Description
Overview
Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.
The Sea, Land, Air Analysis Group's mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, USAF, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.
SPA has a need for an Information Systems Security Manager to lead cybersecurity and Risk Management Framework activities for APACS and related systems. This role is responsible for maintaining authorizations to operate and protecting sensitive data.
Responsibilities
The ISSM oversees RMF compliance, eMASS packages, and all cybersecurity documentation for assigned systems. They coordinate with government security officials, system owners, and engineers to address vulnerabilities, manage plans of action and milestones, and support audits. They advise on security architecture and design decisions, ensuring controls are correctly implemented and tested. They also provide guidance and training to team members on cybersecurity policies and best practices.
Qualifications
Required Qualifications:
- 8+ years of experience in cybersecurity, with substantial time as an ISSM or comparable lead for DoD information systems
- Deep familiarity with RMF, eMASS, STIGs, and vulnerability management processes
- Relevant security certification (e.g., CISSP, CAP, CISM)
- Active TS/SCI clearance
Desired Qualifications:
- Experience securing IL4/IL5/IL6 and SIPRNet systems
- Background working with large user‑facing applications containing PII or other sensitive data
Pay Range Information
At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $130,000.00/Yr. - USD $170,000.00/Yr.
Qualifications
Required Qualifications:
- 8+ years of experience in cybersecurity, with substantial time as an ISSM or comparable lead for DoD information systems
- Deep familiarity with RMF, eMASS, STIGs, and vulnerability management processes
- Relevant security certification (e.g., CISSP, CAP, CISM)
- Active TS/SCI clearance
Desired Qualifications:
- Experience securing IL4/IL5/IL6 and SIPRNet systems
- Background working with large user‑facing applications containing PII or other sensitive data
Responsibilities
The ISSM oversees RMF compliance, eMASS packages, and all cybersecurity documentation for assigned systems. They coordinate with government security officials, system owners, and engineers to address vulnerabilities, manage plans of action and milestones, and support audits. They advise on security architecture and design decisions, ensuring controls are correctly implemented and tested. They also provide guidance and training to team members on cybersecurity policies and best practices.
Apply on company website