Information Systems Security Manager

Posted Yesterday
Be an Early Applicant
Houston, TX, USA
In-Office
Senior level
Aerospace • Greentech • Energy
The Role
Manage security for classified information systems across their full lifecycle, including accreditation, security controls, SSPs, RMF activities, vulnerability remediation, audits, incident response, insider threat coordination, COMSEC, and TEMPEST/EMSEC compliance. Lead security professionals, coordinate with government agencies, conduct training and self-inspections, and ensure systems meet NIST, DoD, SCI, and related regulatory requirements.
Summary Generated by Built In

Information Systems Security Manager

Houston, TX

About Intuitive Machines:

Intuitive Machines is an innovative and cutting-edge space company making cislunar space accessible to both public and private customers. Our mission is to further science and exploration, communications, and economic progress from the Earth to the Moon and beyond. With multiple NASA lunar missions in development and additional private missions on our manifest, we pride ourselves in supporting NASA, our customers, and the nation in paving the way to return humans to the surface of the Moon. Our world-class team includes experts in all aspects of spacecraft subsystems design, development, and test, on-orbit operations, and safety.

About the Position:

We are currently seeking an Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM). This role is based in our Houston, TX office. In this role, you will be responsible for a portfolio of classified programs covering Collateral, Sensitive Compartmented Information (SCI). You will support information system full life cycle activities including scoping information systems for new programs, preparing accreditation/certification packages in accordance with relevant regulations and standards, maintenance and monitoring of operational systems, system upgrades and feature additions during program execution, and system decommission and de-certification activities.

Responsibilities:

  • Responsible for ensuring Information System compliance with the potential to span multiple business areas or programs.
  • Ensure system security measures comply with applicable government policies. Provide configuration management and accurately assess the impact of modifications and vulnerabilities for each system.
  • Maintain a thorough understanding of NIST 800-53 controls, and determine which controls are applicable to the application, as well as document implementation in Security Controls Tractability Matrix (SCTM).
  • Monitor and resolve Plan of Action and Milestones (POA&M) to mitigate system vulnerabilities on assigned Information Systems.
  • Communicate and coordinate Information Systems Security policy across their organization and work with government agencies to obtain rulings, interpretations, and acceptable deviations for compliance with regulations.
  • Establish, document, implement, and monitor the IS Security Program and related procedures for the facility and ensure compliance with IS security requirements.
  • Prepare and maintain Systems Security Plans (SSP) which accurately reflect the installation and security provisions of the system.
  • Ensure that each SSP has been implemented, that the specified security controls are in place and properly tested, and that the IS is functioning as described in the SSP.
  • Evaluate proposed changes or additions to the SSP and collaborate with customers for systems approvals.
  • Conduct on-going security reviews and tests for information systems to periodically verify that security features and operating controls are functional and effective.
  • Ensure that periodic self-inspections of the facility’s IS Program are conducted as part of the overall facility self-inspection program.
  • Ensure the development, documentation and presentation of IS security education, awareness, and training activities for facility management, IS personnel, users, and others as appropriate.
  • Ensure personnel are trained on the IS’s prescribed security restrictions and safeguards before they are initially allowed to access a system.
  • Responsible for reporting compliance metrics to government CSA, Program Management, and Information System Owner.
  • Manage, lead and provide security guidance and mentoring to a team of security professionals
  • Oversee and coordinate insider threat program activities for assigned information systems in collaboration with the Insider Threat Program Manager.
  • Ensure proper media sanitization, destruction, and accountability procedures are followed for classified storage devices and system components throughout the system lifecycle and during decommissioning activities.
  • Coordinate security incident response activities for assigned systems, including timely reporting to appropriate government agencies (DCSA, NSA, etc.) and internal stakeholders.
  • Oversee physical security integration with IS security requirements, ensuring proper coordination with facility security personnel.
  • Manage COMSEC material accountability and cryptographic key management for assigned systems as applicable.
  • Ensure compliance with TEMPEST/EMSEC requirements for SCI-level systems as applicable

Requirements:

