YOUR ROLEThe Information Systems Security Manager/Engineer (ISSM/E) at WRX will excel in a dynamic and ever-changing environment, demonstrating adaptability, flexibility, and proactive initiative. This role focuses on creating new compliance policy and programs and continuously monitoring and improving existing security programs, ensuring it meets U.S. federal, global, and industry specific security requirements and standards. The ISSM/E will report to the and work closely with the Sr. Director of Compliance.
The ISSM/E will play a vital role in aligning internal IT security objectives with broader business goals, effectively communicating progress and potential challenges to stakeholders at various levels. Responsibilities include ensuring compliance with relevant regulations and standards, conducting risk assessments, monitoring controls, developing and implementing IT security policies and procedures, and overseeing IT security audits and assessments. The ideal candidate will bring prior ISSM/E experience from FOCI mitigated companies and a deep knowledge in with network and systems engineering and architecture.
RESPONSIBILITIESGovernance, Risk & Compliance (GRC) Execution- Maintain enterprise compliance readiness aligned to ISO 27001, NIST 800-171, CMMC, SOX, TISAX, GDPR, NIS2, and similar regulatory frameworks.
- Drive engagement with control owners, SMEs, and leadership to track risk exceptions, POA&Ms, maturity improvements, and audit-ready evidence.
- Support continuous improvement of the cybersecurity policy, standards, and governance framework to ensure consistency across multi-entity operations.
- Developing architecture documentation and Systems Security Plans (SSP) to support Accreditation and Authorization (A&A) reviews
Enterprise Resilience & Continuity- Own documentation, updates, and execution of business impact assessments (BIAs), continuity plans, disaster recovery strategies, and tabletop exercises.
- Partner with cross-functional teams to ensure IT and cyber security compliance across the business.
- Maintain continuity and response playbooks, leveraging prior experience leading large-scale DoD and enterprise network operations.
- Knowledge of the complex environment involving shared networks and multiple security enclaves.
- Engineering for Cyber engineering and integration services including security, authentication, identity management, authorization, and access control engineering.
Third-Party Risk Management (TPRM) & Cyber Training- Execute WRX's vendor risk assessments, evidence reviews, and remediation tracking, applying DoD and federal acquisition (ISA Level III) experience to strengthen supply-chain posture.
- Enforce cybersecurity right-to-audit clauses and support contract redline reviews for both buy- and sell-side agreements.
- Support mandatory cybersecurity training initiatives, awareness campaigns, and development of role-based materials.
Audit & Assurance Leadership- Lead enterprise IT audit preparation for internal reviews, external audits, customer assessments, and regulatory inquiries.
- Manage and maintain System Security Plans (SSPs), Electronic Communications Plan (ECP), Plans of Action & Milestones (POA&Ms), and required customer assurance documentation.
- Coordinate walkthroughs, interviews, and evidence collection across matrixed teams, operating with the discipline gained from federal audit, CMMC AUDIT and certification, RMF, and DoDIN environments.
Cross-Functional Operations & Leadership- Provide high-quality execution support for strategic initiatives led by the President and Government Security Committee, Training, and continued monitoring.
- Work closely with Architecture, Product Security, Engineering, and vendor partners to unblock dependencies and support compliance-aligned implementations.
- Self-starter able to work independently and build relationships with technical reps across divisions, comfortable with cyber security and able to brief issues to the customer
Key skills and competencies for succeeding in this role are:
- Cyber security.
- Security Development and Operations (SecDevOps)
- Cloud security controls and implementation
- STIG compliance and vulnerability management
- Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, Xacta
- Experience with network and systems engineering and architecture.
- Strong writing skills and ability to collaborate with cross departmental teams.
- Microsoft Office365
- Experience in one or more software products associated with cyber system engineering for data analytics including SQL security, TANIUM Endpoint Management Software, Powershell, MacAfee, App Blocker, Splunk ITSI.
- Experience in one or more cloud computing services and technologies including but not limited to: AWS/C2S, Microsoft Azure, Nutanix, VMware.
- Familiarity with relevant governmental regulation and organizations.
- Experience in creating and implementing policy for companies operating under FOCI mitigation.
Required Qualifications:
- 2-10 years in cybersecurity risk management, compliance, audit, or GRC-experience in federal/DoD, FOCI-mitigated, or highly regulated environments strongly preferred.
- Demonstrate understanding on how to Build and/or maturing cybersecurity governance programs, SSP/ECP/POA&M development, control implementation, and audit readiness.
- Experience with frameworks such as ISO 27001, NIST 800-171, CMMC, RMF, TISAX, SOX, GDPR, or similar.
- Familiarity with GRC platforms and compliance tooling.
- Strong writing, documentation, and communication skills, including senior-level briefings.
- U.S. Citizenship required.
Preferred Qualifications:
- Experience leading cybersecurity efforts in multi-entity operations, including standing up new IT environment that meets all of the required government cyber security standards.
- Demonstrated background in secure architecture, enterprise networking, CMMC, SOC/SIEM/SOAR strategy.
- Experience in vendor risk management, contract review, and supply-chain security.
- Relevant certifications: CISSP, CISM, CISA, CEH, ITIL, CCNP, JNCIA, ISO Lead Auditor, or similar.
- Prior experience supporting continuity planning, technical operations centers, or enterprise response teams.