Information Security Manager (Job ID: 1533)
Colonna's Shipyard, IncInformation Security Manager Purpose: The Information Security Manager leads and maintains the company's cybersecurity, information assurance, compliance, and Microsoft 365 technology programs. This role protects company systems, customer information, and Controlled Unclassified Information (CUI); supports compliance with contractual and regulatory cybersecurity requirements; and serves as a senior escalation point for complex technical issues across the commercial technology environment. The position is located onsite in Norfolk, VA and will often require hours beyond a standard work week with flexible schedule availability to support production/operations. Position may require limited travel. Job Description: Information Security and Compliance Lead the organization's information security and cybersecurity programs. Develop, implement, and maintain cybersecurity policies, standards, procedures, and security controls. Manage compliance initiatives related to CMMC, NIST SP 800-171, DFARS, FAR, and customer cybersecurity requirements. Conduct risk assessments and oversee remediation efforts, Plans of Action and Milestones (POA&Ms), and continuous improvement activities. Coordinate internal and external cybersecurity audits, assessments, and evidence collection. Oversee incident response planning, exercises, investigations, containment, recovery, and reporting. Monitor threats, vulnerabilities, and emerging risks and recommend appropriate mitigation strategies. Manage security awareness and role-based training programs. Collaborate with business leaders and IT teams to implement practical security controls that support operations while reducing risk. Microsoft 365 and Cloud Technology Management Manage and support the company's Microsoft 365 technology environment, including Microsoft Entra ID, Exchange Online, SharePoint Online, Microsoft Teams, Intune, Microsoft Defender, and related cloud services. Maintain Microsoft 365 security, identity, access, endpoint-management, governance, and compliance configurations. Oversee privileged access, conditional access, multifactor authentication, information protection, retention, and data loss prevention capabilities. Evaluate and implement Microsoft 365 features and integrations that improve security, reliability, governance, and operational efficiency. Coordinate licensing, service changes, platform standards, and administrative practices with IT leadership and business stakeholders. Technical Leadership and Escalation Act as a senior escalation point for complex technical issues across the commercial environment, including infrastructure, cloud platforms, identity, endpoints, collaboration services, enterprise applications, and cybersecurity incidents. Lead or coordinate troubleshooting and resolution of high-impact technology issues affecting business operations. Partner with infrastructure, applications, support, and business teams to deliver secure, reliable, and supportable technology services. Provide technical guidance for system architecture, integrations, identity management, access control, and technology modernization initiatives. Support business continuity, disaster recovery, and operational resilience planning and testing. Mentor IT personnel on cybersecurity practices, Microsoft 365 administration, operational procedures, and advanced troubleshooting. Governance and Strategic Planning Develop cybersecurity roadmaps, budgets, metrics, and strategic initiatives aligned with business objectives. Communicate cybersecurity risks, compliance status, technical concerns, and recommended investments to leadership. Support vendor risk management, third-party security reviews, and cybersecurity requirements within contracts and procurement activities. Evaluate emerging technologies and industry trends and recommend solutions that improve security and business operations. Qualifications: Bachelor's degree in cybersecurity, information technology, information systems, computer scien…