We are looking for a highly skilled and motivated
Information Systems Security Manager (ISSM) to join our team onsite at our San Diego office. Reporting to the Director of Operations, you will be at the forefront of developing, implementing, and upholding our company's digital security compliance strategy and information security, ensuring compliance with stringent government regulations and standards. Your expertise will be crucial in protecting our sensitive data, managing risks, and ensuring that our operations meet all required cybersecurity maturity models and information control protocols. With expertise in NIST, DFARS, ISO 27001, and classified information management, you will play a key role in securing our operations and maintaining compliance with defense industry requirements. If you're passionate about safeguarding critical data and upholding the highest standards of security, we'd love for you to join us at Firestorm.
What You'll Do - Develop, implement, and maintain the company's information security policies, standards, and procedures to ensure compliance with NIST SP 800-171, DFARS [redacted], and other relevant regulations.
- Lead efforts to achieve and maintain compliance with CMMC and ISO 27001, including coordinating certification processes and managing ongoing audits.
- Oversee the protection of Controlled Unclassified Information (CUI) and other controlled information.
- Implement and oversee procedures for handling classified information, ensuring compliance with all applicable government regulations and directives.
- Conduct regular risk assessments and vulnerability analyses to identify and mitigate potential security threats, including those related to classified information systems.
- Coordinate with internal teams to integrate security controls into all aspects of operations, including product development and supply chain management.
- Serve as the primary liaison with government agencies and customers regarding information security compliance, and reporting.
- Develop and manage the incident response plan, leading investigations and remediation efforts, in the event of security breaches or incidents involving classified or sensitive information.
- Provide training and awareness programs to educate employees on information security policies, procedures, best practices, and the handling of classified information.
- Stay current with evolving regulatory requirements, emerging threats, and industry best practices to continuously improve the company's security posture.
- Collaborate with our DevSecOps team on the design, implementation and maintenance of cATO (continuous Authority to Operate) pipelines.
- Collaborate with IT and engineering teams to ensure secure system architectures and data protection mechanisms are in place, especially for systems processing classified information.
- Must be willing to travel up to 10%
Required Qualifications- Bachelor's degree in Computer Science, Information Systems, Cybersecurity or a related field; relevant experience may be substituted in lieu of a degree
- U.S. Citizenship required due to ITAR regulations, with the ability to obtain and maintain a DoD security clearance
- 7+ years of experience in information security management, with at least 3 years in a leadership role.
- Extensive knowledge of NIST SP 800-171, NIST SP 800-53, DISA-STIGS, DFARS [redacted], ISO 27001, CUI handling requirements, and classified information security protocols.
- Proven experience in developing and implementing information security programs and achieving compliance with regulatory standards.
- Strong understanding of risk management principles and experience conducting risk assessments and vulnerability management, including in classified environments.
- Experience with incident response planning and execution, particularly concerning classified information.
- Familiarity with data protection laws and regulations.
- Excellent communication skills, with the ability to articulate complex security requirements to technical and non-technical stakeholders.
Preferred Qualifications - Professional certifications such as CISSP, Security+, CISM, CISA or other DoD Approved 8570 Baseline Certification in the Information Assurance Management (IAM) Level III category.
- Defense or aerospace industry experience a plus.
- Familiarity with cybersecurity maturity models like CMMC (Cybersecurity Maturity Model Certification).
- Experience with security audit processes and interfacing with regulatory auditors.
- Experience with informing design and implementation cATO pipelines.
- Experience with classified information systems (e.g., Joint Worldwide Intelligence Communications System - JWICS, Secret Internet Protocol Router Network - SIPRNet).
- Experience with Special Access Programs (SAP) and Sensitive Compartmented Information (SCI).
- Knowledge of cloud security principles and experience securing cloud environments handling classified or sensitive data.
Work Environment- Position is based onsite at our San Diego, CA headquarters
- We welcome candidates who are local or open to relocating; relocation assistance is available and may be included in the offer package where appropriate.
- Willingness and ability to travel up to 10% for seminars
Compensation- Base salary: $140,000 - $180,000 base, commensurate with experience
- Equity: Meaningful equity grant in a growth-stage defense technology company
The posted salary range reflects an estimate based on a variety of compensation factors, including but not limited to relevant experience, education, certifications, specialized skills, geographic location, and business needs. Actual compensation may vary, and this range is subject to change as our compensation structure or market conditions evolve.
Benefits & PerksOur culture fosters collaboration, respect, and trust, empowering passionate people to do their best work. We offer a competitive salary, comprehensive benefits, and opportunities for career growth. In addition to an opportunity to take part in an innovative, collaborative and fast-growing business with a highly motivated and skilled team, we also take pride in taking care of our employees. Here are just a few ways that we show our appreciation:
- We offer comprehensive medical, dental, and visions plans
- 401(k) Retirement Savings Plan to invest in your long-term retirement goals
- Equity grants for new hires
- Unlimited PTO
- Extremely generous company holiday calendar, including holiday hiatuses in July & December.
- Generous Parental Leave
- Lifestyle Spending Account
- FSA
- DCFSA
- HSA
- Hospital Indemnity insurance
- Critical Illness insurance
- Accident insurance
- Basic Life/AD&D, short-term and long-term disability insurance, 100% covered by Firestorm. Plus, the option to purchase additional life insurance for you and your family.
- Mental Health Resources: We provide free mental health resources 24/7 including therapy and more. Additional work-life services, such as free legal and financial support, are available to you as well.
Export Control ComplianceTo conform to U.S. government export control regulations, including the International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or otherwise eligible to obtain the required authorizations from the U.S. Department of State or U.S. Department of Commerce.