Kranze Technology Solutions, Inc logo

Information Systems Security Manager

Kranze Technology Solutions, Inc

Des Plaines, ILFull-time$100–150K/yrPosted 4mo agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$100–150K/yr
Location
Des Plaines, IL
Schedule
Full-time
Work Authorization
US work authorization required

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Security clearanceBachelor's degree

Job overview

Kranze Technology Solutions, Inc is hiring an Information Systems Security Manager. The Information System Security Manager (ISSM) applies and documents Information System (IS) security principles, practices, and procedures under the Risk Management Framework (RMF) to maintain compliance with applicable security regulations. This role involves governing the development and management of classified information systems, integrating security into front-end requirements, and overseeing the implementation and sustainment of security controls throughout the program lifecycle.

Key focus areas include Achieve and maintain Authorization to Operate for classified information systems, Manages Risk Management Framework (RMF) process, and Leads and supports security assessments and audits.

Successful candidates bring Bachelor's Degree In Applicable Field, 5+ Years Experience, and Security Clearance. Important skills include Information System Security Principles, Information System Security Practices, Information System Security Procedures, Risk Management Framework, CNSSI, and NISPOM. Preferred (not required): NIST and Risk Assessment.

Skills & qualifications

RequiredNice to have

Skills

Information System Security PrinciplesInformation System Security PracticesInformation System Security ProceduresRisk Management FrameworkNISTCNSSINISPOMIntegrating Security Into Front-End RequirementsOverseeing Security Controls ImplementationOverseeing Security Controls SustainmentAchieve Authorization to OperateMaintain Authorization to OperateLead Security AssessmentsSupport Security AssessmentsLead Security AuditsSupport Security AuditsAudit Log ReviewsSecurity PatchingHardware/Software ConfigurationCMMC Compliance ProgramDoD Cybersecurity StandardsDevelop Information Security PoliciesDocument Information Security PoliciesGuide Implementation of Information Security PoliciesDevelop Information Security ProceduresDocument Information Security ProceduresDevelop Information Security ControlsDocument Information Security ControlsSSPPOAMAssess Security ControlsRefine Security ControlsManage Implementation of Security ControlsSecurity MetricsProvide Technical Guidance to IT TeamEvaluate Cybersecurity TechnologiesRecommend Cybersecurity TechnologiesEvaluate Cybersecurity Best PracticesRecommend Cybersecurity Best PracticesCOMSECPhysical SecurityDocument ControlInsider ThreatOPSECVisit RequestsRisk AssessmentStrong Written CommunicationStrong Verbal CommunicationMaintain Organized RecordsMaintain Complete Records

Qualifications

Bachelor's Degree in Applicable Field5+ Years Relevant ExperienceAbility to Obtain Security ClearanceUnited States Citizenship5+ Years Progressive Experience in Information SecuritySecurity+ CertifiedEquivalent Certification3+ Years Experience Assessing and Documenting Test or Analysis Data

Benefits

Paid Time Off
Medical Insurance
Vision Insurance
Dental Insurance
401(k) Match
Tuition Assistance

Full job description

The Information System Security Manager (ISSM) is responsible for applying and documenting Information System (IS) security principles, practices, and procedures under the Risk Management Framework (RMF) to maintain compliance with applicable security regulations such as NIST, CNSSI, and NISPOM as well as governing the development and management of classified information systems. This position requires the ISSM to be a strong advocate for integrating security into front-end requirements and overseeing the implementation and sustainment of security controls in all stages of the program lifecycle. This is not a hybrid or work from home position. It is a full-time onsite position at the office in Des Plaines, IL.

Responsibilities:

  • Achieve and maintain Authorization to Operate for classified information systems

  • Manages Risk Management Framework (RMF) process

  • Leads and supports security assessments and audits

  • Perform tasks to meet continuous monitoring requirements such as audit log reviews, security patching, and hardware/software configuration

  • Lead the organization's CMMC compliance program, ensuring alignment and adherence to DoD cybersecurity standards (NIST SP 800-171, etc.)

