Information System Security Manager (ISSM)
Work Arrangement: Onsite / Situational Remote
Salary Range: $135,000–$160,000 annually
Security Clearance: Active Top Secret/SCI (TS/SCI) Required
Recruitment Partner Notice
This position is being recruited and advertised by The O'Neil Group Company, LLC on behalf of Catalyst Campus for Technology & Innovation (CCTI). Applications will be submitted through The O'Neil Group Company, LLC; however, the selected candidate will be employed directly by Catalyst Campus for Technology & Innovation (CCTI) and will work onsite at CCTI's Colorado Springs location.
About Catalyst Campus
Catalyst Campus for Technology & Innovation (CCTI) is strategically headquartered in Colorado Springs, home to five military installations and a robust ecosystem of aerospace and defense organizations, innovative startups, entrepreneurs, government partners, and academic institutions.
Through its collaborative campus environment, CCTI brings together industry, academia, government, and key partners to cultivate public-private partnerships and accelerate the delivery of novel and disruptive aerospace and defense technologies supporting our nation and allied warfighters.
Position Summary
CCTI is seeking an experienced Information System Security Manager (ISSM) to lead cybersecurity accreditation, compliance, continuous monitoring, and operational security activities for classified information systems and supporting infrastructure.
Serving as the primary cybersecurity lead for CCTI's classified environments, the ISSM will work closely with Government security representatives, technical teams, and organizational leadership to ensure information systems remain secure, compliant, accredited, and operational throughout their lifecycle.
The ISSM will lead activities required to obtain, maintain, and sustain Authorities to Operate (ATOs) and support implementation of the Risk Management Framework (RMF) in accordance with applicable Intelligence Community (IC), Department of Defense (DoD), NIST, CNSSI, and Government cybersecurity requirements.
This position serves as a key point of contact for cybersecurity accreditation and compliance activities and will coordinate with Government security personnel, Accrediting Officials (AOs), Information System Owners (ISOs), System Security Officers (SSOs), technical teams, and operational stakeholders.
What You'll Do
Security Accreditation & Risk Management
- Lead cybersecurity accreditation activities required to obtain, maintain, and sustain ATOs for classified information systems and supporting infrastructure.
- Execute RMF activities throughout the system lifecycle in accordance with NIST SP 800-53 and applicable Government cybersecurity requirements.
- Develop, maintain, and manage authorization packages and accreditation artifacts, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Security Control Traceability Matrices (SCTMs)
- Plans of Action and Milestones (POA&Ms)
- Supporting accreditation evidence
- Coordinate with Government security representatives and accrediting authorities throughout authorization and sustainment activities.
Security Compliance & Continuous Monitoring
- Manage continuous monitoring activities to maintain cybersecurity, configuration management, and accreditation compliance.
- Track, assess, and coordinate remediation of vulnerabilities identified through security scans, assessments, audits, and compliance reviews.
- Maintain documentation and supporting evidence for ongoing accreditation, compliance reporting, and Government inspections.
- Coordinate cybersecurity incident reporting, response activities, and corrective actions affecting accredited systems.
Classified Systems Security Operations
- Support the secure operation of classified information systems and associated infrastructure within approved classified environments.
- Provide guidance regarding cybersecurity requirements, security controls, system changes, and compliance obligations.
- Support development and maintenance of cybersecurity architecture documentation, network diagrams, data-flow diagrams, and related system-security artifacts.
Stakeholder Engagement & Program Support
- Serve as a primary cybersecurity point of contact for Government security representatives, program leadership, system administrators, and operational users.
- Coordinate cybersecurity activities with Government SSOs, SSRs, AOs, CSAs, Information System Owners, and technical teams.
- Conduct security briefings, cybersecurity awareness activities, compliance communications, and user education as required.
- Provide cybersecurity recommendations and risk-based guidance to leadership, technical teams, and other stakeholders.
Required Qualifications
- Active Top Secret/SCI (TS/SCI) security clearance.
- 5+ years of combined experience in an Information System Security Officer (ISSO) and/or Information System Security Manager (ISSM) role.
- Experience supporting classified information systems within Department of Defense (DoD), Intelligence Community (IC), or other U.S. Government environments.
- Experience performing Risk Management Framework (RMF) and Authority to Operate (ATO) activities.
- Experience supporting continuous monitoring, vulnerability management, and cybersecurity compliance activities.
- Experience developing and maintaining accreditation artifacts, security documentation, and authorization packages.
- Experience supporting SCIF operations, accreditation, sustainment, classified environments, or information systems operating at multiple classification levels.
- Experience coordinating with Government security stakeholders, accrediting authorities, system administrators, and program personnel.
- Working knowledge of NIST, ICD 503, CNSSI guidance, and applicable DoD and Intelligence Community cybersecurity requirements.
- Familiarity with cybersecurity, vulnerability management, and compliance tools such as eMASS, XACTA, ACAS/Nessus, or similar platforms.
- Due to U.S. Government security clearance and classified-access requirements associated with this position, U.S. citizenship is required.
Preferred Qualifications
- Experience supporting U.S. Space Force programs or classified environments at Peterson Space Force Base or Schriever Space Force Base.
- Advanced cybersecurity certification such as CISSP or equivalent.
- Experience supporting government, defense, aerospace, cybersecurity, or innovation-focused programs.
Education
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related field preferred. Work experience may substitute for education requirement.
The following routes are available to substitute for the bachelor's degree and five (5) years:
- High School diploma or GED and nine (9) years of related experience.
- Associate's degree in Business or a related field and seven (7) years of related experience.
The individual may also substitute up for experience using the following routes:
- Master's degree in Business or a related field and three (3) years of related experience.
- Doctorate in Business or a related field and one (1) year of related experience.
Knowledge, Skills & Abilities
- Thorough understanding of RMF, accreditation, and compliance requirements applicable to classified information systems.
- Ability to comply with Government and customer security requirements.
- High degree of integrity, discretion, and professionalism when handling sensitive, proprietary, or classified information.
- Strong written and verbal communication skills, including the ability to explain cybersecurity requirements, risks, and compliance obligations to both technical and non-technical audiences.
- Ability to build effective working relationships with Government security representatives, contractors, industry partners, tenants, and internal stakeholders.
- Ability to conduct security briefings, awareness training, compliance communications, and user education activities.
- Strong organizational, documentation, and recordkeeping skills with exceptional attention to detail.
- Ability to manage multiple priorities and adapt to changing mission, operational, and compliance requirements.
- Customer-focused and collaborative approach to supporting mission partners, Government customers, and internal teams.
Work Environment & Physical Requirements
- Primarily onsite within a SCIF/classified environment in Colorado Springs, Colorado.
- Situational remote work may be available based on operational and security requirements.
- Work environment is typically quiet.
- Ability to occasionally lift and/or move up to 30 pounds.
- Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.
The anticipated salary range for this position is $135,000–$160,000 annually, depending on qualifications, experience, skills, and other job-related factors.
CCTI offers eligible employees a benefits package that includes:
Catalyst Campus for Technology & Innovation (CCTI) is an Equal Opportunity Employer. Employment decisions are made based on business needs, job requirements, and individual qualifications without regard to race, color, religion, creed, sex, pregnancy, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital status, military or veteran status, or any other status protected by applicable federal, state, or local law.
CCTI is committed to fostering an equitable and inclusive workplace and encourages qualified individuals from all backgrounds to apply.