Information Systems Security Manager (ISSM)

Astranis•San Francisco, CA
•$150,000 - $218,000•Onsite

About The Position

The Information Systems Security Manager (ISSM) is responsible for leading the development, implementation, and oversight of Risk Management Framework (RMF), Information Security, and information assurance programs supporting classified and unclassified systems across collateral and Sensitive Compartmented Information Facility (SCIF) environments. This role ensures compliance with 32 CFR Part 117 (NISPOM) and applicable Intelligence Community Directives (ICDs), safeguarding national security information while enabling mission success. The ISSM serves as the principal advisor on all classified information system security matters and collaborates closely with government customers, security leadership, and technical teams to maintain secure, compliant, and inspection-ready environments. Working in coordination with the Chief Security Officer, the ISSM implements enterprise common controls and represents the organization with U.S. Government accrediting authorities, including Authorizing Officials (AOs) and Security Control Assessors (SCAs). The ISSM ensures a strong operational security posture across local area networks (LANs), wide area networks (WANs), and standalone systems through proactive risk management and continuous monitoring.

Requirements

  • Active U.S. Government Top Secret clearance with SCI eligibility.
  • Bachelor’s degree in a related field or equivalent experience.
  • 6+ years of experience in ISSM roles supporting classified systems in collateral and SCIF environments.
  • Demonstrated experience with eMASS and participation in DCSA assessments.
  • Current CompTIA Security+ (or equivalent) certification in compliance with DoD Directive 8140.
  • U.S. Citizenship, Lawful Permanent Residency, or Refugee/Asylee Status Required

Responsibilities

  • Lead and manage the Information System Security Program in accordance with NISPOM and applicable ICDs (e.g., ICD 503, ICD 705).
  • Serve as principal advisor on all classified systems security matters.
  • Oversee RMF lifecycle activities, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Ensure systems meet classified processing requirements and maintain proper accreditation status.
  • Develop, review, and maintain System Security Plans (SSPs), policies, procedures (SPPs), and supporting artifacts.
  • Represent the organization with accrediting authorities; review and approve authorization packages.
  • Interface directly with Security Control Assessors (SCAs) to demonstrate compliance during assessments.
  • Manage continuous monitoring programs, including vulnerability assessments, POA&M tracking, and audit reviews.
  • Analyze SIEM outputs and audit logs to identify anomalous or unauthorized activity.
  • Conduct self-assessments and implement corrective actions to address vulnerabilities and compliance gaps.
  • Maintain accurate system documentation, including SSPs, POA&Ms, and risk assessment reports.
  • Ensure configuration management, patching, and system hardening in alignment with STIG requirements.
  • Oversee the cybersecurity posture of LANs, WANs, and standalone systems.
  • Monitor systems to detect threats, vulnerabilities, and operational risks.
  • Manage COMSEC, media control, and data spill response procedures across classified environments.
  • Develop and execute incident response processes for spills, malware, and insider threat activities.
  • Investigate, document, and report incidents in accordance with government requirements.
  • Assess the security impact of system changes and support formal change management processes.
  • Lead and support inspections, audits, and assessments conducted by DCSA and Intelligence Community stakeholders.
  • Engage directly with government representatives to validate compliance with technical and policy requirements.
  • Review and implement security advisories, directives, and emerging requirements.
  • Deliver security education and awareness training to users, administrators, and leadership.
  • Develop and enforce classified system policies, procedures, and standard operating procedures (SOPs).
  • Communicate security responsibilities clearly across all organizational levels.

Benefits

  • Equity package via incentive stock options
  • High-quality company-subsidized healthcare
  • Disability insurance
  • Life insurance
  • 401(k) retirement planning
  • Flexible PTO
  • Free on-site catered meals
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service