OverviewSystems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter . Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.
The Sea, Land, Air Analysis Group's mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, USAF, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.
SPA has a need for an Information System Security Manager (ISSM), who will serve as the overall cybersecurity lead for the systems and environments delivered under this contract. This individual will own RMF execution, accreditation package development, and coordination with government security stakeholders. The ISSM will be responsible for defining and enforcing cybersecurity and cyber-resiliency practices that are integrated into development, integration, and test activities across the Mission Planning Enterprise. #FC #Dice
Responsibilities The ISSM is responsible for the overall cybersecurity posture, compliance, and accreditation of systems delivered under this contract. They lead Risk Management Framework (RMF) activities, maintain security documentation and artifacts, and coordinate with government security officials on security testing, ATO/ATC actions, and policy compliance. The ISSM defines and enforces cybersecurity and cyber-resiliency practices across the development and integration lifecycle, including secure coding standards, vulnerability management, and security training. They work closely with engineering, test, and platform operations to embed security controls into architectures, pipelines, and test environments, ensuring that cybersecurity is a first-class aspect of the Mission Planning Enterprise.
QualificationsRequired Qualifications:
- BS in cybersecurity, computer science, information assurance, or similar field plus 8+ years of cybersecurity experience on medium-to-large IT or software programs, including at least 4 years in an ISSM or equivalent leadership role
- Direct experience implementing DoD RMF (and prior DIACAP) processes, including authoring and maintaining accreditation packages and FISMA-related records
- Demonstrated experience leading or supporting DISA STIG compliance, vulnerability scanning, penetration testing, and testing in NIPR/SIPR and related environments
- Familiarity with mission planning or similar weapon-system security contexts, including support for ATO and ATC activities and security targets
- DoD-approved cybersecurity certification such as CISSP, CAP, or CISM
- Active DoD Secret clearance (or higher) and the ability to maintain it throughout employment
Desired Qualifications:
- Master's degree in relevant field plus experience developing and maintaining enterprise cybersecurity master plans, Program Protection Plans, anti-tamper plans, and related security documentation
- Familiarity with Air Force cybersecurity policy and coordination with AF network and accreditation authorities
- Background in cyber resiliency for mission or weapon systems, including secure coding standards, security-focused scenarios, and user certification requirements
- Experience integrating security controls into DevSecOps pipelines and CDE environments, including automated compliance and security testing
- Prior experience addressing security considerations for FMS deliveries and multi-national information-sharing constraints
Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Massachusetts, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $215,000.00/Yr.