Information System Security Manager positions focus on delivering results in their domain. This page aggregates open Information System Security Manager roles and what employers typically expect.
About Firefly Aerospace Firefly Aerospace is a space and defense technology company on a mission to reliably and repeatedly launch, land, and operate space systems from Earth to the Moon and beyond. As the partner of choice for critical space missions, Firefly is the first commercial company to launch a satellite to orbit with 24-hour notice and the first company to achieve a successful Moon landing. Headquartered in north Austin, Texas, Firefly is looking for passionate, hardworking innovators to join our team and help fuel our successful trajectory into space. SUMMARY As the Information System Security Manager at Firefly Aerospace, you will play a critical role in ensuring all mission-critical systems and enterprise networks maintain rigorous compliance with national security and corporate mandates. This role operates at the critical intersection of cybersecurity policy and system engineering, focusing heavily on translating CNSSP-12 requirements into actionable engineering architectures. You will lead the information assurance strategy, manage the Risk Management Framework (RMF) life cycle per NIST SP 800-37 Rev. 2, and drive continuous compliance for corporate standards including CMMC and NIST SP 800-171. This position offers the opportunity to architect security compliance for advanced space systems and corporate infrastructure. You will report directly to Director of Cybersecurity and collaborate closely with security leaderships, systems engineers, and operations teams to embed security into the development life cycle and ensure our systems achieve and maintain full authorization. RESPONSIBILITIES Space Systems Engineering: CNSSP-12 Compliance Translate complex CNSSP 12 (National Information Assurance Policy for Space Systems) mandates into measurable system engineering requirements and architectural constraints. � Coordinate directly with system owners, space vehicle engineers, and DevOps teams to embed security controls into the system development life cycle (SDLC). � Lead the design and oversee the implementation of secure network architectures for ground and space segments. � Conduct security impact assessments, threat modeling, and risk assessments on proposed space vehicle architectures and system changes. Risk Management Framework (RMF) Accreditation � Manage the full system life cycle accreditation processes under NIST SP 800-37 Rev. 2, driving systems through the RMF to secure Authorities to Operate (ATO). � Develop and maintain critical accreditation documentation, including System Security Plans (SSPs), POAMs, and Security Assessment Reports (SARs). � Provide regular status reports, continuous monitoring metrics, and compliance briefings to senior management and government Authorizing Officials (AOs). � Ensure system configurations continuously comply with DISA STIGs and DoD Security Technical Implementation Guides. Corporate Compliance; Security Operations � Lead and manage the corporate-wide cybersecurity compliance initiatives, ensuring strict adherence to NIST SP 800-171, NIST SP 800-53 and Space Policy Directive 5 (SPD � 5) across enterprise. � Manage a diverse, multi-location Information Assurance team, setting goals, driving accountability, and mentoring security personnel. � Support incident response activities, ensure timely reporting to government stakeholders (e.g., DCSA), and lead tabletop exercises to evaluate and improve cross- functional readiness. � Oversee red-teaming and penetration testing activities to uncover vulnerabilities and ensure network resilience. QUALIFICATIONS Required: � BS or MS degree in Computer Science, Cybersecurity, Information Technology, or a related technical discipline. Equivalent experience may be considered. Proven ability to translate high-level policies (such as CNSSP-12) into technical engineering requirements. � At least 10 years of experience in information assurance, cybersecurity compliance, or risk management within the aerospace, federal, or DoD contractin…