Information Systems Security Manager

your Jared

Northern (KY)

Hybrid

USD 110,000 - 165,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

BNS is seeking an Information Systems Security Manager to serve as the technical lead for securing and maintaining information systems handling FCI and CUI. You will drive the implementation of safeguards to achieve CMMC Level 2 and compliance with NIST SP 800-171 and DFARS.

You will lead IT operations, security controls, vendor coordination, and audit readiness across a dispersed workforce, balancing strategic planning with hands-on technical work.

Qualifications

  • 5+ years of progressive IT experience with cybersecurity focus.
  • Experience supervising IT or security teams is required.
  • Ability to communicate technical concepts to both technical and non-technical staff.

Responsibilities

  • Oversee IT operations across offices, field personnel, and remote workers.
  • Lead cybersecurity policy implementation and technical controls for CMMC/NIST SP 800-171.
  • Coordinate assessments, remediation, and continuous monitoring activities.
  • Manage vendor relationships and evaluate security solutions for risk and compliance.
  • Develop SSP/POA&Ms and support audit readiness.

Skills

Microsoft 365
Windows environments
Active Directory/Entra ID
Networking fundamentals
Endpoint protection
Vulnerability management
Security incident response

Tools

SIEM
EDR
MFA
Cloud platforms

Job description

Department: Information Technology
Location: Remote / Hybrid (U.S.)
Reports To: Chief Operating Officer
Job Type: Full-Time, Exempt

Position Summary

The Information Systems Security Manager will serve as BNS's technical lead for establishing, securing, documenting, and maintaining the information systems used to process, store, or transmit Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The position will lead implementation and continuous operation of the technical safeguards necessary for BNS to achieve and maintain its required CMMC status and comply with NIST SP 800-171 and applicable DFARS cybersecurity requirements.

The Information Systems Security Manager will lead and support the systems, networks, hardware, software, user accounts, devices, security controls, and technology processes that enable BNS employees and field teams to perform their work effectively.

This position will also play an important role in supporting the company's cybersecurity and compliance efforts, including leading the planning, implementation, documentation, assessment readiness, remediation, and continuous monitoring activities necessary for BNS to achieve and maintain its required CMMC Level 2 status.

The successful candidate will be comfortable moving between strategic thinking and hands-on problem solving. That could mean troubleshooting a user’s computer, managing Microsoft 365, addressing a network issue, coordinating with an outside vendor, improving cybersecurity controls, or helping prepare the organization for an audit.

