Information System Security Manager

The O'Neil Group Company

Colorado Springs (CO)

Hybrid

USD 135,000 - 160,000

Full time

40 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
401(k)

Job summary

Catalyst Campus for Technology & Innovation (CCTI) in Colorado Springs is seeking an experienced Information System Security Manager (ISSM) to lead cybersecurity accreditation, compliance, continuous monitoring, and operations for classified information systems.

The ISSM will coordinate with Government security representatives, accrediting officials, ISOs, SSOs, and technical teams to ensure secure, compliant, and accredited systems throughout their lifecycle, with onsite work and situational

Qualifications

  • 5+ years of combined ISSO/ISSM experience required.
  • Experience with RMF and ATO activities in DoD/IC environments.
  • Familiarity with NIST, ICD 503, CNSSI guidance and related security requirements.

Responsibilities

  • Lead accreditation activities to obtain and sustain ATOs for classified systems.
  • Execute RMF lifecycle activities per NIST SP 800-53 and government requirements.
  • Develop and maintain SSPs, SARs, SCTMs, POA&Ms and supporting artifacts.
  • Coordinate with Government security personnel and accrediting authorities.
  • Support continuous monitoring, vulnerability management, and incident response.

Skills

RMF
ATO processes
Accreditation artifacts
Government security liaison
Cybersecurity governance

Education

Bachelor's degree in Cybersecurity, IT, or related field

Tools

eMASS
XACTA
ACAS/Nessus

Job description

Information System Security Manager (ISSM)

Work Arrangement: Onsite / Situational Remote

Salary Range: $135,000–$160,000 annually

Security Clearance: Active Top Secret/SCI (TS/SCI) Required

Recruitment Partner Notice

This position is being recruited and advertised by The O'Neil Group Company, LLC on behalf of Catalyst Campus for Technology & Innovation (CCTI). Applications will be submitted through The O'Neil Group Company, LLC; however, the selected candidate will be employed directly by Catalyst Campus for Technology & Innovation (CCTI) and will work onsite at CCTI's Colorado Springs location.

About Catalyst Campus

Catalyst Campus for Technology & Innovation (CCTI) is strategically headquartered in Colorado Springs, home to five military installations and a robust ecosystem of aerospace and defense organizations, innovative startups, entrepreneurs, government partners, and academic institutions.

Through its collaborative campus environment, CCTI brings together industry, academia, government, and key partners to cultivate public-private partnerships and accelerate the delivery of novel and disruptive aerospace and defense technologies supporting our nation and allied warfighters.

Position Summary

CCTI is seeking an experienced Information System Security Manager (ISSM) to lead cybersecurity accreditation, compliance, continuous monitoring, and operational security activities for classified information systems and supporting infrastructure.

Serving as the primary cybersecurity lead for CCTI's classified environments, the ISSM will work closely with Government security representatives, technical teams, and organizational leadership to ensure information systems remain secure, compliant, accredited, and operational throughout their lifecycle.

The ISSM will lead activities required to obtain, maintain, and sustain Authorities to Operate (ATOs) and support implementation of the Risk Management Framework (RMF) in accordance with applicable Intelligence Community (IC), Department of Defense (DoD), NIST, CNSSI, and Government cybersecurity requirements.

This position serves as a key point of contact for cybersecurity accreditation and compliance activities and will coordinate with Government security personnel, Accrediting Officials (AOs), Information System Owners (ISOs), System Security Officers (SSOs), technical teams, and operational stakeholders.

What You'll Do

Security Accreditation & Risk Management

  • Lead cybersecurity accreditation activities required to obtain, maintain, and sustain ATOs for classified information systems and supporting infrastructure.
  • Execute RMF activities throughout the system lifecycle in accordance with NIST SP 800-53 and applicable Government cybersecurity requirements.
  • Develop, maintain, and manage authorization packages and accreditation artifacts, including:
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Security Control Traceability Matrices (SCTMs)
  • Plans of Action and Milestones (POA&Ms)
  • Supporting accreditation evidence
  • Coordinate with Government security representatives and accrediting authorities throughout authorization and sustainment activities.

Security Compliance & Continuous Monitoring

  • Manage continuous monitoring activities to maintain cybersecurity, configuration management, and accreditation compliance.
  • Track, assess, and coordinate remediation of vulnerabilities identified through security scans, assessments, audits, and compliance reviews.
  • Maintain documentation and supporting evidence for ongoing accreditation, compliance reporting, and Government inspections.
  • Coordinate cybersecurity incident reporting, response activities, and corrective actions affecting accredited systems.

Classified Systems Security Operations

  • Support the secure operation of classified information systems and associated infrastructure within approved classified environments.
  • Provide guidance regarding cybersecurity requirements, security controls, system changes, and compliance obligations.
  • Support development and maintenance of cybersecurity architecture documentation, network diagrams, data-flow diagrams, and related system-security artifacts.

Stakeholder Engagement & Program Support

  • Serve as a primary cybersecurity point of contact for Government security representatives, program leadership, system administrators, and operational users.
  • Coordinate cybersecurity activities with Government SSOs, SSRs, AOs, CSAs, Information System Owners, and technical teams.
  • Conduct security briefings, cybersecurity awareness activities, compliance communications, and user education as required.
  • Provide cybersecurity recommendations and risk-based guidance to leadership, technical teams, and other stakeholders.

