SonicJobs Logo
Left arrow iconBack to search

Information Systems Security Manager (ISSM)

CFD Research Corporation
Posted a day ago, valid for 20 days
Location

Dayton, OH, US

Salary

Competitive

Contract type

Full Time

Life Insurance
Disability Insurance

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

About CFD Research: Since its inception in 1987, CFD Research has delivered innovative technology solutions within the Aerospace & Defense, Biomedical & Life Sciences, Intelligence & Sensing, and Energy & Materials industries. CFD Research has earned multiple national awards for successful application and commercialization of innovative component/system technology prototypes, multi-physics simulation software, multi-disciplinary analyses, and expert support services. Based in Huntsville, Alabama where laboratory facilities and headquarters are located, CFD Research also has office and laboratory facilities in Dayton, Ohio, prototyping test and evaluation facilities in Hollywood, Alabama, and office facilities in Fort Walton Beach, Florida. CFD Research is an ISO9001:AS9100D registered company and is appraised at CMMI Level II for Services. CFD Research is a 100% ESOP (employee-owned company) recognized in Inc. Magazine's Inc5000 as a top growing company for four of the last five years. Learn more at www.cfd-research.com

About the Role

CFD Research is seeking an experienced Information System Security Manager to lead and support the authorization, operation, and continuous monitoring of classified information systems at our Beavercreek, OH facility.

The ISSM will serve as a trusted security advisor responsible for ensuring classified systems are developed, authorized, maintained, and operated in accordance with the National Industrial Security Program Operating Manual, DCSA Assessment and Authorization Guide, Risk Management Framework, customer requirements, and applicable special-access security guidance.

The ideal candidate will have demonstrated experience managing multiple authorization packages across different government agencies, system architectures, classification levels, and mission environments. Experience supporting Special Access Programs is strongly preferred.

This position requires an individual who can work independently, coordinate effectively with technical and program personnel, and translate government cybersecurity requirements into practical, sustainable processes.

What You’ll Do

  • Serve as the appointed ISSM for classified information systems.
  • Lead the development, submission, maintenance, and reauthorization of system authorization packages in eMASS or other government-directed authorization platforms.
  • Manage multiple systems and authorization efforts across collateral, SCI, SAP, and other customer security environments, as applicable.
  • Develop and maintain System Security Plans (SSP), security policies, procedures, control implementation statements, diagrams, inventories, risk assessments, Plans of Action and Milestones, and continuous-monitoring documentation.
  • Coordinate directly with DCSA Information System Security Professionals, Authorizing Officials, government cybersecurity representatives, program security personnel, and customer system owners.
  • Interpret and implement requirements from 32 CFR Part 117, the DCSA DAAG, NIST SP 800-53, applicable Security Technical Implementation Guides, Committee on National Security Systems guidance, and customer-specific direction.
  • Evaluate proposed system architectures, authorization boundaries, hardware, software, connections, data flows, and classified processing requirements.
  • Support the development and approval of new classified systems, including proposal systems, standalone systems, peer-to-peer environments, client-server networks, and interconnected systems.
  • Establish and manage configuration-control, change-management, vulnerability-management, audit, patching, account-management, media-protection, and incident-response processes.
  • Ensure system changes are reviewed, documented, approved, and maintained within the authorized security posture.
  • Conduct periodic reviews, self-inspections, control assessments, vulnerability scans, and continuous-monitoring activities.
  • Coordinate classified-system requirements with the Facility Security Officer, program leadership, Information Technology, physical security, personnel security, and insider-threat personnel.
  • Prepare systems and supporting personnel for DCSA, customer, SAP, SCI, and other government cybersecurity inspections or assessments.
  • Identify program deficiencies, communicate risk to leadership, and ensure corrective actions are documented and completed.
  • Develop repeatable processes, templates, and governance standards that can scale as the company’s classified-system portfolio grows.

Required Qualifications

  • Bachelor’s degree in related field, or an equivalent combination of education and relevant experience.
  • CISSP, CISM, or equivalent advanced cybersecurity certification.
  • 7+ years of progressively responsible cybersecurity, information-assurance, classified-system, or Risk Management Framework experience.
  • 3+ years of direct experience serving as an ISSM or ISSO
  • Demonstrated experience developing, managing, or maintaining authorization packages in eMASS.
  • Ability to evaluate Windows, Linux, standalone, peer-to-peer, client-server, and networked system environments.
  • Active Top Secret clearance with eligibility for SCI access required

Preferred Qualifications

  • IAT Level II - (Security+ CE, CCNA Security, etc.)
  • DoD 8570.01-M IAM Level II (in lieu of IAT Level II)
  • Experience supporting Special Access Programs
  • Experience managing authorization packages across multiple agencies, Authorizing Officials, or security cognizance authorities.
  • Experience with collateral, SCI, and SAP systems at the Secret and Top Secret levels.
  • Experience supporting multi-program or shared systems with access separation and multiple DD Form 254 requirements.
  • Experience with security assessments, government inspections, vulnerability scanning, STIG implementation, audit review, and corrective-action tracking.

Benefits: CFD Research offers competitive salaries and excellent employee benefits, including an employer matching 401(k) and Employee Stock Ownership Plan (ESOP). CFD Research offers our Full-Time, permanent employee-owners a highly competitive insurance package, including medical, vision, and dental insurance. Additionally, we offer company paid leave, compensation time, parental leave, long-term and short-term disability, accidental death and dismemberment, and life insurance. Part-Time and Temporary employee-owners may receive partial or reduced benefits and leave time based on their employment status level. Performance appraisals occur twice a year and annual pay increases are based upon corporate goals, personal development, performance, and outstanding achievements. In addition, group and individual bonuses are awarded for exceptional performance.

CFD Research is an EO employer - Veterans/Disabled and other protected categories




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.