Key Responsibilities
IT Operations & Infrastructure
  • Oversee day-to-day IT operations across BNS offices, field personnel, and remote employees.
  • Manage and maintain company networks, servers, workstations, laptops, mobile devices, printers, peripherals, and other technology assets.
  • Support Microsoft 365, cloud applications, user accounts, email, collaboration tools, and other business-critical applications.
  • Manage user onboarding, offboarding, access changes, equipment deployment, and technology provisioning.
  • Monitor system performance, availability, backups, security alerts, and other key IT functions.
  • Troubleshoot hardware, software, networking, connectivity, and access issues.
  • Maintain accurate IT asset inventories and technology documentation.
  • Coordinate technology deployments, upgrades, migrations, and lifecycle replacements.
  • Establish and maintain appropriate backup, recovery, and business continuity practices.
Cybersecurity & Compliance
  • Help develop, implement, and maintain BNS cybersecurity policies, procedures, and technical controls.
  • Support the organization’s cybersecurity risk management program.
  • Define, document, and maintain the CMMC assessment scope, including CUI data flows, system boundaries, network diagrams, asset inventories, external service providers, security-protection assets, and specialized assets.
  • Establish and administer a secure CUI environment or enclave, including approved methods for receiving, processing, storing, transmitting, sharing, printing, and destroying CUI.
  • Develop and maintain the System Security Plan, supporting policies and procedures, control implementation evidence, configuration baselines, and Plans of Action and Milestones.
  • Conduct or coordinate NIST SP 800-171 self-assessments, gap assessments, control testing, remediation, and assessment preparation.
  • Maintain evidence sufficient to demonstrate that each applicable security requirement is implemented and operating effectively, rather than only documented.
  • Coordinate with BNS leadership, legal/contracts personnel, managed service providers, cloud providers, Registered Practitioners, assessors, and C3PAOs.
  • Manage security configuration, multifactor authentication, privileged access, endpoint protection, encryption, vulnerability scanning, patching, logging, audit-log retention, backups, incident response, and security awareness training.
  • Evaluate IT and cloud vendors for CMMC, DFARS, data-residency, incident-reporting, and flow-down implications before introducing them into the CUI environment.
  • Establish continuous-monitoring metrics and report compliance status, deficiencies, risks, and corrective actions to executive management.
  • Support SPRS assessment submissions and annual affirmations while recognizing that formal affirmation is a senior-official responsibility.
  • Support access control, authentication, endpoint security, encryption, patching, vulnerability management, logging, and incident response processes.
  • Monitor and respond to security incidents and elevate significant issues appropriately.
  • Assist with security assessments, audits, documentation, evidence collection, and remediation activities.
  • Partner with leadership to identify technology and cybersecurity risks and recommend appropriate solutions.
  • Help ensure technology practices align with company policies, contractual requirements, and applicable regulatory or customer requirements.
IT Leadership & Team Supervision
  • Supervise and provide direction to IT personnel and/or IT support resources.
  • Establish priorities, assign work, and monitor completion of IT tasks and projects.
  • Develop consistent IT support processes and service expectations.
  • Coach and develop team members while maintaining accountability for performance.
  • Serve as the escalation point for complex technical and user issues.
  • Establish and maintain standards for troubleshooting, documentation, security, and customer service.
Vendor & Technology Management
  • Manage relationships with IT vendors, service providers, software providers, telecommunications providers, and technology partners.
  • Evaluate technology solutions and make recommendations based on business requirements, security, scalability, and cost.
  • Assist with IT budgeting, purchasing, licensing, renewals, and technology forecasting.
  • Review vendor performance and ensure services meet BNS requirements.
  • Help negotiate technology-related services and support agreements as appropriate.
Business & Project Support
  • Partner with BNS leadership and department managers to understand technology needs and business priorities.
  • Support technology requirements associated with data center, network, field service, and critical infrastructure operations.
  • Assist project teams with technology planning and deployment when IT support is required.
  • Support remote and traveling employees with secure and reliable access to company systems.
  • Help establish technology standards that can scale with BNS’s continued growth.
  • Participate in company-wide technology initiatives and process improvement efforts.
Required Qualifications
  • 5+ years of progressive IT experience, with demonstrated responsibility for IT infrastructure, systems, networking, or cybersecurity.
  • Previous experience supervising an IT team, IT support function, or technical resources.
  • Strong working knowledge of:
    • Microsoft 365
    • Windows environments
    • Active Directory / Entra ID
    • Networking fundamentals, including TCP/IP, DNS, DHCP, VPN, and firewalls
    • Endpoint management and security
    • User and access management
    • Hardware and software deployment
    • Backup and recovery
    • Cloud-based applications and services
  • Strong troubleshooting and problem-solving skills.
  • Ability to communicate technical concepts clearly to both technical and non-technical employees.
  • Ability to prioritize multiple competing IT needs in a fast-paced environment.
  • Experience managing vendors and outside technology providers.
  • Strong documentation and organizational skills.
  • Ability to maintain confidentiality and exercise sound judgment when handling sensitive information.
Preferred Qualifications & Experience
  • Experience establishing or administering an FCI/CUI environment.
  • Working knowledge of the NIST Cybersecurity Framework and demonstrated experience implementing the security requirements of NIST SP 800-171 Revision 2.
  • Experience developing and maintaining an SSP, POA&M, assessment scope, asset inventory, network diagrams, and objective evidence.
  • Experience preparing for or participating in a NIST SP 800-171 or CMMC assessment.
  • Working knowledge of DFARS 252.204-7012, -7019, -7020, and -7021.
  • Experience with Microsoft 365 GCC/GCC High or another appropriately configured government-contracting cloud environment.
  • Demonstrated administration of MFA, least privilege, privileged accounts, EDR, SIEM/logging, vulnerability management, encryption, mobile-device management, and secure remote access.
  • Experience supporting government contractors, defense contractors, or other regulated environments.
  • Experience with endpoint detection and response (EDR), SIEM, vulnerability management, or security monitoring tools.
  • Experience with Microsoft Intune, Defender, Entra ID, or related Microsoft security technologies.
  • Experience with network security, firewalls, VLANs, VPNs, and wireless infrastructure.
  • Experience supporting geographically dispersed employees and field personnel.
  • Experience in telecommunications, data centers, critical infrastructure, construction technology, engineering, or other project-based environments.
  • Industry certifications such as CompTIA Security+, Network+, CySA+, Microsoft certifications, CISSP, CISM, or related credentials are a plus.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Manager
Information Systems Security Manager

Bold New Solutions - BNS Power • Sumter (SC)

Hybrid
USD 90,000 - 130,000
401(k)
Paid time off
Dental insurance
+2
Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
Cyber Security Specialist
Cyber Security Specialist

X-Bow Systems Inc. • Luling (TX)

On-site
USD 70,000 - 110,000
CMMC & NIST Cybersecurity Manager (Remote)
CMMC & NIST Cybersecurity Manager (Remote)

your Jared • Northern (KY)

Hybrid
USD 110,000 - 165,000
IT Manager
IT Manager

Blue Raven Solutions • City of Yonkers (NY)

On-site
USD 122,000 - 132,000
Cyber Security Manager
Cyber Security Manager

Point Blank Enterprises, Inc. • Pompano Beach (FL)

On-site
USD 100,000 - 130,000
Remote Information Security Manager — CMMC & Compliance
Remote Information Security Manager — CMMC & Compliance

Bold New Solutions - BNS Power • Sumter (SC)

Hybrid
USD 90,000 - 130,000
401(k)
Paid time off
Dental insurance
+2
Cybersecurity Administrator
Cybersecurity Administrator

QED Systems Inc • Virginia Beach (VA)

On-site
USD 55,000 - 76,000
Competitive benefits package
Employee Assistance Program
Information Systems Security Engineer - Entry to Mid Level (Maryland)
Information Systems Security Engineer - Entry to Mid Level (Maryland)

National Security Agency • Fort Meade (MD)

On-site
USD 87,000 - 153,000
Network Security Engineer
Network Security Engineer

Credence • McLean (VA)

Hybrid
USD 120,000 - 170,000