Description
Overview
Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.
The Sea, Land, Air Analysis Group's mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, US Air Force, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.
SPA has an immediate need for an Information Systems Security Manager.
Responsibilities
The Systems Security Manager position is responsible for leading Risk Management Framework (RMF) lifecycle activities from initial system categorization through achieving an Authority to Operate (ATO). The selected candidate will develop and maintain comprehensive authorization packages and coordinate closely with Security Control Assessor (SCA) and Authorizing Official (AO) representatives to adjudicate findings and manage risk. Additional responsibilities include preparing systems for ATO, Interim Authorization to Test (IATT), and continuous authorization; ensuring the implementation and validation of security controls in accordance with the Joint Special Access Program Implementation Guide (JSIG) and National Institute of Standards and Technology (NIST) Special Publication 800‑53. The Systems Security Manager will track and remediate Plans of Action and Milestones (POA&Ms), conduct internal compliance assessments and inspection preparation, assess technical risk and provide written recommendations to Government cybersecurity leadership, and ensure configuration management and baseline integrity. The role also includes delivering cybersecurity briefings to senior leadership and maintaining effective relationships with external stakeholders to support secure and mission‑ready system operations.
Qualifications
Required Qualifications:
- Reports to Joint Base Anacostia-Bolling, up to full-time, based upon the needs of the client
- Master's Degree in Cybersecurity, Information Technology, Engineering, or related field (or equivalent experience)
- 7+ years cybersecurity experience in DoD classified environments. (SAP/SCI) and 3+ years experience as ISSM or equivalent senior cybersecurity lead
- Deep familiarity with: JSIG, RMF (DoDI 8510.01), ICD 503, NIST 800-53 and DoD 8570/8140 IAT Level III or IAM Level II/III certification
- Strong written and verbal communication skills with experience preparing presentation materials for leadership audiences
- Experience working directly with Authorizing Officials and SCAs and Experience in multi-system portfolio management
- Active TS/SCI and the ability to maintain it throughout employment
Desired Qualifications:
- Certified Information Systems Security Professional (CISSP) Certification.
Pay Range Information
At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Washington, DC, Pay Transparency Salary range: USD $160,000.00/Yr. - USD $180,000.00/Yr.
Qualifications
Required Qualifications:
- Reports to Joint Base Anacostia-Bolling, up to full-time, based upon the needs of the client
- Master's Degree in Cybersecurity, Information Technology, Engineering, or related field (or equivalent experience)
- 7+ years cybersecurity experience in DoD classified environments. (SAP/SCI) and 3+ years experience as ISSM or equivalent senior cybersecurity lead
- Deep familiarity with: JSIG, RMF (DoDI 8510.01), ICD 503, NIST 800-53 and DoD 8570/8140 IAT Level III or IAM Level II/III certification
- Strong written and verbal communication skills with experience preparing presentation materials for leadership audiences
- Experience working directly with Authorizing Officials and SCAs and Experience in multi-system portfolio management
- Active TS/SCI and the ability to maintain it throughout employment
Desired Qualifications:
- Certified Information Systems Security Professional (CISSP) Certification.
Responsibilities
The Systems Security Manager position is responsible for leading Risk Management Framework (RMF) lifecycle activities from initial system categorization through achieving an Authority to Operate (ATO). The selected candidate will develop and maintain comprehensive authorization packages and coordinate closely with Security Control Assessor (SCA) and Authorizing Official (AO) representatives to adjudicate findings and manage risk. Additional responsibilities include preparing systems for ATO, Interim Authorization to Test (IATT), and continuous authorization; ensuring the implementation and validation of security controls in accordance with the Joint Special Access Program Implementation Guide (JSIG) and National Institute of Standards and Technology (NIST) Special Publication 800‑53. The Systems Security Manager will track and remediate Plans of Action and Milestones (POA&Ms), conduct internal compliance assessments and inspection preparation, assess technical risk and provide written recommendations to Government cybersecurity leadership, and ensure configuration management and baseline integrity. The role also includes delivering cybersecurity briefings to senior leadership and maintaining effective relationships with external stakeholders to support secure and mission‑ready system operations.
Apply on company website