
Information Systems Security Manager (ISSM)
San Francisco, CA at a glance
- Rent
- #2 of 51$2,680/mo+46% vs US avg
- Weather
- #17 of 51295 mild days0 hot · 0 cold
- Income tax
- #1 of 5113.3% top rateCalifornia
What you need
- Active TS/SCI clearance with SCI eligibility
- 8+ yrs ISSM experience in classified/SCIF environments
- Bachelor's degree or equivalent experience
- Expertise in RMF, NISPOM, ICD 503/705, NIST
- CompTIA Security+ certification (DoD 8140)
What you'll do
- Lead ISSM program per NISPOM/ICDs
- Oversee RMF lifecycle for classified systems
- Manage continuous monitoring, vulnerability assessments, POA&Ms
- Develop/execute incident response for classified environments
- Lead DCSA/IC inspections and compliance validation
Astranis builds advanced satellites for high orbits, expanding humanity’s reach into the solar system. Today Astranis satellites provide dedicated, secure networks to highly-sophisticated customers across the globe – large enterprises, sovereign governments, and the US military.
With five satellites on orbit and many more set to launch soon, the company is servicing a backlog of more than $1 billion of commercial contracts. Astranis is the preferred satellite communications partner for buyers with stringent requirements for uptime, data security, network visibility, and customization.
Astranis has raised over $1.2 billion from some of the world’s best investors, including Andreessen Horowitz, Baillie Gifford, Blackrock, Fidelity, Franklin Templeton, and Snowpoint, and employs a team of 500 engineers and entrepreneurs. Astranis designs, builds, and operates its satellites out of its 153,000 sq. ft. headquarters in Northern California, USA.
Information Systems Security Manager (ISSM)
The Information Systems Security Manager (ISSM) is responsible for leading the development, implementation, and oversight of Risk Management Framework (RMF), Information Security, and information assurance programs supporting classified and unclassified systems across collateral and Sensitive Compartmented Information Facility (SCIF) environments. This role ensures compliance with 32 CFR Part 117 (NISPOM) and applicable Intelligence Community Directives (ICDs), safeguarding national security information while enabling mission success.
The ISSM serves as the principal advisor on all classified information system security matters and collaborates closely with government customers, security leadership, and technical teams to maintain secure, compliant, and inspection-ready environments.
Working in coordination with the Chief Security Officer, the ISSM implements enterprise common controls and represents the organization with U.S. Government accrediting authorities, including Authorizing Officials (AOs) and Security Control Assessors (SCAs). The ISSM ensures a strong operational security posture across local area networks (LANs), wide area networks (WANs), and standalone systems through proactive risk management and continuous monitoring.
Role
-
Program Leadership, Compliance & RMF
- Lead and manage the Information System Security Program in accordance with NISPOM and applicable ICDs (e.g., ICD 503, ICD 705).
- Serve as principal advisor on all classified systems security matters.
- Oversee RMF lifecycle activities, including system categorization, control implementation, assessment, authorization, and continuous monitoring.
- Ensure systems meet classified processing requirements and maintain proper accreditation status.
- Develop, review, and maintain System Security Plans (SSPs), policies, procedures (SPPs), and supporting artifacts.
- Represent the organization with accrediting authorities; review and approve authorization packages.
- Interface directly with Security Control Assessors (SCAs) to demonstrate compliance during assessments.
System Security & Continuous Monitoring
- Manage continuous monitoring programs, including vulnerability assessments, POA&M tracking, and audit reviews.
- Analyze SIEM outputs and audit logs to identify anomalous or unauthorized activity.
- Conduct self-assessments and implement corrective actions to address vulnerabilities and compliance gaps.
- Maintain accurate system documentation, including SSPs, POA&Ms, and risk assessment reports.
- Ensure configuration management, patching, and system hardening in alignment with STIG requirements.
Network, Operations & Incident Response
- Oversee the cybersecurity posture of LANs, WANs, and standalone systems.
- Monitor systems to detect threats, vulnerabilities, and operational risks.
- Manage COMSEC, media control, and data spill response procedures across classified environments.
- Develop and execute incident response processes for spills, malware, and insider threat activities.
- Investigate, document, and report incidents in accordance with government requirements.
- Assess the security impact of system changes and support formal change management processes.
Inspections, Training & Governance
- Lead and support inspections, audits, and assessments conducted by DCSA and Intelligence Community stakeholders.
- Engage directly with government representatives to validate compliance with technical and policy requirements.
- Review and implement security advisories, directives, and emerging requirements.
- Deliver security education and awareness training to users, administrators, and leadership.
- Develop and enforce classified system policies, procedures, and standard operating procedures (SOPs).
- Communicate security responsibilities clearly across all organizational levels.
Requirements
- Active U.S. Government Top Secret clearance with SCI eligibility.
- Bachelor’s degree in a related field or equivalent experience.
- 8+ years of experience in ISSM roles supporting classified systems in collateral and SCIF environments.
- Demonstrated experience with eMASS and participation in DCSA assessments.
- Current CompTIA Security+ (or equivalent) certification in compliance with DoD Directive 8140.
- Strong expertise in RMF and working knowledge of NISPOM, ICD 503, ICD 705, and NIST standards.
- Experience with vulnerability scanning tools (e.g., ACAS), SIEM platforms, and STIG implementation across Windows and Linux systems.
- Proven leadership, communication, and stakeholder engagement skills.
- Preferred certifications: CISSP, CISM, or CAP.
Base pay is just one component of Astranis’s total rewards package. Your compensation also includes a significant equity package via incentive stock options, high-quality company-subsidized healthcare, disability and life insurance, 401(k) retirement planning, flexible PTO, and free on-site catered meals.
Astranis SMS Terms of Service
-
Recruiting Updates: By opting in, you agree to receive SMS updates, interview coordination, and recruiting communications from Astranis Space Technologies Corp.
-
Opt-Out: You can cancel this service at any time by replying STOP. We will send one final text confirming your unsubscription.
-
Opt-In Again: To resume receiving messages, reply START or YES.
-
Support & Rates: For assistance, reply HELP or contact us at [email protected]. Message and data rates may apply. Message frequency varies; carriers are not liable for delayed or undelivered messages.
-
Privacy: For details on how we protect your data, view our Privacy Policy.
Optimize your resume for this job
Get a match score and the keywords you're missing
About Astranis
Astranis is a space startup that builds small and low-cost telecommunications satellites to provide internet access in remote regions.
Similar Security roles


