and manage the System Security Authorization Agreement (SSAA) or equivalent documentation for all IS operating at the TS level or above.

Compliance & Policy Management

• Ensure all classified information systems comply with 32 CFR Part 117 (NISPOM), applicable DoD and IC cybersecurity policies, Contract Data Requirements List (CDRLs), and Statement of Work (SOW) security requirements.

• Develop, implement, and maintain facility-level Information Systems Security policies, procedures, and Standard Operating Procedures (SOPs).

• Enforce configuration management (CM) controls and ensure all hardware/software changes to classified IS are reviewed and approved prior to implementation.

• Conduct periodic self-inspections of classified IS programs and remediate findings in coordination with the FSO and program leadership.

Continuous Monitoring & Incident Response

• Implement and manage a Continuous Monitoring (ConMon) program for all authorized classified information systems.

• Monitor audit logs, SIEM alerts, and vulnerability scan results; investigate anomalies and potential insider threats.

• Serve as the Facility Incident Response Manager for classified information system security incidents; coordinate reporting to DCSA and GCAs within required timeframes.

• Conduct or oversee technical vulnerability assessments and penetration testing as required by the CSA or contract requirements.

Personnel Security & Training

• Oversee ISSM-delegated Information System Security Officer (ISSO) personnel; provide mentorship, task delegation, and performance oversight.

• Develop and deliver annual IS security awareness training and role-based training for users of classified information systems.

• Maintain personnel access records and access control lists (ACLs) for all classified IS; ensure need-to-know verification prior to system access grants.

• Coordinate with the FSO to ensure the integration of personnel security and information security requirements.

Physical & Technical Security Integration

• Coordinate with facilities and physical security teams to ensure IS are housed in appropriately accredited spaces (SCIFs, Closed Areas, SAPs) in accordance with ICD 705 and DCSA physical security standards.

• Manage and enforce media protection, sanitization, and destruction procedures for classified storage media in accordance with NSA/CSS EPL requirements.

• Oversee PKI, multi-factor authentication (MFA), and privileged access management (PAM) implementations across classified networks

More at E-Space

Related open roles

View all roles