Jobs and Careers
FI
Information Systems Security Officer (ISSO)
FirestormSan Diego, United Statesfull_timeVerifiedPosted 20 May 2025
💰 $160,000/yr($125,000/yr – $160,000/yr)
About the role
Who We Are
At Firestorm, we’re on a mission to revolutionize how defense solutions are designed and delivered. Our goal is to empower U.S. ally nations to effectively deter aggressors—regardless of their defense budget—through innovative, cost-efficient technologies. We call this vision “democratized deterrence.” As a VC-backed company at the intersection of defense and Silicon Valley, we’re pioneering the development of mission-adaptable aerial vehicles that put power back into the hands of operators. By prioritizing operator effectiveness, we’re pioneering a new era of aerial vehicle design. We aim to upend the traditional defense procurement model by delivering world-class capabilities at a fraction of the usual cost. Join us at Firestorm as we redefine defense procurement, making cutting-edge technology accessible to all at a fraction of the cost.
About the Role
We are looking for a highly skilled and motivated Information Systems Security Officer (ISSO) to join our team onsite at our San Diego office. Reporting to the Director of Operations, you will be at the forefront of developing, implementing, and upholding our company's digital security compliance strategy and information security, ensuring compliance with stringent government regulations and standards. Your expertise will be crucial in protecting our sensitive data, managing risks, overseeing our Facility Security Clearance (FCL), and ensuring that our operations meet all required cybersecurity maturity models and information control protocols. With expertise in NIST, DFARS, ISO 27001, and classified information management, you will play a key role in securing our operations and maintaining compliance with defense industry requirements. If you’re passionate about safeguarding critical data and upholding the highest standards of security, we’d love for you to join us at Firestorm.This position is required to be on-site daily in the San Diego, CA office.
What You’ll Do
- Develop, implement, and maintain the company's information security policies, standards, and procedures to ensure compliance with NIST SP 800-171, DFARS 252.204-7012, and other relevant regulations.
- Lead efforts to achieve and maintain compliance with CMMC and ISO 27001, including coordinating certification processes and managing ongoing audits.
- Oversee the protection of Controlled Unclassified Information (CUI) and other controlled information.
- Manage and maintain the company's Facility Security Clearance (FCL), serving as the primary point of contact (FSO) for all matters related to classified information security.
- Implement and oversee procedures for handling classified information, ensuring compliance with all applicable government regulations and directives.
- Conduct regular risk assessments and vulnerability analyses to identify and mitigate potential security threats, including those related to classified information systems.
- Coordinate with internal teams to integrate security controls into all aspects of operations, including product development and supply chain management.
- Serve as the primary liaison with government agencies and customers regarding information security compliance, FCL matters, and reporting.
- Develop and manage the incident response plan, leading investigations and remediation efforts, in the event of security breaches or incidents involving classified or sensitive information.
- Provide training and awareness programs to educate employees on information security policies, procedures, best practices, and the handling of classified information.
- Stay current with evolving regulatory requirements, emerging threats, and industry best practices to continuously improve the company's security posture.
- Collaborate with our DevSecOps team on the design, implementation and maintenance of cATO (continuous Authority to Operate) pipelines.
- Collaborate with IT and engineering teams to ensure secure system architectures and data protection mechanisms are in place, especially for systems processing classified information.
- Must be willing to travel up to 10%
Qualifications
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field.
- Minimum of 7 years of experience in information security management, with at least 3 years in a leadership role.
- Extensive knowledge of NIST SP 800-171, DFARS 252.204-7012, ISO 27001, CUI handling requirements, and classified information security protocols.
- Proven experience in developing and implementing information security programs and achieving compliance with regulatory standards.
- Strong understanding of risk mana
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Information Security Operations Engineer
Sanford Health
Stevens Center Building, United States
Lead Information Security Operations Engineer
Sanford Health
Stevens Center Building, United States
Head of Research & Information Services (Medical Center Library)
Saint Louis University
Learning Resources Center, United States