Firefly Aerospace Logo

Firefly Aerospace

Information Systems Security Manager

Posted 14 Days Ago
Be an Early Applicant
In-Office
Cedar Park, TX, USA
Expert/Leader
In-Office
Cedar Park, TX, USA
Expert/Leader
Lead information assurance for space and enterprise systems, map CNSSP-12 into engineering requirements, manage RMF (NIST SP 800-37) accreditation to obtain ATOs, enforce NIST/CMMC/STIG compliance, run risk assessments, oversee compliance teams, incident response, and red-team/testing to ensure secure architectures for ground and space segments.
The summary above was generated by AI

About Firefly Aerospace

Firefly Aerospace is a space and defense technology company on a mission to reliably and repeatedly launch, land, and operate space systems from Earth to the Moon and beyond. As the partner of choice for critical space missions, Firefly is the first commercial company to launch a satellite to orbit with 24-hour notice and the first company to achieve a successful Moon landing. Headquartered in north Austin, Texas, Firefly is looking for passionate, hardworking innovators to join our team and help fuel our successful trajectory into space.

SUMMARY

As the Information System Security Manager at Firefly Aerospace, you will play a critical role in ensuring all mission-critical systems and enterprise networks maintain rigorous compliance with national security and corporate mandates. This role operates at the critical intersection of cybersecurity policy and system engineering, focusing heavily on translating CNSSP-12 requirements into actionable engineering architectures. You will lead the information assurance strategy, manage the Risk Management Framework (RMF) life cycle per NIST SP 800-37 Rev. 2, and drive continuous compliance for corporate standards including CMMC and NIST SP 800-171. This position offers the opportunity to architect security compliance for advanced space systems and corporate infrastructure. You will report directly to Director of Cybersecurity and collaborate closely with security leaderships, systems engineers, and operations teams to embed security into the development life cycle and ensure our systems achieve and maintain full authorization.

RESPONSIBILITIES

Space Systems Engineering: CNSSP-12 Compliance

Translate complex CNSSP 12 (National Information Assurance Policy for Space Systems) mandates into measurable system engineering requirements and architectural constraints.

· Coordinate directly with system owners, space vehicle engineers, and DevOps teams to

embed security controls into the system development life cycle (SDLC).

· Lead the design and oversee the implementation of secure network architectures for

ground and space segments.

· Conduct security impact assessments, threat modeling, and risk assessments on

proposed space vehicle architectures and system changes.

Risk Management Framework (RMF) Accreditation

· Manage the full system life cycle accreditation processes under NIST SP 800-37 Rev. 2,

driving systems through the RMF to secure Authorities to Operate (ATO).

· Develop and maintain critical accreditation documentation, including System Security

Plans (SSPs), POAMs, and Security Assessment Reports (SARs).

· Provide regular status reports, continuous monitoring metrics, and compliance

briefings to senior management and government Authorizing Officials (AOs).

· Ensure system configurations continuously comply with DISA STIGs and DoD Security

Technical Implementation Guides.

Corporate Compliance; Security Operations

· Lead and manage the corporate-wide cybersecurity compliance initiatives, ensuring

strict adherence to NIST SP 800-171, NIST SP 800-53 and Space Policy Directive 5 (SPD – 5) across enterprise.

· Manage a diverse, multi-location Information Assurance team, setting goals, driving

accountability, and mentoring security personnel.

· Support incident response activities, ensure timely reporting to government

stakeholders (e.g., DCSA), and lead tabletop exercises to evaluate and improve cross-

functional readiness.

· Oversee red-teaming and penetration testing activities to uncover vulnerabilities and

ensure network resilience.

QUALIFICATIONS

Required:

· BS or MS degree in Computer Science, Cybersecurity, Information Technology, or a

related technical discipline. Equivalent experience may be considered.

  • Proven ability to translate high-level policies (such as CNSSP-12) into technical engineering requirements.

· At least 10 years of experience in information assurance, cybersecurity compliance, or

risk management within the aerospace, federal, or DoD contracting environment.

· Demonstrated expertise in applying NIST SP 800-37 Rev. 2 (RMF), Space Policy Directive 5 (SPD – 5), NIST SP 800-171, NIST SP 800-53, and FISMA standards.

· Hands-on experience with DoD security tools (e.g., eMASS, ACAS, HBSS, SPRS).

· Exceptional leadership and communication skills to effectively interface with technical

and non-technical executive stakeholders.

Desired:

· Direct experience acting as an ISSM or Security Control Assessor (SCA) for space-based systems.

· Familiarity with satellite telemetry, tracking, and commanding (TT&C) encryption and security requirements.

· Hands-on experience executing a CMMC Level 2 implementation.

· Active clearance or ability to obtain and maintain clearance.

· Experience with requirements management platforms (e.g., Jama, DOORS) used in systems engineering.

Firefly offers outstanding benefits for our employees, including generous health, dental and vision plans with low plan deductibles, parental leave, educational reimbursement, short term disability, and flexible PTO options.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Firefly Aerospace, Inc. is an Equal Opportunity Employer; employment with Firefly is governed based on merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

HQ

Firefly Aerospace Cedar Park, Texas, USA Office

Cedar Park, TX, United States

Similar Jobs

4 Days Ago
In-Office
108K-205K Annually
Senior level
108K-205K Annually
Senior level
Aerospace • Defense
Oversee cybersecurity compliance, assessment, authorization, and operations for classified information systems across one or more programs. Manage RMF and DCSA requirements, continuous monitoring, POA&M development, system security sustainment, self-inspections, training, vulnerability mitigation, incident response support, and security reviews. Coordinate with government assessors, internal stakeholders, IT teams, security organizations, and program managers while maintaining site-level accountability for system metrics, authorizations, and cybersecurity controls.
Top Skills: AcasDcsa DaapmDod 8140/8570EmassForcepointHbssIvantiJsigNispomNist Special PublicationsRcastRisk Management Framework (Rmf)SIEMSplunkTenable
4 Days Ago
In-Office
108K-205K Annually
Senior level
108K-205K Annually
Senior level
Aerospace • Defense
Oversee cybersecurity compliance, assessment, authorization, and continuous monitoring for classified information systems across one or more programs. The ISSM manages RMF and DCSA requirements, POA&Ms, system security sustainment, self-inspections, incident investigations, security training, vulnerability mitigation, and customer or government engagements. This role coordinates with system stakeholders, security officials, IT teams, and assessment representatives while maintaining accountability for site systems and required cybersecurity metrics.
Top Skills: AcasClassified Information SystemsDcid 6/3Dcsa DaapmDodd 8140/8570EmassForcepointHbssIcd-503Iso 9001IvantiJafan 6/3JsigNispomNist Special PublicationsPciRcastRisk Management Framework (Rmf)SIEMSplunkTenable
12 Days Ago
In-Office
Austin, TX, USA
130K-150K Annually
Mid level
130K-150K Annually
Mid level
Aerospace • Professional Services • Defense
Manage enterprise information security strategy, incident response, forensic investigations, threat hunting, SIEM optimization, patch management, DLP, continuous monitoring, and risk mitigation. Implement Microsoft Intune, Sentinel, Defender, Splunk, and automated security solutions. Develop IT roadmaps, enforce NIST, FISMA, HIPAA, PCI, CUI, and ITAR compliance, and support FedRAMP technology integration. Produce executive-level security reporting and oversee enterprise security posture improvements.
Top Skills: DlpDod EmassFedrampKustoMicrosoft DefenderMicrosoft Defender For CloudMicrosoft IntuneMicrosoft SentinelSIEMSplunkStig ViewerWindows Automatic Update

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account