Information Systems Security Manager

Arenatechnologies

San Diego (CA)

On-site

USD 125,000 - 175,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Retirement savings plans
Flexible spending accounts

Job summary

Arenatechnologies is seeking an Information Systems Security Manager to oversee cybersecurity measures across multiple systems. This role requires expertise in Risk Management Framework and information security policies, ensuring compliance and protection of sensitive information.

The ideal candidate will have a bachelor’s degree in a related field, maintain a DoD IAM Level II certification, and have significant experience with federal agencies. The position is based in San Diego, California, with a competitive salary up to $175,000.

Qualifications

  • Bachelor’s degree in information security, IT, or equivalent experience with 5+ years professional experience.
  • Must maintain a DoD 8570.01-M IAM Level II certification.
  • 3+ years of experience with RMF artifacts and system ATOs.

Responsibilities

  • Develop and maintain RMF information security policies and procedures.
  • Oversee information security programs for classified systems.
  • Maintain compliance for accredited information systems.

Skills

Risk Management Framework (RMF)
Information Assurance Workforce IAM Level II
Continuous Monitoring
Experience with federal/government agencies
Active Secret security clearance

Education

Bachelor’s degree in information security or related discipline

Tools

Information technology equipment

Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the U.S. and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear‑sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

The Cybersecurity Pillar under SPA’s CIO establishes and maintains a robust cybersecurity posture and policy architecture across SPA's information systems. The team manages cyber policy, develops control implementations and system security plans, continuously monitors SPA systems, and performs routine cyber operations including patching, auditing, and incident response. Cybersecurity is critical to SPA's mission; therefore we strive to offer secure solutions that ensure data is protected while meeting the needs of the business.

In this role, you will serve as the Information Systems Security Manager (ISSM) for multiple systems operating under SPA's Operations Research and Cyber Analysis (C5ISR/ORCA) Group. This requires the individual to operate with autonomy while interfacing directly with SPA clients and leaders overseeing the business unit's operation.

This position will develop information system solutions following Risk Management Framework (RMF) with implementations following the DAAG/DAAPM and CMMC. The ISSM will be responsible for attaining and maintaining system assessments and authorizations through government authorizing agencies from requirements through operational deployment. ISSM will implement requirements to establish classified communication links including internet, phone, video teleconferencing and other vital communications channels. The successful candidate will coordinate requirements with DoD agencies to ensure mission accomplishment and the protection of sensitive information.

Responsibilities
  • Develop and maintain enterprise-wide RMF information security policies, standards, guidelines, procedures, and artifacts following the RMF framework.
  • Oversees the development and deployment of the information security program for multiple classified systems to meet business and enterprise requirements, policies, standards, guidelines, and procedures Prepares, reviews, and presents technical reports and briefings.
  • Create and Maintain the System Security Plans (SSP) and associated documentation.
  • Create a book of business for Cybersecurity Team.
  • Maintain compliance of accredited information systems based on federal and DoD security standards.
  • Manages and performs security compliance via continuous monitoring.
  • Identifies root causes, prioritizes threats and recommends and/or implements corrective actions.
  • Research and address information security issues as required as an authority on the subject.
  • Ensure systems are operated, maintained, and disposed of in accordance with internal and DCSA security policies and practices.
  • Participate in internal and external security audits and inspections; performs risk assessments.
  • Evaluate proposed changes or additions to the information system and assess their security relevance.
  • Ensure configuration management (CM) for security relevant IS software, hardware, and firmware is maintained and documented.
  • Conduct investigations of computer security violations and incidents, reporting as necessary.
  • Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered.
  • Communicate, implement and manage a formal Information Security / Information Systems Security Program together with CISO, CIO, and ISO.
  • Receive and respond to incoming calls and/or e-mails regarding end-user or system problems.
  • Interface with third‑party support and equipment vendors as needed.

Some travel may be required.

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities.

SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and several programs that provide for both paid and unpaid time away from work.

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc.

Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. California Pay Transparency Range: $125,000-$175,000

Qualifications
  • Bachelor’s degree in information security, Information Technology, or related discipline, or equivalent experience/combined education, with 5+ years of professional experience.
  • Must have and maintain a DoD 8570.01‑M (Information Assurance Workforce) IAM Level II certification (e.g. CAP, CISM, or CISSP).
  • A minimum of 3 years of direct experience with RMF artifacts, obtaining and maintaining system ATOs, and implementing new and complex technologies at multiple classification levels within large enterprise environments.
  • A minimum of 3 years of direct experience performing a continuous monitoring and the cybersecurity hygiene of windows domains and network enclaves.
  • A minimum of 5 years of direct experience working with federal/government agencies in sensitive and classified environments.
  • A minimum of 3 years of direct experience with Risk Management Framework (RMF), NIST 800-53, DAAG/DAAPM, and other legal and regulatory guidance.
  • Active Secret security clearance.
Desired Skills
  • At least 3 years’ experience in the deployment, configuration, and troubleshooting of information technology equipment.
  • Ability to understand information systems equipment configurations (switches, routers, IDS, firewalls, servers, storage, etc.).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Manager
Information Systems Security Manager

Arenatechnologies • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Retirement plan
Paid time off
Information Systems Security Manager
Information Systems Security Manager

Systems Planning and Analysis, Inc. • Arlington (VA)

On-site
USD 130,000 - 170,000
Information Systems Security Manager
Information Systems Security Manager

Systems Planning & Analysis • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Flexible spending accounts
Health savings accounts
+3
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Systems Planning & Analysis • Lincoln (MA)

On-site
USD 180,000 - 215,000
Health insurance
Retirement plans
Paid time off
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Arenatechnologies • Lincoln (MA)

On-site
USD 180,000 - 215,000
Information Systems Security Engineer
Information Systems Security Engineer

Arenatechnologies • Colorado Springs (CO), Northern (KY)

Hybrid
USD 85,000 - 100,000
Health insurance
Retirement savings plans
Paid time off
Information Systems Security Officer
Information Systems Security Officer

Arenatechnologies • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Specialist
Information Systems Security Specialist

Arenatechnologies • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement plans
Health savings accounts
+2
Information Systems Security Engineer
Information Systems Security Engineer

Systems Planning & Analysis • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 170,000 - 195,000
Medical Insurance
Dental Insurance
Vision Insurance
+4