Information Systems Security Manager - Security

Greenwood Village, Colorado, United Statesyesterday
Work style:On-site
Employment:Contract
Education:Bachelor’s degree
Apply Now

Job description

York is seeking an Information Systems Security Manager (ISSM) to manage cybersecurity and the Risk Management Framework (RMF) lifecycle for assigned on-premises ground systems supporting DoD missions. The ISSM will oversee system authorization and continuous monitoring activities, provide direction to the assigned ISSO, and coordinate with engineering, operations, program leadership, and government stakeholders.

This role will be fully on-site in our Greenwood Village, Colorado office.

Responsibilities

Manage the RMF lifecycle, including categorization, control selection and implementation, assessment coordination, authorization support, reauthorization, and continuous monitoring.

Develop and maintain eMASS authorization packages, System Security Plans (SSPs), assessment evidence, security procedures, and Plans of Action and Milestones (POA&Ms).

Track authorization milestones and maintain assessment readiness to support initial authorizations, ATO sustainment, and IATTs, as applicable.

Provide direction, mentorship, and oversight to the assigned ISSO, establishing priorities and reviewing work for accuracy, completeness, and timeliness.

Coordinate security control implementation, ACAS scanning, DISA STIG assessments, and vulnerability remediation with technical teams.

Oversee continuous monitoring activities, including periodic control reviews, audit log review processes, and tracking of outstanding findings.

Review system changes for security impact and support configuration management, approved baselines, and change control processes.

Prepare for security assessments, inspections, and audits; coordinate incident reporting, corrective actions, and resolution of assessment findings.

Serve as the cybersecurity point of contact for assigned systems and communicate authorization status, security risks, and remediation priorities.

Coordinate with the FSO and other security personnel on access requirements, user security responsibilities, and protection of classified information, as applicable.

This role will have direct reports.

Required Qualifications

Bachelor’s degree in cybersecurity, information technology, or a related field and five years of relevant information systems security experience, or an equivalent combination of education, training, and experience.

Security+ or another qualification satisfying applicable DoD 8140/DCWF requirements.

Experience managing DoD RMF activities and authorization packages as an ISSM or an ISSO with substantial package responsibility.

Hands-on eMASS experience, including security controls, assessment evidence, POA&Ms, and authorization documentation.

Working knowledge of NIST SP 800-53/53A, CNSSI 1253, DISA STIGs, and applicable DoD authorization requirements.

Experience developing SSPs, security procedures, and continuous monitoring documentation that accurately reflect system implementation.

Experience interpreting vulnerability scan results and STIG findings, coordinating remediation, and documenting unresolved risks.

Familiarity with on-premises Windows and Linux systems, networking, virtualization, access controls, audit logging, and configuration management.

Ability to independently manage system security responsibilities, guide an ISSO, and coordinate with technical and program stakeholders.

Experience supporting security assessments or audits and presenting documentation and evidence to assessors.

Strong communication, documentation, and organizational skills, including the ability to explain security risks and track competing priorities.

U.S. Citizenship

Active Secret security clearance and applicable contract-required cybersecurity qualifications.

Experience supporting multiple authorization boundaries, ATOs, or IATTs.

Willingness to work full-time in office in Greenwood Village, CO

Preferred Qualifications

Prior ISSM experience supporting classified DoD or ground mission systems.

Experience with SDA and DCSA authorization activities and DAAG requirements.

CISSP, CISM, or another relevant cybersecurity management certification.

Skills mentioned


Aerospace
Greenwood Village, Colorado, United States

Apply for this job

Use the application link supplied with this listing to apply to York Space Systems. Check the destination before entering personal information.

Apply Now