  • Must be a U.S. citizen with Active TS/SCI clearance and CI Poly
  • Experience as an ISSM/ISSO implementing NISPOM Chapter 8, ICD 503, and/or JSIG IS requirements in an SAP/SCI environment
  • CISSP and CISM certifications
  • Ability to obtain GSLC certification within 6 months of hire
  • Bachelor of Science degree
  • 8 years of related IT security experience
  • Minimum of 2 years related IT or security experience in a classified (SCI) environment
  • Hands-on experience with SIEM tools (Splunk, Elastic, or similar) for log analysis and security event correlation
  • Knowledge of Information Security or Information technology standards
  • Experience with Risk Management Framework (RMF) including participation in assessment and authorization activities
  • Experience conducting security audits and vulnerability assessments in operational classified systems
  • Department of Defense Directive (DoDD) 8140 / 8570 Certification requirements (CompTIA Security+ CE or equivalent certification)
  • Experience coordinating with government assessment teams (DCSA, NSA, Program Security Officers)

Preferred Requirements: 

  • Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, ICD, DoD, or other Government Regulatory compliance standards within a professional industry
  • Experience with Information Security tools including audit reduction, vulnerability management, change detection, network monitoring, etc. (ACAS, Nessus, HBSS, SPLUNK, RedSeal, Tripwire, DISA SCC and STIG Viewer)
  • Experience developing IS security plans, policy and procedures for Local Area Network (LAN) Information Systems and Wide Area Network (WAN) Information systems
  • Experience with both Windows and Linux operating environments
  • Previous leadership experience
  • Experience managing security incidents and coordinating response activities in classified environments
  • Knowledge of DevSecOps practices and secure software development lifecycle in classified systems
  • Experience with insider threat detection tools and procedures

US EEO Statement:

Intuitive Machines is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.

Skills Required

  • U.S. citizenship
  • Active TS/SCI clearance and CI Polygraph
  • Experience as an ISSM or ISSO implementing NISPOM Chapter 8, ICD 503, and/or JSIG requirements in an SAP/SCI environment
  • CISSP certification
  • CISM certification
  • Ability to obtain GSLC certification within six months of hire
  • Bachelor of Science degree
  • Eight years of related IT security experience
  • At least two years of related IT or security experience in a classified SCI environment
  • Hands-on experience with SIEM tools such as Splunk or Elastic for log analysis and security event correlation
  • Knowledge of information security or information technology standards
  • Experience with RMF, including assessment and authorization activities
  • Experience conducting security audits and vulnerability assessments in operational classified systems
  • DoD Directive 8140/8570 certification, such as CompTIA Security+ CE or equivalent
  • Experience coordinating with government assessment teams, including DCSA, NSA, and Program Security Officers
  • Familiarity with NIST, CNSSI, ICD, DoD, and other government regulatory compliance standards
  • Experience with information security tools including ACAS, Nessus, HBSS, Splunk, RedSeal, Tripwire, DISA SCC, and STIG Viewer
  • Experience developing security plans, policies, and procedures for LAN and WAN information systems
  • Experience with Windows and Linux operating environments
  • Previous leadership experience
  • Experience managing security incidents and coordinating response activities in classified environments
  • Knowledge of DevSecOps and secure software development lifecycle practices in classified systems
  • Experience with insider threat detection tools and procedures
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Houston, TX
128 Employees
Year Founded: 2013

What We Do

Intuitive Machines' complete lunar program unlocks the lunar economy to explore the solar system further and gain knowledge for the progress of humanity. As the premier provider of space services and technologies, Intuitive Machines is reestablishing the United States' dominance on the ultimate high ground, the Moon. Designed by the greatest minds in spaceflight, IM's lunar program will send the first American spacecraft to the surface of the Moon since the Apollo program and send the first spacecraft ever to reach the lunar south pole.

Similar Jobs

In-Office
Cedar Park, TX, USA
384 Employees

General Motors Logo General Motors

Engineering Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees

General Motors Logo General Motors

Controls Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
Arlington, TX, USA
165000 Employees

General Motors Logo General Motors

Senior Machine Learning Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
3 Locations
165000 Employees
171K-261K Annually

Similar Companies Hiring

Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account