IT and Security Manager

Brightline Interactive

Ashburn (VA)

On-site

USD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Brightline Interactive is seeking a hands-on IT & Security Manager to lead CMMC certification efforts and own on-site IT operations, security governance, and compliance. Responsibilities include administering Microsoft 365 and core IT platforms, securing enclaves and endpoints, running SIEM/vulnerability/IR workflows, and leading audits (CMMC, NIST, FedRAMP alignment).

You’ll report to the COO, collaborate with engineering, operations, and leadership, and ensure controls are effective without

Qualifications

  • 5+ years in IT operations and security in regulated or public-sector environments.
  • Leadership of CMMC/NIST 800-171 efforts including gap analysis and POA&M.
  • M365 administration and endpoint management (Entra ID/SSO, Intune, Exchange).
  • Strong SecOps foundations: SIEM, vulnerability mgmt, IR.
  • Clear communication and cross-team collaboration across engineering and operations.

Responsibilities

  • Lead CMMC end-to-end: gap analysis, remediation roadmap, controls implementation, evidence library.
  • Coordinate internal audits, drills, assessor engagement and findings closure.
  • Vendor due diligence and contract clauses for CUI handling.
  • Own ITSM operations and asset lifecycle including onboarding/offboarding and change management.
  • Perform security evaluations of tools/hardware to ensure compliance with controls.

Skills

IT Operations
Security Management
CMMC/NIST
M365 Administration
Scripting

Education

Bachelor's in CS/IT/Cybersecurity

Tools

Nessus
SIEM
Entra ID
PowerShell
Terraform

Job description

IT and Security Manager (On-Site)
Overview

We’re hiring a hands-on IT & Security Manager to lead our company through the CMMC certification process—from gap assessment and remediation planning to control implementation, evidence collection, and assessment readiness—while owning on-site IT operations, security governance, and compliance. You’ll administer Microsoft 365 and core IT platforms, secure our enclaves and endpoints, run SIEM/vulnerability/IR workflows, and lead audits (CMMC, NIST, FedRAMP alignment). You’ll report to the COO, collaborate closely with engineering, operations, and leadership, and ensure controls are effective without disrupting production.

Key Responsibilities
CMMC Program Leadership
  • Own CMMC end-to-end: Gap analysis → remediation roadmap → control implementation (SSP/POA&M) → objective evidence library → assessment readiness.
  • Assessment readiness: Coordinate internal audits, stakeholder drills, assessor engagement, and track findings to closure.
  • Vendor due diligence and contract clauses for CUI handling.
IT Operations (ITSM) & Asset Lifecycle
  • Service reliability: Own M365 tenant administration (Entra ID/SSO, Intune, Exchange, SharePoint/OneDrive), core IT services, and helpdesk workflows.
  • Asset management: Provisioning, inventory, and lifecycle for laptops, peripherals, and enclave hardware; maintain CMDB accuracy.
  • On/Offboarding: Role-based access, least-privilege, and auditable user transitions.
  • Change management: Define CAB/approvals, back-out plans, and maintenance windows with minimal disruption.
Security Engineering & SecOps
  • Controls & hardening: Enclaves, endpoints, VMs/containers (policy baselines, MFA, encryption in transit/at rest).
  • SIEM & monitoring: Manage detections, triage alerts, and lead incident response/post-mortems.
  • Vulnerability management: Scans (e.g., Nessus), risk-based prioritization, remediation SLAs, and verification.
  • Network & endpoint security: Firewalls, VPNs (WireGuard/OpenVPN/IPsec), IDS/IPS, EDR, device posture.
  • Automation: PowerShell, Bash, and Python for baselines, hardening, and evidence capture.
Security Evaluations (Software/Hardware)
  • Tool & hardware reviews: Perform security evaluations of software tools and hardware (pre-procurement and periodic) to ensure compliance with CMMC/NIST controls and internal standards.
  • Standards & artifacts: Assess against benchmarks, DISA STIGs, vendor hardening guides; verify SBOMs, patch cadence, logging/telemetry, data residency, encryption, and identity integrations (SSO/MFA/SCIM).
  • 3rd-party risk: Run security questionnaires, review pen-test/SOC 2/FedRAMP reports, and document compensating controls and residual risk.
Compliance, Audit & Risk
  • Framework ownership: CMMC, NIST 800-171/53, CSF; support FedRAMP alignment where applicable.
  • Documentation: Maintain SSP, POA&M, policies/standards, diagrams, data flows, and objective evidence mapped to practices.
  • Assessments & audits: Internal audits, vendor risk reviews, external assessor support.
  • Training & awareness: Security and CUI handling enablement across teams.
On-Site Responsibilities
  • Hands-on enclave access/process support, break/fix triage, and lab/office network hygiene.
  • Vendor/tooling evaluation, renewals, and contracts that meet security/compliance needs.
Required Qualifications
  • 5+ years in IT operations/service management and security within regulated/public-sector or similar environments.
  • CMMC/NIST 800-171 leadership (gap analysis, remediation, evidence, assessor readiness).
  • M365 administration (Entra ID/SSO, Intune, Exchange, SharePoint/OneDrive) and endpoint management.
  • SecOps: SIEM, vulnerability management, incident response; strong network security fundamentals.
  • Scripting/automation: PowerShell, Bash, and/or Python.
  • Communication & leadership: Clear writing, stakeholder influence, cross-team enablement.
  • Education: Bachelor’s in CS/IT/Cybersecurity or equivalent experience.
  • US Citizenship required.
Preferred Qualifications
  • CISSP, CISM, Security+, or audit certs (e.g., CISA).
  • Experience with container hardening and Terraform/Kubernetes governance (policy/admission controls)—advisory/controls focus.
  • Familiarity with FedRAMP, DoD IL4/IL5 expectations and evidence workflows.
  • Project management experience running multi-team initiatives.
Nice to Have Qualifications:
  • Exposure to spatial/immersive tech or game-engine security.
  • Cloud or full-stack development experience (for automation/internal tools).
  • Experience supporting public-sector customers and responding to RFP/security questionnaires.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Project Manager
Compliance Project Manager

M3 Technology Consultants • Fairfax (VA)

On-site
USD 80,000 - 115,000
Very competitive compensation package
Annual paid training for continuing.
Collaborative team environment
+4
Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 110,000 - 140,000
Information Security Program Lead
Information Security Program Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
IT Security and Systems Engineer
IT Security and Systems Engineer

SilencerCo, LLC • West Valley City (UT)

On-site
USD 120,000 - 180,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Cloud Security Architect (GCC High)
Cloud Security Architect (GCC High)

Two Five • Washington

On-site
USD 180,000 - 240,000
Implementation Specialist, CMMC
Implementation Specialist, CMMC

United States Digital Space LLC • United States

On-site
USD 85,000 - 120,000
Security Compliance Engineer with Security Clearance
Security Compliance Engineer with Security Clearance

NexTech Solutions LLC • Tampa (FL)

On-site
USD 110,000 - 160,000