Information Systems Security Manager (ISSM)
Astranis · San Francisco
About this role
**Astranis — Information Systems Security Manager (ISSM)** Astranis builds advanced satellites for high orbits, providing dedicated, secure networks for large enterprises, sovereign governments, and the U.S. military. With five satellites on orbit and more launching soon, the ISSM will help ensure classified and unclassified systems are secure, compliant, and inspection-ready across collateral and SCIF environments. --- ## **Role** The Information Systems Security Manager (ISSM) leads the development, implementation, and oversight of **Risk Management Framework (RMF)**, **Information Security**, and **information assurance** programs. This role ensures compliance with **32 CFR Part 117 (NISPOM)** and applicable **Intelligence Community Directives (ICDs)**, while enabling mission success. You will serve as the principal advisor on classified information system security matters and coordinate closely with government customers, security leadership, and technical teams. --- ## **Key Responsibilities** ### **Program Leadership, Compliance & RMF** - Lead and manage the Information System Security Program in accordance with **NISPOM** and applicable **ICDs** (e.g., **ICD 503, ICD 705**) - Serve as principal advisor on classified systems security matters - Oversee RMF lifecycle activities: categorization, control implementation, assessment, authorization, and continuous monitoring - Ensure systems meet classified processing requirements and maintain proper accreditation status - Develop, review, and maintain **System Security Plans (SSPs)**, **policies**, **procedures (SPPs)**, and supporting artifacts - Represent the organization with accrediting authorities; review and approve authorization packages - Interface directly with **Security Control Assessors (SCAs)** during assessments ### **System Security & Continuous Monitoring** - Manage continuous monitoring programs (vulnerability assessments, **POA&M** tracking, audit reviews) - Analyze **SIEM** outputs and audit logs to identify anomalous or unauthorized activity - Conduct self-assessments and implement corrective actions for vulnerabilities and compliance gaps - Maintain accurate system documentation (SSPs, POA&Ms, risk assessment reports) - Ensure configuration management, patching, and system hardening aligned with **STIG** requirements ### **Network, Operations & Incident Response** - Oversee cybersecurity posture of **LANs**, **WANs**, and standalone systems - Monitor systems to detect threats, vulnerabilities, and operational risks - Manage **COMSEC**, media control, and data spill response procedures across classified environments - Develop and execute incident response processes for spills, malware, and insider threat activities - Investigate, document, and report incidents per government requirements - Assess security impact of system changes and support formal change management ### **Inspections, Training & Governance** - Lead and support inspections, audits, and assessments by **DCSA** and Intelligence Community stakeholders - Engage with government representatives to validate compliance with technical and policy requirements - Review and implement security advisories, directives, and emerging requirements - Deliver security education and awareness training to users, administrators, and leadership - Develop and enforce classified system policies, procedures, and SOPs - Communicate security responsibilities across all organizational levels --- ## **Requirements** - **
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.