Sr. Information Systems Security Manger

QinetiQ U.S.

Chantilly (VA)

On-site

USD 150,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

QinetiQ US is seeking a Sr. Information Systems Security Manager to provide strategic cybersecurity support for a critical Chantilly client. You will lead RMF A&A, define security architecture, and oversee continuous monitoring across on-premises, cloud, PIT, and FRCS environments.

The role requires strong collaboration with DoD partners, extensive SSP/ATO experience, and active TS/SCI with SAP eligibility. On-site work five days a week in Chantilly, VA is expected.

Qualifications

  • Experience applying NIST RMF and SP 800-53.
  • Proficient with ACAS and Splunk for continuous monitoring.
  • Experience developing and maintaining SSPs and ATO packages.
  • Active TS/SCI clearance with SAP eligibility.
  • On-site Chantilly, VA 5 days a week.

Responsibilities

  • Lead RMF A&A efforts for DoD enterprise-level SaaS and FRCS; prepare and validate SSPs.
  • Serve as liaison between engineering, SCA, SCO ITX, ISO, and AO for DoD/NIST compliance.
  • Oversee continuous monitoring programs and conduct regular security checks.
  • Monitor privileged user accounts, conduct audits, and review baselines and data flows.
  • Develop and track Plans of Action and Milestones (POA&Ms); remediate vulnerabilities.
  • Draft and enforce platform-specific cybersecurity policies and SOPs for cloud SaaS; align with JSIG, CNSSI 1253, and DoD regulations.
  • Maintain accountability of SAP removable media with lifecycle tracking.
  • Establish AFT procedures as Data Transfer Agent with TPI and auditable logs.
  • Lead cybersecurity assessments of FRCS (HVAC, Utility Control, ECSS) per UFC 4-010-06 and NIST SP 800-82.
  • Provide real-time analysis and support Incident Response activities.

Skills

RMF expertise
Security policy development
Stakeholder communication
Cross-functional collaboration
On-site coordination

Education

Bachelor's degree in IT/Cybersecurity

Tools

ACAS (Tenable Nessus/SecurityCenter)
Splunk Enterprise

Job description

Sr. Information Systems Security Manger

Job Location: US-VA-Chantilly

Company Overview

We are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50+ locations world-wide. Much of our work contributes to innovative research in the fields of sensor science, signal processing, data fusion, artificial intelligence (AI), machine learning (ML), and augmented reality (AR).

QinetiQ US's dedicated experts in defense, aerospace, security, and related fields all work together to explore new ways of protecting the American Warfighter, Security Forces, and Allies. Being a part of QinetiQ US means being central to the safety and security of the world around us. Partnering with our customers, we help save lives; reduce risks to society; and maintain the global infrastructure on which we all depend.

Why Join QinetiQ US?

If you have the courage to take on a wide variety of complex challenges, then you will experience a unique working environment where innovative teams blend different perspectives, disciplines, and technologies to discover new ways of solving complex problems. In our diverse and inclusive environment, you can be authentic, feel valued, be respected, and realize your full potential. QinetiQ US will support you with workplace flexibility, a commitment to the health and well-being of you and your family and provide opportunities to work with a purpose. We are committed to supporting your success in both your professional and personal lives.

Position Overview

QinetiQ US is seeking a senior Cybersecurity Information Systems Security Mnager to provide strategic cybersecurity support to a critical client in Chantilly, va. The cybersecurity professional will serve as the principal cybersecurity authority and liaison for internal, external, and guest information systems across multiple classification enclaves up to TS/SCI/SAR. Candidate will be responsible for the end-to-end Risk Management Framework (RMF) lifecycle, security architecture engineering, and continuous monitoring of complex on-premises, cloud, Platform IT (PIT), and Facility-Related Control Systems (FRCS). Utilizing extensive cybersecurity policy writing expertise, this position partners with DoD mission partners and joint-service stakeholders to establish secure interconnectivity, govern Assured File Transfers (AFT), and execute guest system lifecycles from initial site survey through final authorization.

