Information Systems Security Manager (ISSM)

Cypress HCM

San Diego (CA)

On-site

USD 150,000 - 175,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cypress HCM in San Diego seeks an Information Systems Security Manager (ISSM) to lead our security program, aligning with NIST SP 800-171, DFARS, and government regulations. You will oversee CUI protection, risk assessments, and cross-functional security integration across product and vendor ecosystems.

The role requires strong regulatory expertise, CMMC/ISO 27001 readiness, and experience with classified information workflows. Travel up to 10% may be required; U.S. person clearance is a plus.

Qualifications

  • BS in Information Security, CS, Cybersecurity or related field.
  • 7+ years in information security management, with 3+ years in a leadership role.
  • Extensive knowledge of NIST SP 800-171, DFARS 252.204-7012, DISA-STIGS, ISO 27001 and CUI handling.
  • Experience crafting and deploying information security frameworks and achieving compliance.
  • Risk governance, threat assessments, and vulnerability oversight in classified environments.
  • Incident response planning and execution for classified information.

Responsibilities

  • Create and maintain information security frameworks aligned to NIST SP 800-171 and DFARS.
  • Lead efforts to secure CMMC and ISO 27001 certifications and audits.
  • Protect CUI and sensitive data assets across organization.
  • Oversee classification handling and compliance with gov't directives.
  • Conduct risk assessments and gap analyses for vulnerabilities.
  • Collaborate with IT, engineering and vendors to embed security across lifecycle.
  • Act as liaison with government agencies and customers on compliance.
  • Develop and manage incident response framework and investigations.
  • Deliver security training to staff on policies and best practices.
  • Monitor regulatory changes and adjust security posture accordingly.
  • Coordinate with DevSecOps on cATO workflows and secure architectures.

Skills

Security leadership
Regulatory compliance
Cross-functional collaboration
Communication skills

Education

Bachelor's degree in Information Security, Computer Science, Cybersecurity or related field

Job description

This is an exciting opportunity to join a fast-growing startup in the aerospace/defense industry as their Information Systems Security Manager (ISSM). This position will be at the forefront of developing, implementing, and upholding our company's digital security compliance strategy and information security, alignment with rigorous governmental standards and regulatory frameworks. Your expertise will be essential in safeguarding proprietary assets, orchestrating risk mitigation strategies, and verifying operational adherence to mandated cybersecurity maturity models and information governance protocols. Leveraging extensive knowledge in NIST, DFARS, ISO 27001, and classified information stewardship, you'll be instrumental in fortifying operational security and maintaining compliance with defense sector requirements.

Responsibilities
  • Create, execute, and update organizational information security frameworks, guidelines, and protocols to align with NIST SP 800-171, DFARS 252.204-7012, and additional applicable regulations.
  • Spearhead initiatives to secure and sustain CMMC and ISO 27001 certifications, including orchestrating assessment procedures and overseeing audits.
  • Supervise the safeguarding of Controlled Unclassified Information (CUI) and related sensitive data assets.
  • Establish and monitor protocols for classified information handling, ensuring adherence to all relevant governmental regulations and directives.
  • Perform systematic risk evaluations and security gap analyses to detect and address potential vulnerabilities, particularly those affecting classified information systems.
  • Partner with cross-functional teams to embed security measures throughout operational domains, including product lifecycle and vendor relationship management.
  • Serve as the primary liaison with government agencies and customers regarding information security compliance and reporting.
  • Develop and oversee the incident response framework, directing investigations and corrective actions following security compromises involving classified or sensitive information.
  • Deliver training programs to enhance employee understanding of security policies, procedures, recommended practices, and classified information protocols.
  • Monitor changes in regulatory landscapes, security threats, and sector-specific best practices to enhance the organization's defensive posture.
  • Engage with DevSecOps specialists on the design, deployment, and support of continuous Authority to Operate (cATO) workflows.
  • Work alongside IT and engineering personnel to ensure robust system architectures and data protection mechanisms, with special focus on systems handling classified information.
Requirements And Desired Experience
  • BS in Information Security, Computer Science, Cybersecurity or similar related field
  • 7+ years of experience in information security management; 3 or more years in a leadership role
  • Extensive knowledge of NIST SP 800-171, DFARS 252.204-7012, DISA-STIGS, ISO 27001, CUI handling requirements, and classified information security protocols.
  • Demonstrated track record in crafting and deploying comprehensive information security frameworks and attaining regulatory compliance benchmarks.
  • Robust grasp of risk governance fundamentals and proven capability in executing threat assessments and vulnerability oversight, particularly within classified domains.
  • Experience with incident response planning and execution, particularly concerning classified information.
  • Working knowledge of data protection laws and regulations.
  • Superior interpersonal and communication capabilities, adept at translating intricate security protocols for diverse audiences spanning technical specialists and executive leadership.
  • Must be a U.S. Person due to the nature of work & required access to U.S. export-controlled information
  • Must be able to obtain and maintain a U.S. Government security clearance.
  • Must be willing to travel (up to 10%)
  • Relevant professional certifications (i.e.CISSP, CISM, CISA, Security+, ISP) or other DoD 8570 certifications in Information Assurance Management (Level III) is strongly preferred
  • Knowledge of cloud security principles and experience securing cloud environments handling classified or sensitive data.
  • Familiar with cybersecurity maturity models and CMMC a plus
  • Previous experience managing Facility Security Clearances (FCL) and handling classified information within a defense contractor environment is a plus
  • Experience with security audit processes and interfacing with regulatory auditors a plus
  • Experience with classified information systems a plus
  • Experience with Special Access Programs (SAP) and Sensitive Compartmented Information a plus
Compensation (DOE):

$150k - $175k annual base salary

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Manager
Information System Security Manager

ATR International • Palo Alto (CA)

On-site
USD 120,000 - 180,000
Information Systems Security Manager
Information Systems Security Manager

Modern Technology Solutions, Inc. (MTSI) • Patuxent Highland (MD)

On-site
USD 120,000 - 150,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Astrion • Columbia (MD)

On-site
USD 137,000 - 205,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Koitecc Solutions • Oklahoma City (OK)

On-site
USD 120,000 - 150,000
Facility Security Officer (FSO)
Facility Security Officer (FSO)

Cypress HCM • California (MO)

On-site
USD 150,000 - 175,000
Principal Information Security Engineer
Principal Information Security Engineer

Clarityinnovates • Fort Meade (MD)

On-site
USD 117,000 - 292,000
Information System Security Manager
Information System Security Manager

CACI International • Florham Park (NJ)

On-site
USD 104,000 - 218,000
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 170,000 - 195,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Information System Security Manager
Information System Security Manager

CACI International Inc • Florham Park (NJ)

On-site
USD 104,000 - 218,000
Information Systems Security Manager
Information Systems Security Manager

Modern Technology Solutions, Inc. • Dayton (OH)

On-site
USD 80,000 - 110,000
Limited travel required.