IT and Security Manager

brightline

Ashburn (VA)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Brightline is seeking a hands-on IT and Security Manager to lead the CMMC certification program and own on-site IT operations. You will administer Microsoft 365, secure enclaves and endpoints, run SIEM/vulnerability workflows, and guide audit readiness with minimal production disruption.

Reporting to the COO, you’ll collaborate with engineering, operations, and leadership to implement controls, manage documentation, and ensure evidence pipelines meet compliance standards.

Qualifications

  • 5+ years in IT operations, security in regulated environments.
  • Leadership in CMMC/NIST gap analysis, remediation, evidence.
  • M365 administration and endpoint management experience.
  • Strong SIEM, vulnerability management and incident response.
  • Scripting/automation with PowerShell, Bash, or Python.

Responsibilities

  • Lead CMMC program end-to-end from gap analysis to evidence library.
  • Own IT operations, security governance, and compliance efforts.
  • Manage on-site IT services, asset lifecycle, and change control.
  • Oversee security engineering, SIEM, vulnerability management, and incidents.
  • Coordinate audits, assessments, and vendor risk for CUI handling.

Skills

IT operations
Security management
CMMC/NIST leadership
M365 administration
SIEM/vulnerability
Scripting/automation
Communication & leadership
US Citizenship

Education

Bachelor’s degree in CS/IT/Cybersecurity or equivalent experience

Tools

Entra ID/SSO
Intune
Exchange
SharePoint/OneDrive
Nessus

Job description

IT and Security Manager (On-Site)

Overview

We’re hiring a hands‑on IT & Security Manager to lead our company through the CMMC certification process—from gap assessment and remediation planning to control implementation, evidence collection, and assessment readiness—while owning on‑site IT operations, security governance, and compliance. You’ll administer Microsoft 365 and core IT platforms, secure our enclaves and endpoints, run SIEM/vulnerability/IR workflows, and lead audits (CMMC, NIST, FedRAMP alignment). You’ll report to the COO, collaborate closely with engineering, operations, and leadership, and ensure controls are effective without disrupting production.

Key Responsibilities
CMMC Program Leadership
  • Own CMMC end‑to‑end: Gap analysis → remediation roadmap → control implementation (SSP/POA&M) → objective evidence library → assessment readiness.
  • Assessment readiness: Coordinate internal audits, stakeholder drills, assessor engagement, and track findings to closure.
  • Vendor due diligence and contract clauses for CUI handling.
IT Operations (ITSM) & Asset Lifecycle
  • Service reliability: Own M365 tenant administration (Entra ID/SSO, Intune, Exchange, SharePoint/OneDrive), core IT services, and helpdesk workflows.
  • Asset management: Provisioning, inventory, and lifecycle for laptops, peripherals, and enclave hardware; maintain CMDB accuracy.
  • On/Offboarding: Role‑based access, least‑privilege, and auditable user transitions.
  • Change management: Define CAB/approvals, back‑out plans, and maintenance windows with minimal disruption.
Security Engineering & SecOps
  • Controls & hardening: Enclaves, endpoints, VMs/containers (policy baselines, MFA, encryption in transit/at rest).
  • SIEM & monitoring: Manage detections, triage alerts, and lead incident response/post‑mortems.
  • Vulnerability management: Scans (e.g., Nessus), risk‑based prioritization, remediation SLAs, and verification.
  • Network & endpoint security: Firewalls, VPNs (WireGuard/OpenVPN/IPsec), IDS/IPS, EDR, device posture.
  • Automation: PowerShell, Bash, and Python for baselines, hardening, and evidence capture.
Security Evaluations (Software/Hardware)
  • Tool & hardware reviews: Perform security evaluations of software tools and hardware (pre‑procurement and periodic) to ensure compliance with CMMC/NIST controls and internal standards.
  • Standards & artifacts: Assess against benchmarks, DISA STIGs, vendor hardening guides; verify SBOMs, patch cadence, logging/telemetry, data residency, encryption, and identity integrations (SSO/MFA/SCIM).
  • 3rd‑party risk: Run security questionnaires, review pen‑test/SOC 2/FedRAMP reports, and document compensating controls and residual risk.
Compliance, Audit & Risk
  • Framework ownership: CMMC, NIST 800‑171/53, CSF; support FedRAMP alignment where applicable.
  • Documentation: Maintain SSP, POA&M, policies/standards, diagrams, data flows, and objective evidence mapped to practices.
  • Assessments & audits: Internal audits, vendor risk reviews, external assessor support.
  • Training & awareness: Security and CUI handling enablement across teams.
On‑Site Responsibilities
  • Hands‑on enclave access/process support, break/fix triage, and lab/office network hygiene.
  • Vendor/tooling evaluation, renewals, and contracts that meet security/compliance needs.
Required Qualifications
  • 5+ years in IT operations/service management and security within regulated/public‑sector or similar environments.
  • CMMC/NIST 800‑171 leadership (gap analysis, remediation, evidence, assessor readiness).
  • M365 administration (Entra ID/SSO, Intune, Exchange, SharePoint/OneDrive) and endpoint management.
  • SecOps: SIEM, vulnerability management, incident response; strong network security fundamentals.
  • Scripting/automation: PowerShell, Bash, and/or Python.
  • Communication & leadership: Clear writing, stakeholder influence, cross‑team enablement.
  • Education: Bachelor’s in CS/IT/Cybersecurity or equivalent experience.
  • US Citizenship required.
Preferred Qualifications
  • CISSP, CISM, Security+, or audit certs (e.g., CISA).
  • Experience with container hardening and Terraform/Kubernetes governance (policy/admission controls)—advisory/controls focus.
  • Familiarity with FedRAMP, DoD IL4/IL5 expectations and evidence workflows.
  • Project management experience running multi‑team initiatives.
Nice to Have Qualifications
  • Exposure to spatial/immersive tech or game‑engine security.
  • Cloud or full‑stack development experience (for automation/internal tools).
  • Experience supporting public‑sector customers and responding to RFP/security questionnaires.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Compliance Engineer
Cyber Security Compliance Engineer

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Daniels Manufacturing Corporation • Orlando (FL)

On-site
USD 80,000 - 110,000
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist
Cybersecurity Compliance Engineer: NIST/CMMC 2.0 Specialist

Leonardo • Philadelphia

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Dmctools • Orlando (FL)

On-site
USD 80,000 - 120,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Senior Information Security Specialist
Senior Information Security Specialist

Insight Global • Horsham (PA)

On-site
USD 120,000 - 170,000
Senior IT Security Manager
Senior IT Security Manager

GoFormz • San Diego (CA)

On-site
USD 140,000 - 190,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Senior IT Security Manager I
Senior IT Security Manager I

GoFormz • San Diego (CA)

On-site
USD 150,000 - 190,000