Back to all jobs
C
About the role
<p>CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats. </p>
<p>CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit <a href="https://www.chaosinc.com">www.chaosinc.com</a>.</p>
<p><strong><span data-contrast="auto">Role Overview:</span></strong></p>
<p><span data-contrast="auto"><span class="TextRun SCXW85821554 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW85821554 BCX0">CHAOS Industries <span class="NormalTextRun SCXW262922489 BCX0">seeks an experienced Information Systems Security Manager (ISSM) to serve as the primary security authority for classified information systems across one or more Program Security Authorization Boundaries (PSABs). The ISSM will be responsible for the end-to-end security posture of program systems, driving risk management decisions, and ensuring compliance with applicable government regulations and contractual requirements. This role interfaces directly with government Authorizing Officials (</span><span class="NormalTextRun SCXW262922489 BCX0">AOs), Program Managers, and cross-functional engineering teams to sustain Authorization to Operate (ATO) for complex, multi-domain environments.</span></span></span></span></p>
<p><strong><span data-contrast="auto">Responsibilities: </span></strong><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><strong><span data-contrast="none">Authorization & Compliance</span></strong><span data-ccp-props="{"335559738":240,"335559739":80}"> </span>
<ul>
<li><span data-contrast="none">Develop, maintain, and submit system Security Authorization Packages in accordance with NIST SP 800-37 RMF, ICD 503, JSIG, and DAAPM frameworks.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Manage the full lifecycle of ATOs including continuous monitoring, annual reviews, and Plan of Action & Milestones (POA&Ms).</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Serve as the primary liaison to government AO/ISSM/ISSO community for all classified system authorization activities.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Ensure compliance with DCSA, DSS, and applicable IC community security policies across all assigned programs.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="none">System Security Engineering & Risk Management</span></strong><span data-ccp-props="{"335559738":240,"335559739":80}"> </span>
<ul>
<li><span data-contrast="none">Conduct and review security assessments, risk analyses, and vulnerability scans (Nessus, ACAS, SCAP) to identify and remediate risks.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Develop and maintain System Security Plans (SSPs), Security Concept of Operations (CONOPS), hardware/software baseline documentation, and interconnection agreements.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Evaluate proposed changes to hardware, software, and firmware for security impact; approve or reject changes in accordance with the Configuration Management (CM) process.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Oversee implementation and validation of STIG/SRG hardening requirements across Windows, Linux, and network infrastructure.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="none">Personnel & Program Support</span></strong><span data-ccp-props="{"335559738":240,"335559739":80}"> </span>
<ul>
<li><span data-contrast="none">Supervise and mentor ISSOs supporting assigned programs; provide guidance and review of ISSO-generated artifacts.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Conduct security briefings, annual refresher training, and onboarding education for cleared program personnel.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Investigate and report security incidents, anomalies, and potential compromise events in accordance with reporting requirements.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Support program proposal activities including security cost estimates, security architecture inputs, and DD254 reviews.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="none">Audit & Continuous Monitoring</span></strong><span data-ccp-props="{"335559738":240,"335559739":80}"> </span>
<ul>
<li><span data-contrast="none">Implement and oversee continuous monitoring strategies including log management, audit trail reviews, and SIEM integration.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Conduct periodic self-inspections, security reviews, and audit activities; track findings to closure.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Coordinate with Facilities Security Officers (FSOs) and Physical Security personnel to ensure integrated program protection.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
</ul>
</li>
</ul>
<p><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span><strong><span data-contrast="auto">Minimum Requirements:</span></strong><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="auto"><span class="TextRun SCXW241747422 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW241747422 BCX0"><span class="TextRun SCXW66586950 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW66586950 BCX0">Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related technical discipline. Equivalent experience considered in lieu of degree.</span></span><span class="EOP SCXW66586950 BCX0" data-ccp-props="{"335559738":40,"335559739":40}"> </span></span></span></span></li>
<li><span data-contrast="none">8+ years of experience in information security with a minimum of 4 years serving in an ISSM or senior ISSO role on classified U.S. Government programs.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Demonstrated experience managing RMF-based ATOs for classified systems (Secret, Top Secret, TS/SCI) under ICD 503, JSIG, or DAAPM.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Experience with ACAS/Nessus, SCAP tools, and security technical implementation guidance (STIGs).</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Hands-on experience with Windows Server, RHEL/CentOS, VMware, and network security architectures.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-ccp-props="{"335559738":40,"335559739":40}"><span class="TextRun SCXW69381226 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW69381226 BCX0">IAM Level III certification required: CISSP, CISM, or GSLC (IAW DoD 8570.01-M / DoD 8140).</span></span><span class="EOP SCXW69381226 BCX0" data-ccp-props="{"335559738":40,"335559739":40}"> </span></span></li>
<li><span data-contrast="none">Active Secret clearance required at time of hire; TS/SCI eligibility preferred or required depending on program assignment.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Preferred Requirements:</span></strong><span data-ccp-props="{"201341983":0,"335559685":360,"335559739":0,"335559740":240}"> </span></p>
<ul>
<li><span data-contrast="none">Active TS.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Experience with Special Access Programs (SAPs), Sensitive Compartmented Information Facilities (SCIFs), or Special Access Facilities (SAFs).</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Familiarity with Cross Domain Solutions (CDS), multi-level security architectures, or Type 1 encryption devices.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Knowledge of CMMC Level 2/3 requirements and their intersection with classified program requirements.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Experience with cloud security (AWS GovCloud, Azure Government) within classified or CUI environments.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Prior experience working with DCSA, NSA, DIA, or Air Force ISSM community personnel.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
<li><span data-contrast="none">Additional certifications: CAP, Security+, CASP+, CEH, or equivalent.</span><span data-ccp-props="{"335559738":40,"335559739":40}"> </span></li>
</ul>
<p><strong>Why CHAOS?</strong></p>
<ul>
<li><strong>Health Benefits: </strong>Medical, dental, and vision benefits 100% paid for by the company</li>
<li><strong>Additional benefits</strong>: 401k (+ 50% company match up to 6% of pay), FSA, HSA, life insurance, and more</li>
<li><strong>Our Perks: </strong>Free daily lunch, ‘No meeting Fridays’, unlimited PTO, casual dress code</li>
<li><strong>Compensation Components:</strong> Competitive base salaries, generous pre-IPO stock option grants, relocation assistance, and (coming soon!) annual bonuses</li>
<li><strong>Team Growth: </strong>250 employees and counting across 5 global offices</li>
</ul>
<div><em><strong>Salary Range: $140,000 - $200,000</strong></em></div>
<p><em>The stated compensation range reflects only the targeted base compensation range and excludes additional earnings such as bonus, equity, and benefits. If your compensation requirements fall outside of the range, we still encourage you to apply. The salary range for this role is an estimate based on a range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. </em></p>
<p> </p>
<hr>
<h3>Recruiting Agencies: CHAOS Industries does not accept unsolicited resumes or outreach. Unsolicited submissions will not be reviewed or compensated.</h3>
<hr>
<p> </p>
<p><em>#LI-onsite</em></p>
Perks & benefits
- 401k
- Vision Insurance
- Unlimited Vacation
- Paid Time Off
- Pension Matching
- Equity Compensation
747,000+ hidden jobs like this
CHAOS Industries and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites