Information Systems Security Manager

Anduril Anduril · Defense · Costa Mesa, CA · Corporate Technology : Classified Systems : Classified Infrastructure

This role is for an Information Systems Security Manager at Anduril, a defense technology company. The manager will lead teams to support the deployment of Anduril's products in classified environments, focusing on IT, Risk Management Framework, and customer requirements. Responsibilities include documenting security controls, coordinating security artifacts, applying technology standards in classified environments, tailoring NIST 800-53 controls, conducting security scanning, and overseeing compliance.

What you'd actually do

  1. Provide expertise in documenting security controls to reduce the administrative cost of deploying Anduril’s products into operational environments.
  2. Partner with program and security teams to coordinate security artifacts in support of classified deployments.
  3. Apply technology standards from the commercial space in classified, air-gapped environments.
  4. Collaborate with Information System Owners to understand key stakeholders’ needs and provide complex technical solutions to meet contractual obligations.
  5. Tailor NIST 800-53 controls to determine applicability to the network environment and oversee the implementation of Continuous Monitoring for respective programs.

Skills

Required

  • Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards.
  • Integrate security best practices into Anduril’s Software Development Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams.
  • Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats.
  • Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and secure communications technologies.
  • Develop and enforce access controls, encryption strategies, and other technical measures to safeguard systems.
  • Maintain and update System Security Plans (SSPs), POA&Ms, and other accreditation documentation.
  • Manage the organization’s security posture, ensuring compliance with internal policies and external regulatory frameworks.
  • Oversee Authorization and Accreditation (A&A) processes to obtain/maintain system Authority to Operate (ATO).
  • Lead incident response efforts, including investigation, root cause analysis, containment, and reporting.
  • Conduct regular audits, continuous monitoring, and risk assessments to ensure ongoing compliance and system resilience.
  • Collaborate with government security officials, stakeholders, and teams to address security gaps and improve controls.
  • Develop and deliver security awareness training and ensure adherence to security best practices.
  • Provide leadership and mentorship to security team members, fostering a culture of cybersecurity excellence.
  • Currently possesses and is able to maintain an active U.S. Top Secret security clearance.

Nice to have

  • Experience with application security paradigms such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). As well as the tools needed to perform these actions.
  • Proven experience in securing micro-services architecture, including implementing best practices and compliance with DoD cybersecurity standards.
  • Experience with cybersecurity in unmanned and ground control system within DoD environments.
  • Experience with containerization and kubernetes along with the best practices for securing them.
  • Experience with Cloud Service Providers (CSPs) and the various tools they offer for implementing security and compliance best practices.

What the JD emphasized

  • contract deliverables
  • classified environments
  • Risk Management Framework
  • customer requirements
  • contractual obligations
  • NIST 800-53
  • Continuous Monitoring
  • accredited information systems
  • Authorization and Accreditation (A&A)
  • Authority to Operate (ATO)
  • government security officials