The Information Systems Security Manager/Engineer
AptivAbout the role
ABOUT WIND RIVERX
Wind RiverX (WRX) is a mission-driven software company focused on delivering advanced, secure, and resilient solutions that support U.S. defense and national security missions. As a subsidiary of Wind River, a global leader in intelligent systems software with over four decades of proven success in aerospace and defense, WRX builds upon a trusted legacy of innovation, reliability, and mission assurance.
Wind River’s software has powered some of the world’s most critical systems — from the Mars rovers and commercial aircraft to advanced military platforms and autonomous defense technologies. Building on this heritage, WRX extends that technical excellence to accelerate innovation at the edge, combining agility, security, and modern software practices tailored to the unique needs of defense customers.
At WRX, we partner closely with government, defense, and industry leaders to provide secure and reliable systems to the most critical missions, enhance interoperability, and strengthen digital resilience.
Our team brings deep expertise in systems integration, open architecture, customer needs, and software-defined solutions that empower our warfighters and critical partners across air, land, sea, and cyber domains.
We are a fast-growing organization that values collaboration, integrity, and technical mastery. Our culture is rooted in innovation and purpose — we move quickly, think boldly, and take pride in delivering solutions that matter. If you believe you would be an asset to a high powered team with an energetic culture where you will contribute to reducing the definition of impossible, we would like to talk to you.
YOUR ROLE
The Information Systems Security Manager/Engineer (ISSM/E) at WRX will excel in a dynamic and ever-changing environment, demonstrating adaptability, flexibility, and proactive initiative. This role focuses on creating new compliance policy and programs and continuously monitoring and improving existing security programs, ensuring it meets U.S. federal, global, and industry specific security requirements and standards. The ISSM/E will report to the and work closely with the Sr. Director of Compliance.
The ISSM/E will play a vital role in aligning internal IT security objectives with broader business goals, effectively communicating progress and potential challenges to stakeholders at various levels. Responsibilities include ensuring compliance with relevant regulations and standards, conducting risk assessments, monitoring controls, developing and implementing IT security policies and procedures, and overseeing IT security audits and assessments. The ideal candidate will bring prior ISSM/E experience from FOCI mitigated companies and a deep knowledge in with network and systems engineering and architecture.
RESPONSIBILITIES
Governance, Risk & Compliance (GRC) Execution
Maintain enterprise compliance readiness aligned to ISO 27001, NIST 800-171, CMMC, SOX, TISAX, GDPR, NIS2, and similar regulatory frameworks.
Drive engagement with control owners, SMEs, and leadership to track risk exceptions, POA&Ms, maturity improvements, and audit-ready evidence.
Support continuous improvement of the cybersecurity policy, standards, and governance framework to ensure consistency across multi-entity operations.
Developing architecture documentation and Systems Security Plans (SSP) to support Accreditation and Authorization (A&A) reviews
Enterprise Resilience & Continuity
Own documentation, updates, and execution of business impact assessments (BIAs), continuity plans, disaster recovery strategies, and tabletop exercises.
Partner with cross-functional teams to ensure IT and cyber security compliance across the business.
Maintain continuity and response playbooks, leveraging prior experience leading large-scale DoD and enterprise network operations.
Knowledge of the complex environment involving shared networks and multiple security enclaves.
Engineering for Cyber engineering and integration services including security, authentication, identity management, authorization, and access control engineering.
Third-Party Risk Management (TPRM) & Cyber Training
Execute WRX’s vendor risk assessments, evidence reviews, and remediation tracking, applying DoD and federal acquisition (ISA Level III) experience to strengthen supply-chain posture.
Enforce cybersecurity right-to-audit clauses and support contract redline reviews for both buy- and sell-side agreements.
Support mandatory cybersecurity training initiatives, awareness campaigns, and development of role-based
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s