  • Develop, document, and guide the implementation of practical, actionable information security policies, procedures, and controls aligned with CMMC and NIST standards (SSP, POAM, etc.)

  • Continuously assess, refine, and manage the implementation of security controls across the enterprise architecture, using security metrics to drive improvements

  • Provide clear technical guidance to the IT team on the implementation and operation of security measures

  • Evaluate and recommend emerging cybersecurity technologies and best practices relevant to our environment

  • Support the Facility Security Officer in other security disciplines such as COMSEC, physical security, document control, Insider Threat, OPSEC, and visit requests

  • Perform other duties as assigned

Minimum Educational Qualifications & Requirements:

  • Bachelor's degree in an applicable field and at least five years of relevant experience

  • Preferred Security+ (or equivalent) certified

  • Ability to perform risk assessment and risk management for classified information systems

  • Ability to obtain Security Clearance, for which the United States Government requires United States citizenship

  • Strong written and verbal communication skills

  • Ability to maintain organized and complete records

  • Ability to prioritize competing demands and complete tasks on schedule

Minimum Previous Experience:

  • 5+ years of progressive experience in information security

  • Expertise in RMF and ATO processes

  • Previous experience with classified information system security management and administration

  • Proven ability to translate CMMC/NIST SP 800-171 requirements into documented, implementable procedures

  • Experience maturing a cybersecurity program, including developing processes and documentation

  • Strong background in defense contracts and classified information handling procedures.

  • Experience implementing and assessing systems using DISA STIGs for Windows and Linux operating system

  • Experience in implementing and monitoring technical, administrative, and operational security controls

Other Preferred Skills:

  • 3+ years of experience in assessing and documenting test or analysis data to show cybersecurity compliance to auditors

  • Experience with Microsoft Intune, Azure, Active Directory, Group Policy, and System Administration

  • Experience with submitting and managing accreditation packages to Enterprise Mission Assurance Support Service (eMASS)

  • Use of automated vulnerability and compliance scanning tools such as Security Content Automation Protocol (SCAP), Compliance Checker (SCC), Security Technical Implementation Guides (STIGs), and Nessus

  • Experience with SIPRNet installation, deployment, and management

We recognize that attracting the best talent is key to our strategy and success as a company. As a result, we aim for flexibility in structuring competitive compensation offers to ensure we are able to attract the best candidates. As required by law in this state, the estimated salary range for this position is $100,000-$150,000 and represents our good faith estimate as to what our ideal candidates are likely to expect. We tailor our offers within the range based on organizational needs, internal equity, market data, geographic zone, and the selected candidate’s experience, education, industry knowledge, location, technical and communication skills, and other factors that may prove relevant during the selection process.

Benefits

Kranze Technology Solutions is proud to provide extremely competitive benefits to all full time employees including:

  • Comprehensive Leave plan (Paid Time Off)

  • Comprehensive Health Care package including Medical, Vision, Dental, Health Savings Account (HSA), and more

  • 401 (k) retirement plan

  • Paid Overtime

  • Flex Time and Flexible Scheduling

  • Opportunities to travelTuition Reimbursement options

  • Casual and relaxed work environment

About Kranze Technology Solutions

We are part of an SPX Technologies’ Communication Technologies platform in the Detection & Measurement business segment. KTS is focused in the defense industry specializing in Infrared Countermeasures (IRCM) systems, digital interoperability and networking, and program support for the US Navy, US Marine Corps, and Special Operations Command. We provide hardware and software product development, systems integration, system test and evaluation support, modeling and simulation analysis, and other engineering services to support the Warfighter.

Each team member has significant opportunities to solve a variety of complex technical challenges in small teams while working hand in hand with our defense customers.

KTS is an equal opportunity employer and prohibits discrimination and harassment of any kind. All applicants will be considered for employment without regards to race, color, religion, age, sex, sexual orientation, gender identity, national origin, veteran or disability status, or any other segmenting characteristics protected by law.

If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to:

Human Resources

847-737-7299

[email protected]

Powered by JazzHR

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.