Responsibilities
  • Lead comprehensive RMF Assessment and Authorization (A&A) efforts for DoD enterprise-level SaaS (IL5) and Facility-Related Control Systems (FRCS), preparing and validating complete System Security Plans (SSPs) to achieve and maintain System ATOs.
  • Serve as the primary liaison between engineering staff and senior leadership, working directly with the Security Control Assessor (SCA), the SCO ITX Operations team, Information System Owner (ISO), and Authorizing Official (AO) to ensure DoD and NIST IA compliance.
  • Execute robust continuous monitoring (ConMon) programs, performing scheduled administrative and manual security checks to ensure the system's real-time risk posture remains within acceptable parameters.
  • Proactively monitor privileged user accounts, conduct audit reviews, review configuration baselines, and data flows to prevent unauthorized modifications for SaaS environment.
  • Develop, track, remediate, and report on Plans of Action and Milestones (POA&Ms), actively collaborating with technical teams to mitigate identified system vulnerabilities and close security gaps.
  • Draft, establish, and enforce platform-specific cybersecurity policies and Standard Operating Procedures (SOPs) for a cloud-based SaaS solution, aligning cloud tenant configurations with JSIG, CNSSI 1253, and a multitude of DoD regulations.
  • Maintain 100% physical and digital accountability of SAP removable media in coordination with the Agency Security team, enforcing strict lifecycle tracking from onboarding through witnessed destruction.
  • Establish, document, and supervise strict AFT procedures (high-to-low/low-to-high) as a designated Data Transfer Agent (DTA), strictly enforcing Two-Person Integrity (TPI) and auditable transfer logging.
  • Lead comprehensive cybersecurity assessments of FRCS (HVAC, Utility Control, Electronic Security Systems) in strict accordance with UFC 4-010-06 and NIST SP 800-82 (OT Security), executing the RMF process to secure and maintain ATOs.
  • Direct real-time analysis, commentary, and handling of security events, actively assisting in Incident Response (IR) activities and spearheading technical innovations to optimize analyst oversight.
Required Qualifications
  • Expertise in applying NIST Special Publications, including NIST SP 800-37 (RMF), 800-53 (Rev 4/5), 800-137 (ConMon), 800-39 (Risk), 800-171/171A (CUI), 800-30 (Threat ID), and NIST SP 800-18 (System Characterization).
  • Proficient in leveraging ACAS (Tenable Nessus/SecurityCenter) and Splunk Enterprise to orchestrate continuous monitoring; engineered custom Splunk dashboards and correlated ACAS vulnerability data to rapidly identify system anomalies, track DISA STIG compliance, and provide leadership with real-time risk posture visibility.
  • Operational understanding of Operational Technology (OT) security, applying NIST SP 800-82 guidelines to assess utility control, HVAC, and electronic security systems.
  • Extensive experience developing and maintaining core ATO package artifacts, including Disaster Recovery Plans (DRP), Contingency Plans (CP), Incident Response Plans (IRP), and SSPs.
  • Current or recent experience supporting Special Access Programs
  • Current/Active Top Secret/SCI clearance with SAP eligibility
  • Minimum of six (6) years of demonstrated experience in IT, cybersecurity engineering, and Assessment & Authorization (A&A), with increasing responsibility with 10 years of total work experience
  • Active baseline certification equivalent to DoD 8140.01 / 8570.01-M Information Assurance Workforce Improvement Program (IA WIP) for IAT Level II
  • Bachelor's degree in Information Technology, Cybersecurity or similar topic area
  • Ability to work on-site in Chantilly, VA 5 days a week
Preferred Qualifications
  • Previous experience supporting rapid prototyping organizations such as DARPA, RCO, RTCCO etc.
  • Previous experience as SCA preferred but not required
Pay Transparency

The salary range for this role is $150,000 - $200,000USD. The salary range provided is a good faith estimate representative of all experience levels. QinetiQ US considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.

Company EEO Statement

Accessibility/Accommodation:

If because of a medical condition or disability you need a reasonable accommodation for any part of the employment process, please send an e-mail to staffing@us.QinetiQ.com or call (540) 658-2720 Opt. 1 and let us know the nature of your request and contact information.

QinetiQ US is an Equal Opportunity employer. All Qualified Applicants will receive equal consideration for employment without regard to race, age, color, religion, creed, sex, sexual orientation, gender identity, national origin, disability, or protected Veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Program Security Representative (Cyber & Long Range Fires)
Senior Program Security Representative (Cyber & Long Range Fires)

QinetiQ U.S. • Chantilly (VA)

On-site
USD 100,000 - 130,000
Senior Program Security Representative (Cyber & Long Range Fires)
Senior Program Security Representative (Cyber & Long Range Fires)

QinetiQ US • Chantilly (VA)

On-site
USD 90,000 - 120,000
Security Specialist - PERSEC
Security Specialist - PERSEC

QinetiQ US • Chantilly (VA)

On-site
USD 100,000 - 125,000
Security Specialist - PERSEC
Security Specialist - PERSEC

QinetiQ U.S. • Chantilly (VA)

On-site
USD 100,000 - 125,000
Security Specialist - PERSEC
Security Specialist - PERSEC

QinetiQ US (formerly Avantus Federal) • Chantilly (VA)

On-site
USD 100,000 - 125,000
Identity Signature Management Technician
Identity Signature Management Technician

QinetiQ US • Arlington (VA)

On-site
USD 125,000 - 145,000
Identity Signature Management Technician
Identity Signature Management Technician

QinetiQ US • Arlington (VA)

On-site
USD 125,000 - 145,000
Sr International Cooperation Lead (On-site/SETA)
Sr International Cooperation Lead (On-site/SETA)

QinetiQ U.S. • Chantilly (VA)

On-site
USD 150,000 - 200,000
Cyber Analyst - Mid
Cyber Analyst - Mid

QinetiQ U.S. • Washington

On-site
USD 102,000 - 107,000
Executive Communications Specialist
Executive Communications Specialist

QinetiQ U.S. • Chantilly (VA)

On-site
USD 120,000 - 140,000