The Senior Manager of Cybersecurity & IT Compliance at Clarity Innovations, LLC will lead cybersecurity governance, compliance, authorization, and risk management efforts across corporate and mission environments, with a focus on measurable operational outcomes in DoD/IC settings. This role reports to the Vice President of Information Technology and supports authorization, compliance maturity, and risk reduction activities.
Key Responsibilities
- Lead execution of compliance activities across CMMC, NIST 800-171, NIST 800-53, FISMA, RMF, and applicable IC requirements, including ICD and JSIG.
- Develop, maintain, and review SSPs, POA&M, Control Implementation Matrices, boundary documentation, ATO artifacts, and supporting evidence.
- Ensure cybersecurity documentation is current, accurate, audit-ready, and representative of the operating environment.
- Plan and coordinate vulnerability scans, compliance assessments, contingency plan testing, control assessments, and risk assessments.
- Support internal and external assessments, audits, certification activities, and government authorization efforts.
- Manage the POA&M lifecycle, including remediation tracking, risk prioritization, validation, evidence collection, and closure.
- Oversee vulnerability management across enterprise and mission information systems, including vulnerability review and prioritization based on technical severity, operational impact, mission requirements, and organizational risk.
- Coordinate vulnerability discovery using manual assessment and automated tools, including ACAS, Nessus, DISA SRR scripts, HBSS, and endpoint security platforms.
- Develop and track remediation activities aligned with DISA STIGs and applicable DoD security requirements.
- Maintain cybersecurity risk registers with clear owners, remediation plans, and status.
- Support third-party, vendor, software, and supply chain cybersecurity risk assessments.
- Maintain and execute incident response processes covering identification, containment, investigation, reporting, recovery, and lessons learned; coordinate incident activities across One IT, Security, programs, and organizational stakeholders.
- Support continuous monitoring across classified and unclassified environments, including review of telemetry, audit records, alerts, and findings for potentially unauthorized or anomalous activity.
- Coordinate incident response exercises and cybersecurity tabletop exercises.
- Support business continuity and disaster recovery planning and testing.
- Partner with the Director of Engineering & Service Delivery to ensure enterprise systems and networks meet applicable cybersecurity requirements, including cybersecurity governance and technical oversight for SCIF IT operations and classified environments.
- Support secure mission environment activities, including design, deployment, assessment, and operation of classified enclaves, cloud platforms, and cyber ranges.
- Evaluate security technologies and recommend scalable solutions; provide cybersecurity guidance for infrastructure modernization, software implementation, vendor relationships, and third-party services.
- Ensure cybersecurity controls support operational requirements without unnecessarily impacting mission execution or business velocity.
- Serve as a cybersecurity and compliance resource for program delivery, Growth, Capture, and Proposal teams, including reviewing cybersecurity requirements for new programs, contracts, proposals, and technical environments.
- Support customer engagements, government accreditation activities, technical reviews, and cybersecurity discussions; prepare technical reports, risk assessments, cybersecurity briefings, and leadership updates.
- Translate cybersecurity requirements into clear technical and operational actions.
- Lead and develop cybersecurity and compliance personnel by setting priorities, responsibilities, and performance expectations; assign work, track deliverables, remove blockers, and ensure commitments are completed on schedule.
- Partner with Talent Acquisition and One IT leadership to identify workforce requirements and required competencies, and support onboarding, training, mentoring, and knowledge transfer.
- Develop cybersecurity awareness and IT security training programs with measurable outcomes.
- Identify opportunities to automate compliance, evidence collection, monitoring, reporting, and recurring cybersecurity processes.
- Drive continuous improvement to increase cybersecurity maturity, reduce risk, and improve operational effectiveness; promote security as an enabler of mission execution and business growth.
Required Qualifications
- Active TS/SCI clearance.
- Current DoDM 8570 IAM Level II or III certification, with CISSP strongly preferred, or equivalent DoD 8140.03 qualification.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 8 or more years of progressive cybersecurity, information assurance, or IT compliance experience within DoD or IC environments.
- Hands-on experience with RMF, including SSP development, POA&M management, control implementation, evidence development, and ATO package preparation.
- Strong working knowledge of FISMA, NIST 800-53, NIST 800-171, CMMC, RMF, ICD, and JSIG requirements.
- Experience with vulnerability assessment tools such as ACAS, Nessus, eMASS, Xacta, HBSS, or comparable platforms.
- Experience assessing IaaS, PaaS, and SaaS environments.
- Experience working within classified environments and complex enterprise or mission network architectures.
- Demonstrated ability to lead technical personnel and drive cybersecurity initiatives through completion.
- Must be eligible for employment in the United States.
Technologies
- CMMC, NIST 800-171, NIST 800-53, FISMA, RMF, ICD, JSIG
- ACAS, Nessus, DISA SRR scripts, HBSS
- Endpoint security platforms
- DISA STIGs
- eMASS, Xacta
- IaaS, PaaS, SaaS
- SIEM
Benefits
- Performance-based bonuses
- Extensive medical, dental, and vision coverage
- 401(k) plan with company match
- Substantial paid time off and holidays
- Flexible work arrangements where possible
- Range of income protection benefits
Preferred Qualifications
- CISSP certification
- SecurityX, CySA+, or equivalent certifications
- Experience supporting Joint Staff JSIG ATOs or IC accreditation activities
- Experience supporting DoD, IC, or federal cybersecurity and compliance programs
- Prior government civilian or military cybersecurity experience
- Experience supporting cybersecurity budgets and technology planning in a government contracting environment
- Familiarity with SIEM, continuous monitoring, vulnerability management, and automated compliance platforms
- Experience supporting cybersecurity programs through organizational growth, acquisition, or infrastructure modernization
Position Details
- Reports To: Vice President, Information Technology
- Location: Herndon, VA (onsite)
- Travel: Up to 25%
- Security Clearance: Active TS/SCI required
Salary Range
USD 100,000 - 278,000 per yearly
Education
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field