Required Qualifications

  • Active Top Secret/SCI (TS/SCI) security clearance.
  • 5+ years of combined experience in an Information System Security Officer (ISSO) and/or Information System Security Manager (ISSM) role.
  • Experience supporting classified information systems within Department of Defense (DoD), Intelligence Community (IC), or other U.S. Government environments.
  • Experience performing Risk Management Framework (RMF) and Authority to Operate (ATO) activities.
  • Experience supporting continuous monitoring, vulnerability management, and cybersecurity compliance activities.
  • Experience developing and maintaining accreditation artifacts, security documentation, and authorization packages.
  • Experience supporting SCIF operations, accreditation, sustainment, classified environments, or information systems operating at multiple classification levels.
  • Experience coordinating with Government security stakeholders, accrediting authorities, system administrators, and program personnel.
  • Working knowledge of NIST, ICD 503, CNSSI guidance, and applicable DoD and Intelligence Community cybersecurity requirements.
  • Familiarity with cybersecurity, vulnerability management, and compliance tools such as eMASS, XACTA, ACAS/Nessus, or similar platforms.
  • Due to U.S. Government security clearance and classified-access requirements associated with this position, U.S. citizenship is required.

Preferred Qualifications

  • Experience supporting U.S. Space Force programs or classified environments at Peterson Space Force Base or Schriever Space Force Base.
  • Advanced cybersecurity certification such as CISSP or equivalent.
  • Experience supporting government, defense, aerospace, cybersecurity, or innovation-focused programs.

Education

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related field preferred. Work experience may substitute for education requirement.

The following routes are available to substitute for the bachelor's degree and five (5) years:

  • High School diploma or GED and nine (9) years of related experience.
  • Associate's degree in Business or a related field and seven (7) years of related experience.

The individual may also substitute up for experience using the following routes:

  • Master's degree in Business or a related field and three (3) years of related experience.
  • Doctorate in Business or a related field and one (1) year of related experience.

Knowledge, Skills & Abilities

  • Thorough understanding of RMF, accreditation, and compliance requirements applicable to classified information systems.
  • Ability to comply with Government and customer security requirements.
  • High degree of integrity, discretion, and professionalism when handling sensitive, proprietary, or classified information.
  • Strong written and verbal communication skills, including the ability to explain cybersecurity requirements, risks, and compliance obligations to both technical and non-technical audiences.
  • Ability to build effective working relationships with Government security representatives, contractors, industry partners, tenants, and internal stakeholders.
  • Ability to conduct security briefings, awareness training, compliance communications, and user education activities.
  • Strong organizational, documentation, and recordkeeping skills with exceptional attention to detail.
  • Ability to manage multiple priorities and adapt to changing mission, operational, and compliance requirements.
  • Customer-focused and collaborative approach to supporting mission partners, Government customers, and internal teams.

Work Environment & Physical Requirements

  • Primarily onsite within a SCIF/classified environment in Colorado Springs, Colorado.
  • Situational remote work may be available based on operational and security requirements.
  • Work environment is typically quiet.
  • Ability to occasionally lift and/or move up to 30 pounds.
  • Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.

The anticipated salary range for this position is $135,000–$160,000 annually, depending on qualifications, experience, skills, and other job-related factors.

CCTI offers eligible employees a benefits package that includes:

  • Medical insurance
  • 401(k)

Catalyst Campus for Technology & Innovation (CCTI) is an Equal Opportunity Employer. Employment decisions are made based on business needs, job requirements, and individual qualifications without regard to race, color, religion, creed, sex, pregnancy, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital status, military or veteran status, or any other status protected by applicable federal, state, or local law.

CCTI is committed to fostering an equitable and inclusive workplace and encourages qualified individuals from all backgrounds to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Cypress HCM • San Diego (CA)

On-site
USD 150,000 - 175,000
Information System Security Manager
Information System Security Manager

CACI International Inc • Florham Park (NJ)

On-site
USD 104,000 - 218,000
Senior Information System Security Officer
Senior Information System Security Officer

CACI • Town of Springfield (WI)

On-site
USD 121,000 - 266,000
Information System Security Manager
Information System Security Manager

Amentum • Northern (KY)

Hybrid
USD 100,000 - 110,000
Health insurance
Paid time off
401(k) matching
+6
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Abacus Technology Corporation • Massachusetts

On-site
USD 176,000 - 195,000
Information Systems Security Manager
Information Systems Security Manager

Kranze Technology Solutions, Inc. • Des Plaines (IL)

On-site
USD 100,000 - 150,000
Paid Time Off
Health Care package
401(k) retirement plan
+2
Program Information Systems Security Manager (ISSM) - Tucson, AZ
Program Information Systems Security Manager (ISSM) - Tucson, AZ

Prattwhitney • Tucson (AZ)

On-site
USD 107,000 - 205,000
Medical insurance
401(k) match
Flexible work schedules
Information System Security Manager
Information System Security Manager

Amentum • Sumter (SC)

On-site
USD 100,000 - 110,000
Senior Information System Security Officer
Senior Information System Security Officer

CACI International Inc • Springfield (VA)

On-site
USD 121,000 - 266,000
Sr Information Systems Security Manager
Sr Information Systems Security Manager

Continental Electronics Corporation • Richardson (TX)

On-site
USD 145,000 - 155,000
401(k) plan
Health plans