The IT Manager – Secure Mission Environments is responsible for planning, implementing, and maintaining secure IT systems that operate within regulated defense and government contracting environments. The role bridges day-to-day IT operations with compliance program obligations under CMMC, NIST SP 800-171, RMF, and CUI handling requirements. The incumbent will serve as the primary point of accountability for software asset management, system security, and regulatory readiness across enclave environments.
IT Operations & Software Asset Management
- Direct personnel management (4 FTEs)
- Timecard management & direct charge compliance
- Coordinate with vendors and internal stakeholders for enclave management duties
- Hands-on System Administration duties as needed to cover for vacancies, PTO, etc.
- CUI & Classified Enclave Oversight
CMMC & NIST SP 800-171 Compliance
- Maintain and continuously improve the System Security Plan (SSP) in alignment with NIST SP 800-171 Rev 2/3 and CMMC Level 2/3 practices
- Track and remediate Plan of Action & Milestones (POA&M) items, ensuring timely closure prior to assessment windows
- Coordinate with the Assessor Organization (C3PAO or government assessor) for CMMC assessments; prepare evidence packages and conduct readiness reviews
- Implement access control, media protection, audit & accountability, and configuration management controls per CMMC practice families
- Conduct periodic self-assessments and gap analyses; maintain the SPRS score submission
CUI Program Management
- Define, document, and enforce CUI category boundaries across all IT systems, shared drives, collaboration platforms, and cloud environments
- Implement and audit CUI marking, handling, transmission, and destruction procedures in accordance with 32 CFR Part 2002 and NIST SP 800-171
- Train staff on CUI identification and handling requirements; track training completion
- Investigate and report CUI spillage incidents; coordinate with the FSO and program security officers as required
- Maintain a CUI registry and ensure systems processing CUI are covered by active ATOs or equivalent authorization
Risk Management Framework (RMF)
- Lead or support RMF authorization activities (categorization, selection, implementation, assessment, authorization, monitoring) for IT systems operating under DoD/Federal oversight
- Maintain security authorization packages (SSP, SAR, POA&M, ATO artifacts) and ensure continuous monitoring obligations are met
- Coordinate with ISSOs, ISSMs, and AOs to manage system risk posture and residual risk acceptance decisions
- Integrate RMF activities with the broader corporate IT roadmap
- Produce and deliver Security Assessment Reports (SARs) and Control Implementation Summaries (CIS) for government review
IT Security & Infrastructure
- Manage endpoint security, patch management, and vulnerability remediation across classified and unclassified enterprise environments
- Oversee identity and access management (IAM) policies, including MFA, least-privilege enforcement, and periodic access reviews
- Administer network segmentation between CUI-scoped and non-CUI environments; enforce boundary protection controls
- Coordinate incident response activities; maintain and test the Incident Response Plan (IRP)
- Evaluate and implement security tools, SIEM integrations, and automated compliance monitoring capabilities
Stakeholder Engagement & Leadership
- Act as the primary IT compliance liaison to DCSA, government program offices, prime contractors, and corporate leadership
- Brief leadership on compliance posture, risk exposure, and program impacts on a regular cadence
- Lead local cross-functional coordination between IT, Engineering, Finance, Legal, and Program Management on compliance-impacting decisions
- Mentor junior IT staff on security practices, tool administration, and compliance requirements
#CJ3