Security Programs Manager
Security Programs Manager
Responsible for leading and administering the Security Program across industrial, personnel, and physical security, classified information system security, CUI protection, cybersecurity compliance coordination, and security awareness.
This position serves as the appointed Facility Security Officer for the Chesapeake facility and Information System Security Manager for the Chesapeake classified information system.
This position provides functional security leadership and coordination to collateral security personnel by establishing corporate security expectations, coordinating required activities, supporting consistent execution, tracking compliance, and escalating unresolved security risks or gaps as appropriate.
The role partners closely with IT, HR, Contracts, Supply Chain, Operations, Quality, Program Management, external Security and Cyber partners and company leadership to ensure company protects classified information, controlled unclassified information, facilities, and systems in accordance with applicable regulatory, contractual, and company requirements.
Essential Responsibilities
Security Program Leadership
- · Lead the development, administration, and continuous improvement of the Company Security Program across industrial security, personnel security, physical security, classified information system security, CUI protection, security awareness, and related compliance activities.
- Establish security program priorities, procedures, compliance calendars, inspection readiness activities, corrective action tracking, and recurring security reporting.
- Serve as a primary security advisor to the Director, OD & Compliance, Senior Management Official, and Government Security Committee (GSC) on matters involving facility clearance, NISPOM compliance, FOCI mitigation, DCSA engagement, classified contract requirements, security risk, and overall security program health.
- Lead physical security program requirements including access control, badges, visitor procedures, end-of-day checks, secure storage, alarm/access logs, and facility security posture.
- Coordinate security responsibilities across company locations and functions, ensuring consistency, appropriate ownership, documentation, and follow-through.
- Support CUI protection and CMMC readiness from a security program governance perspective by helping coordinate requirements, evidence, corrective actions, POA&M visibility, risk reporting, and assessment readiness with IT, the MSP, the CMMC consultants, and other responsible stakeholders.
- Provide functional guidance, templates, procedures, and training to collateral security personnel supporting the company security program.
- Review security-related compliance evidence and readiness materials for completeness, consistency, and alignment with applicable contractual, regulatory, and company requirements.
- Escalate unresolved security or cybersecurity compliance risks to the Director, Compliance, IT leadership, the Senior Management Official, or other leadership as appropriate.
- Lead through influence, coordination, subject matter expertise, compliance authority, and executive escalation when needed.
- Develop, coordinate, and deliver security education and awareness activities, including new hire briefings, annual refresher training, CUI training support, insider threat awareness, reporting requirement reminders, and role-based security guidance.
- Promote a practical security culture that supports compliance without unnecessarily impeding business operations.
Facility Security Officer for the Headquarter Facility
- Serve as the company’s point of contact for DCSA correspondence, self-inspections, security vulnerability assessments, and security program matters related to the Chesapeake facility.
- In accordance with the Special Security Agreement, act as the security advisor to the GSC.
- Manage personnel security clearance processes, including initial clearance submissions, reinvestigations, access updates, visit certifications, debriefings, and related personnel security records.
- Maintain required facility, system, and personnel information in applicable government systems, including DISS, NISS, eMASS, SPRS, or other systems as required.
- Advise employees and managers on security reporting requirements, including personal, administrative, foreign travel, foreign contact, adverse information, suspicious contact, and incident-related reporting obligations.
- Ensure full implementation of the Special Security Agreement and Foreign Ownership, Control, or Influence mitigation requirements, including maintenance and implementation of related plans and procedures (AOP, TCP, ECP, SPP, etc)
- Support insider threat meeting preparation, awareness training, reporting pathways, escalation practices, and related program documentation.
- Conduct or coordinate required security briefings, debriefings, refresher training, and access-specific acknowledgements.
- Support visit requests, security briefings, meeting coordination, and related visitor control processes.
Classified Information System Security / ISSM
- Ensure the Chesapeake classified system is maintained in accordance with applicable government, contractual, NISPOM, RMF, system authorization, and DMS security requirements and coordinate with system administrators, IT personnel, users, DCSA, and other government security personnel as required to maintain the system’s approved security posture.
- Provide GSC with visibility into classified system risks, authorization status, corrective actions, resource needs, and compliance concerns.
Required Skills and Competencies
- Strong working knowledge of NISPOM requirements, DCSA expectations, industrial security practices, personnel security, classified material handling, and facility clearance requirements.
- Working knowledge of FOCI mitigation, SSA compliance, and security governance in a FOCI-mitigated environment.
- Working knowledge of RMF, classified information system security, system authorization, continuous monitoring, and ISSM responsibilities.
- Working knowledge of CUI protection, NIST SP 800-171, CMMC, cybersecurity compliance governance, POA&M tracking, and evidence management.
- Strong judgment, discretion, and ability to handle sensitive, confidential, classified, and personnel-related information.
- Ability to lead through influence in a matrixed environment without direct supervisory authority.
- Strong communication skills, including the ability to explain security requirements clearly to employees, managers, technical personnel, executives, and government stakeholders.
- Ability to balance compliance requirements with operational practicality.
Required Experience and Education
- Minimum of five years of experience in industrial security, facility security, classified information system security, or closely related security program roles.
- Prior experience serving as an FSO, ISSM, AFSO, security manager, or similar role in a cleared defense contractor environment.
- Experience working in a FOCI-mitigated company or supporting FOCI mitigation activities strongly preferred.
- Working knowledge of NISPOM, DCSA processes, DISS, NISS, eMASS, RMF, classified systems, and personnel security requirements.
- Working knowledge of CUI, NIST SP 800-171, CMMC, cybersecurity compliance, and security assessment readiness.
- Experience developing or maintaining security policies, procedures, SSPs, security plans, training materials, compliance evidence, POA&Ms, corrective action plans, and inspection materials.
- Experience supporting DCSA reviews, self-inspections, facility clearance requirements, classified contract requirements, and DD254 reviews.
Certifications and Training
- Completion of required FSO training or ability to complete required FSO training within a defined period after appointment.
- Completion of required ISSM training or ability to complete required ISSM training within a defined period after appointment.
- Relevant cybersecurity, information assurance, or industrial security certifications preferred, such as ISP, CAP, CISM, CISSP, Security+, or comparable credentials.
Clearance and Work Authorization Requirements
- This position requires an active security clearance or the ability to obtain and maintain the required security clearance.
- This position requires eligibility to access classified information and controlled information in accordance with applicable government and company requirements.
Physical and Work Environment Requirements
- Ability to work onsite as required to support cleared facility responsibilities, classified system responsibilities, DCSA engagement, physical security activities, classified material control, inspections, and employee support.
- Ability to move throughout office, production, storage, and controlled areas as needed to assess security posture and support program requirements.
- Ability to use standard office equipment and computer systems.
- Ability to handle sensitive, classified, and controlled information in accordance with applicable safeguarding requirements.
- Limited travel may be required to support other company locations.